Key Takeaways

  • Bitget’s hack is larger than first reported, with the exchange now putting the damage at $387.5 million.
  • Gracy Chen wants Thorchain to cut off the hackers as they shuffle stolen funds into bitcoin.
  • Thorchain faced a similar fight after the Bybit hack, and its validators weren’t willing to block the moving funds.

Bitget’s Hack Climbs to $387.5 Million as CEO Gracy Chen Calls on Thorchain to Block Hackers

Two days ago, Bitcoin.com News reported on the Bitget hack, and at the time, the exchange said hackers stole around $351 million. That estimate has been increased since then, and Bitget now estimates that “approximately $387.5 million were transferred to attacker-controlled addresses.” Bitget’s attacker has been moving stolen funds and leveraging a few different rails, including Thorchain.

Thorchain is essentially a decentralized network that allows people to swap different crypto assets across different blockchain networks, like swapping BTC for ETH. This weekend, several reports say that tens of millions in XRP have been deposited into Thorchain vaults, and another stash of tens of millions has already been swapped for BTC. The bitcoin is then peeled and hopped across a myriad of bitcoin addresses.

In addition to Thorchain, the Bitget hackers are reportedly using Chainflip, Uniswap, 1inch Fusion, Stargate, Across, and Relay, to name a few. The Thorchain moves have caught the attention of Bitget executives, and CEO Gracy Chen took to X on Saturday to ask Thorchain to block the attackers. “Our attacker addresses are publicly listed and actively tracked. We are formally asking Thorchain to refuse service to these addresses,” Chen wrote.

The Bitget CEO added:

“Decentralization is a design principle, not a shield for facilitating known stolen funds. The industry is watching.”

Thorchain Faces Another Bybit-Style Standoff

Chen’s comments did not resonate well with some respondents replying to her X thread. “What part of permissionless don’t you understand? Why aren’t you asking BTC miners to stop the funds?” one person asked. “Would you get mad at the highway that the bank robber used to escape?” another individual wrote on the Bitget CEO’s thread.

Chen’s ask is the thing Thorchain had already declined under FBI pressure after the Bybit hack. Thorchain was leveraged to move $1.2 to $1.5 billion in stolen funds from the Bybit breach. At the time, the FBI asked the industry to block DPRK-linked addresses, and three of the protocol’s validators voted to halt ETH trading. Four validators reversed the decision a half an hour later, and Thorchain continued to run. A developer quit over the fiasco.

The protocol can halt the entire system, and nodes can pause trading. For instance, after the May 2026 GG20 exploit that drained about $10.7 to $11 million from one of its vaults, operators paused the network, and it stayed down for weeks while they patched. Alongside this, some Thorchain front ends have screened sanctioned or flagged addresses for years, but this can be bypassed. If Thorchain wasn’t able to block the Bybit funds, or validators chose not to, likely, it won’t happen in this case either.

At 2:17 p.m. Eastern time on Saturday, Thorchain’s official X account responded to the request, alongside tagging the Bitget CEO. “We are devastated to hear about the recent exploit and can imagine how difficult this must be for everyone involved. [Thorchain] is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?”



Source link