THORChain's team has announced that they will not initiate a network halt to selectively block funds linked to the Bitget exchange hack.

A THORChain network halt is an emergency security mechanism designed to protect the protocol.

A halt is not a selective freeze of specific funds or an individual swap.

During the May 2026 exploit that resulted in $10.7M stolen from the liquidity pools, the attackers' addresses… https://t.co/HrigTUbA4Q

— THORChain (@THORChain) September 28, 2026

"A THORChain network halt is an emergency safety measure intended to protect the protocol. It is not a selective freeze of specific funds or a block on individual swaps. […] THORChain operates without permissions and, by design, does not enforce censorship," the statement read.

On September 24, a hacker extracted assets from some of the exchange's hot and warm wallets. The initial damage estimate of $351.6 million was later revised to $387.5 million.

According to Bitget, the attacker compromised a critical backend component and altered transaction data, enabling them to bypass authorization processes and execute unauthorized transfers.

No private key leaks have been reported. Bitget is working with Mandiant and SlowMist on the investigation.

Following the breach, the cybercriminal moved funds across networks using THORChain. On September 26, Gracy Chen, CEO of Bitget, reached out to protocol developers, urging them not to process transactions from the identified attacker’s addresses.

"Decentralization is a design principle, not a cover for facilitating crime. The industry is watching," she stated.

Network Halt and Address Blocking

THORChain has the technical ability to halt its network. In May, after suffering a $10.7 million attack, an automated solvency-checking system stopped trading and transaction signing across multiple networks.

Subsequently, node operators, with the help of Mimir, fully suspended operations.

However, this did not involve blocking specific addresses. THORChain's team clarified that even then, the hacker's addresses were not blacklisted, allowing them to continue operations through the protocol.

The project lacks a centralized authority to make such decisions. In February 2025, the administrative key Mimir, which allowed parameter changes without validator consensus, was removed from the protocol.

Since then, node operators have governed the network. For specific operational measures like halting trading or signing transactions, the votes of three operators are sufficient.

In response to Bitget's request, developers compared THORChain to Bitcoin, Ethereum, and BNB Chain, asserting that the protocol, like these networks, operates without permission and does not determine who can conduct transactions.

On September 27, GoPlus Security experts challenged this comparison, pointing out that assets for cross-chain operations are stored in TSS vaults under collective control of an active set of validators, while THORChain's architecture includes mechanisms for halting operations.

❗️ #THORChain has never been strictly decentralized. Comparing itself to decentralized L1s like BTC and ETH does not hold. Do not enable criminals — or put the industry at risk — just to take swap fees on stolen funds.

1️⃣ Custody: TSS vaults ≠ base-layer consensus… https://t.co/x23ZWABnNb pic.twitter.com/D3wD9qG3hX

— GoPlus Security 🚦 (@GoPlusSecurity) September 27, 2026

Experts believe these tools could allow for freezing stolen assets without disrupting the entire network.

It is worth noting that in February 2025, THORChain's lead developer, known as Pluto, left the project after a vote to block transactions linked to hackers from the Lazarus Group, involved in the Bybit hack, was canceled.

At that time, hackers actively used the protocol for laundering money, with swap volumes in THORChain exceeding $4.6 billion in the week following the attack.

Follow ForkLog on social media

Telegram (main channel) Facebook X Did you find an error in the text? Highlight it and press CTRL+ENTER