Stolen funds from Bitget were not intercepted by THORChain, highlighting inconsistent suspension standards among decentralized protocols.
TL;DR · On September 26, Bitget CEO publicly demanded that THORChain refuse to provide services to flagged attacker addresses. THORChain responded that the protocol, like Bitcoin and Ethereum, is permissionless and should not bear censorship responsibility alone. · The core of the dispute is whether node governance can selectively intervene. After the protocol's self-theft in May this year, the community coordinated a shutdown of 39 days within about two hours. In the 2025 Bybit case, a pause vote briefly passed and was then overturned. · Related targets: RUNE, Bitget User Protection Fund, Bitcoin as the endpoint for converting stolen funds, and similar cross-chain liquidity protocols.
On September 26, 2026, Bitget CEO Gracy posted on X, demanding that THORChain refuse to provide services to known attacker addresses from the platform's September 24 theft. Decentralization is a design principle, not a shield to greenlight known stolen funds.
THORChain also responded, saying no, the protocol, like Bitcoin, Ethereum, and BNB Chain, is permissionless. When known stolen funds flow through these networks, they likewise cannot be required to bear censorship responsibility. But this argument is clearly not very acceptable, because when THORChain itself was stolen from, it stopped quite quickly.
Absurdly, because of the involvement of stolen funds, RUNE fees increased, which also led to a clear surge in RUNE volume.

On the day of the confrontation, RUNE trading volume expanded fourfold
How unwrapped cross-chain became an exit for stolen funds
THORChain allows native assets from different chains to be swapped directly in liquidity pools, without first wrapping ETH into a mapped asset. This step skips the wrapping process, and also skips the issuer behind the wrapped asset.
The consequences are direct. Circle and Tether can freeze USDC and USDT, but once stolen assets are swapped into native BTC, there is no centralized entity that can press the return key.
This is exactly the endpoint hackers want. No real-name verification, no account freezing step, pools deep enough to absorb large amounts, and XRP, ETH, and BNB can all be swapped into hard-to-recover native BTC. On-chain tracking shows that about 103 million XRP (about $157 million) has already been cashed out through THORChain, while the bulk of ETH has still not moved.

ETH unmoved amount still higher than redeemed Bitcoin
Each swap generates fees that flow to nodes and liquidity providers. This is why RUNE is sensitive to volume, and where the attacker's path is tied to the token price.
The TSS vault controversy: is it more like Bitcoin or more like a trading platform
THORChain's vaults operate on a threshold signature (TSS) mechanism. A group of nodes each holds a key fragment, and only when enough of them come together can funds be moved out of the pool. Once the threshold is reached, funds can be moved, with an accountable governance layer behind it.
This is where the skepticism from trading platforms and on-chain trackers lands. The protocol acts as an intermediary between users and native chains, only it has decentralized the intermediary. THORChain officially insists it is permissionless infrastructure and should not be asked to play an enforcement role, tossing the problem back to Bitcoin and Ethereum.
The victims want to intercept, the protocol wants neutrality, and third parties want accountability. The tension among these three forms the complete structure of this debate.
The key to the disagreement is that "not reviewing individual transactions by default" and "lacking the ability to review" are two different things. Node collectives could theoretically refuse to sign. The question is whether they are willing to.
Self-theft shutdown for 39 days, yet Bybit's vote was overturned
On May 15 of this year, malicious nodes exploited a threshold signature-related vulnerability to drain approximately $10.7 million from a single vault. The protocol automatically detected this and stopped signing. The community coordinated a shutdown within about two hours, and trading was suspended for 39 days until resuming on June 23.
When the protocol itself was bleeding, nodes acted quickly. The voting threshold to halt a chain is not high—3 votes to take effect, 4 votes to revoke. This is the hardest piece of evidence for judging "whether they can intercept."
The 2025 Bybit case presents another side. Of the approximately $1.46 billion in stolen funds at the time, research estimates that about $1.2 billion was swapped from ETH to BTC through THORChain, accounting for roughly 85%. Three validators voted to pause ETH transactions, and four votes overturned it within minutes. Core developer Pluto subsequently resigned. The FBI issued a notice the same day requiring virtual asset service providers to block the relevant addresses. The protocol ultimately maintained its permissionless stance.
The difference between the two instances mainly comes from governance willingness, not technical capability. As of now, nodes have not initiated a new chain-halt vote for the Bitget case.

Nodes only choose to halt the chain when they themselves are hacked
Scale far smaller than Bybit, chain-halt vote still not initiated
The stolen amount from Bitget has been revised upward from $351.6 million to approximately $387.5 million. Although it is not on the same scale as Bybit, the amount is not the point. So far, about $157 million has been confirmed as cashed out via THORChain.
What determines the direction of the controversy is whether nodes will initiate another chain-halt vote for Bitget, and how much of the stolen funds will ultimately complete this route. The former is governance willingness, the latter is the pricing basis. For RUNE holders, short-term trading impulses and long-term compliance narrative pressure need to be calculated together on the same ledger.

