THORChain Bitget Dispute: Who Can Actually Freeze Stolen Crypto?

By: WEEX|09/29/2026 03:37:12

THORChain refused Bitget's request to block wallets tied to the exchange's $387.5 million hack, saying its permissionless design has no way to freeze a single address. The THORChain Bitget dispute exposes a rule most users never think about: stolen crypto can only be frozen by someone who controls the asset or the account holding it, such as a stablecoin issuer or a centralized exchange. This explainer walks through what happened between September 24 and September 29, 2026, which parts of the stolen funds could realistically be frozen, why THORChain's refusal became the flashpoint, and what it means for anyone who keeps money on an exchange.

What Happened in the Bitget Hack

Bitget detected unauthorized transfers from parts of its hot and warm wallet infrastructure at 18:31 UTC on September 24, 2026, and suspended all withdrawals. The first loss estimate was $351.6 million; on September 25 Bitget raised it to about $387.5 million after further on-chain tracing, making it the largest reported exchange hack of 2026 so far.

According to Bitget's updates, the attacker compromised a backend system in its wallet infrastructure and spoofed transaction data to get past internal authorization checks. The exchange says private keys were not compromised, cold wallets were not touched, and its separate self-custody product, Bitget Wallet, was unaffected. Stolen assets included XRP, ETH, USDT, USDC, ZEC, BNB, AVAX and TRX across Ethereum, several EVM networks, the XRP Ledger, Zcash and Tron. Bitget says the method matches known North Korean hacking patterns, though attribution has not been formally confirmed.

THORChain Bitget Dispute: Who Can Actually Freeze Stolen Crypto?

Bitget says its User Protection Fund, which held more than $464 million when withdrawals were halted, covers the loss and that user balances are unaffected. Withdrawals are coming back in phases: BTC from 08:00 UTC on September 28, ETH on September 29, USDT on September 30, and remaining tokens, fiat and P2P from October 2.

Why Bitget Asked THORChain to Block the Hacker

THORChain is a cross-chain swap network. Send ETH or XRP in, and it pays out native BTC on another chain, with no account and no custodian in between. For an attacker holding flagged assets, that is the fastest route out of tokens that exchanges and issuers can track into bitcoin that nobody can freeze.

That is what happened here. A wallet linked to the Bitget attacker swapped about 2,390 ETH, worth roughly $6.3 million, for 75.2 BTC through THORChain on September 28. Security firm GoPlus counted around 101.5 BTC and 27.63 million XRP moving through THORChain over the course of the incident. Bitget CEO Gracy Chen publicly asked THORChain on September 26 to refuse service to the published attacker addresses and offered a 5% bounty on any funds frozen or recovered.

THORChain declined. Its position is that it is permissionless by design, that its emergency controls can halt the whole network or a chain but cannot target one address or swap, and that a halt exists to protect the protocol, not to freeze particular funds.

Who Can Actually Freeze Stolen Crypto

The dispute makes more sense once you map where freezing power actually sits. In practice, there are five places, and they are very uneven.

  1. Stablecoin issuers. Tether and Circle can blacklist addresses holding USDT or USDC at the contract level, and they do it routinely. In this case, roughly $318,000 in stablecoins linked to the hack were frozen early on. That is a small slice, because attackers usually swap stablecoins out within hours.
  2. Centralized exchanges and custodians. Any exchange can freeze deposits from flagged addresses. This is why stolen funds rarely go straight to an exchange, and why exchanges like Bybit and OKX offered to track and block Bitget-linked flows.
  3. Chains and protocols with halt switches. Some networks can pause everything, as THORChain can. That is a blunt tool: stopping the attacker also stops every legitimate user.
  4. Token issuers with admin keys. Some tokens carry a freeze or pause function in their contracts. Many do not, and the stolen majors here (ETH, BNB, AVAX, TRX, XRP) are native assets with no issuer to call.
  5. Nobody, for native BTC or ETH in a self-custody wallet. Once stolen funds become native bitcoin in an address the attacker controls, there is no switch anywhere. Recovery then depends on tracing the coins to a future exchange deposit.

The better reading of THORChain's role is that it sits at the handoff between the freezable and the unfreezable. Funds on the way in are still traceable; funds on the way out are native BTC. That is why Bitget pressed so hard, and why the refusal matters more than the $6 million to $10 million that has moved through so far.

-- Price

--
--
--

THORChain's Argument and Why Critics Aren't Buying It

THORChain's defense is consistency: if the protocol blocks one hacker on one exchange's request, it becomes a censorship list that any government or company could lean on. Supporters argue it would be unfair to demand from THORChain what nobody demands from Bitcoin or Ethereum.

Critics, including GoPlus and Chen herself, point out that THORChain is not Bitcoin. Its validators can and do halt the network. They did so in 2021 during exploits, and THORChain paused trading after its own $10.7 million vault exploit on May 15, 2026, resuming only after more than a month of upgrades. The complaint is that the network stops for its own losses but not for other people's.

There is also history. After the February 2025 Bybit hack, Bybit's CEO reported that about $0.9 billion of the stolen ether, roughly 72%, went through THORChain. A validator vote to halt ETH trading at the time was reversed within minutes, and a core developer quit the project in protest. The Bitget case is the second time in two years the same argument has played out with a nine-figure hack.

The more important point for readers is structural: whatever THORChain decides, a permissionless swap route will exist somewhere. Recovery in exchange hacks increasingly depends on speed in the first hours, when funds are still in stablecoins or exchange-traceable tokens.

What the Bitget Hack Means for Exchange Users

For Bitget customers, the practical picture as of September 29, 2026 is reassuring on paper: balances are stated as intact, the protection fund is larger than the loss, and withdrawals are reopening on a published schedule. Expect queues and possible delays on the first day each asset reopens.

For everyone else, three habits are worth taking from this incident:

  • Check what backs a platform when things go wrong. A protection fund and proof-of-reserves reports are the two disclosures that matter in a hack. WEEX, for example, states that it maintains a 1,000 BTC protection fund and publishes 100% proof of reserves; compare such figures across any platform you use.
  • Keep trading balances and savings apart. Funds you are not actively trading don't need to sit on any exchange. Moving them to a wallet you control removes platform hack risk, though it adds your own custody risk. If you have not set one up, see how to get a crypto wallet and fund it safely.
  • Treat "recovery" messages as scams by default. After every major hack, fake support accounts offer to "unlock" or "recover" funds for a fee or a seed phrase. Official updates come only through the platform's own channels.

THORChain Bitget: The Takeaway

The THORChain Bitget dispute is less about one protocol's refusal than about where freezing power really exists in crypto. Stablecoin issuers and exchanges can freeze; permissionless swap networks and native coins cannot. Bitget's users appear protected by a fund that exceeds the loss, but that is a platform choice, not a guarantee the industry provides. Knowing which of your assets could be frozen, by whom, and which could not, is the most useful thing to take from this week.

FAQ

1. Did THORChain help the Bitget hacker?

THORChain did not act on the attacker's behalf, but its network processed swaps from attacker-linked wallets into bitcoin. It refused Bitget's request to block those addresses, saying it cannot selectively freeze transactions.

2. Are Bitget user funds safe after the hack?

Bitget says account balances are unaffected and that its User Protection Fund, which held over $464 million, covers the $387.5 million loss. Withdrawals are resuming in phases through October 2, 2026.

3. Can Tether freeze stolen USDT?

Yes. Tether and Circle can blacklist addresses holding their stablecoins, which is why a portion of stolen stablecoins is often frozen within hours. Once swapped into native BTC or ETH, that option disappears.

4. When do Bitget withdrawals fully resume?

Bitget's schedule lists BTC from September 28, ETH on September 29 and USDT on September 30 at 08:00 UTC, with other tokens, fiat and P2P services returning from October 2.

Risk Warning

Crypto assets are highly volatile and may result in partial or total loss. Funds held on any centralized exchange carry counterparty and security risk, including hacks, withdrawal suspensions and delays in reimbursement. Self-custody removes platform risk but places full responsibility for keys and transfers on you. Stolen crypto that has been converted into native assets is rarely recoverable. Details in this article reflect public statements as of September 29, 2026 and may change as investigations continue. This article is for education only and is not financial advice.

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com