Bitget has asked THORChain to stop processing transactions involving wallets linked to a breach it now estimates at about $387.5 million. THORChain says its emergency shutdown controls are designed to protect the network as a whole, rather than selectively freeze one user’s swap.
The dispute highlights the limits of control in cross-chain transactions. A stablecoin issuer can freeze its own token, a centralised exchange can suspend an account and THORChain node operators can pause routes. But no single organisation has a universal switch for assets once they have moved between networks.
Bitget initially estimated the loss at $351.6 million before revising the figure to approximately $387.5 million. The higher estimate includes additional transactions involving Zcash and TRON. It represents the company’s assessment of assets sent to attacker-controlled addresses, rather than an independently verified final loss.
Bitget CEO Gracy Chen called on THORChain to refuse service to addresses associated with the 24 September breach. In a public response on 28 September, THORChain said stopping the network was not the same as freezing a particular address.
GoPlus Security challenged that distinction, arguing that THORChain’s node operators already play a role in managing vaults and pausing network functions. THORChain maintains that its existing controls can halt activity on individual chains or across the network, but are not an established blacklist for selected addresses.
Stablecoin freezes represent a small proportion
Bitget said Circle and Tether had frozen 99,990 USDC and 218,023 USDT linked to the incident. At their dollar pegs, the two amounts total approximately $318,013.
That represents about 0.082% of the revised $387.5 million estimate – roughly eight cents for every $100 reported as transferred. The figure does not mean only $318,013 remains traceable or that Bitget has recovered no more than that amount. The exchange said other affected assets had been frozen through partners, but did not provide a complete total of frozen and recovered funds in the cited update.
Bitget has offered a 5% bounty for eligible efforts to freeze directly affected funds, alongside a further 5% reward for recovery. The company says customer balances remain intact and that its protection fund will absorb the impact. Those statements have not been independently audited in the information provided.
The powers available to each organisation depend on where the assets are held. A stablecoin issuer may be able to stop a particular token from being transferred from a flagged address, but it cannot freeze native ETH or BTC bought with that token. A centralised exchange can suspend an account or reject a flagged deposit, but cannot control funds held in a self-custodied Bitcoin wallet.
Similarly, a THORChain halt may interrupt legitimate users as well as suspicious transactions. It can stop a route while a transaction is being processed, but it cannot reverse a Bitcoin transfer that has already settled on the Bitcoin network.
Four-stage route reached CoinJoin
AMLBot traced approximately 4 BTC linked to the breach through four blockchain stages before the funds reached a Wasabi CoinJoin round, according to a 27 September report.
The route began with assets on TRON, moved through USDT0 to Ethereum, used THORChain to exchange into Bitcoin and then entered CoinJoin. It is one identified route, not a map of all $387.5 million and not proof that every receiving address belongs to the same person.
The sequence shows how control can change during a transaction. An issuer may act while funds remain in a stablecoin. A bridge operator’s powers depend on its design. THORChain nodes can affect whether swaps are available, while a custodial exchange may block deposits or withdrawals. Once BTC has left a THORChain vault for an external wallet, THORChain no longer controls that balance.
CoinJoin combines inputs and outputs to make simple tracing more difficult, although it does not necessarily make funds permanently untraceable. The four BTC cannot be used to calculate the proportion of the whole breach without a timestamped Bitcoin price, and even then it would represent only that particular route.
What THORChain can and cannot do
THORChain’s native swaps involve a user sending an asset to a protocol vault on its original blockchain. Nodes observe the deposit, calculate the exchange through liquidity pools and arrange an outbound transaction in the destination asset.
The outbound transfer uses threshold signing, meaning several node participants contribute and no single operator holds the complete key. The nodes collectively maintain the infrastructure that receives one asset and sends another, although individual operators do not manually approve every swap.
THORChain’s documented controls include chain-specific and wider network halts. The network used those powers after a vault exploit on 15 May, reported at roughly $10.7 million. Solvency checks identified an imbalance, and further measures were coordinated before trading returned in June under an 11-step restart plan reported by Crypto.news.
That history demonstrates that THORChain can pause operations. It does not prove that the protocol currently screens every transaction against a verified list of stolen-fund addresses. A selective blacklist would require rules for evidence, responsibility, appeals and the treatment of funds moved to new wallets.
A broad halt could interrupt a swap still awaiting settlement, but it would not undo an outbound Bitcoin transaction already completed. Stopping one venue would also leave an attacker free to try another bridge, exchange or direct sale.
Address lists are not universal identities
Bitget has published receiving addresses for several networks, including EVM-compatible chains, XRP Ledger, Zcash and TRON. Those addresses provide starting points for investigation, but they do not establish that every wallet touched by them belongs to the attacker.
A custodial deposit address may receive funds from many customers. Someone may also receive a transfer without involvement in the breach. Treating every connected address as equally culpable risks blocking innocent holders.
The timing of any intervention is therefore critical. Investigators would need to record when Bitget identified an address, when a service was notified, when funds arrived, when an outbound transaction was broadcast and when a freeze took effect. A freeze of a stablecoin before conversion is different from action taken after the asset has become ETH or BTC.
Bitget’s request to THORChain is an appeal to its community, not a court injunction or an automatic change to the protocol. THORChain must decide whether to use its existing emergency controls or consider a new address-screening system.
Bitget is separately planning a staged restart of withdrawals beginning on 28 September. The exchange said Mandiant and SlowMist were assisting its investigation and that the vulnerability had been fixed. Its schedule listed BTC first, followed by ETH, USDT and other services through 2 October. The company said its recovery fund would protect customers, but a published timetable is not proof that every transfer has succeeded.
The clearest measure of progress will be independently checkable evidence showing, by asset and blockchain, how much was moved, frozen and ultimately returned. Until that information is available, the known figures show approximately $318,013 frozen in USDC and USDT against a revised loss estimate of $387.5 million.
