# Bitget CEO Challenges THORChain After $387.5 Million Wallet Breach

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/25416
Published: 2026-09-29T15:33:43.000Z
Updated: 2026-09-29T15:33:43.000Z
Section: Technology

> Gracy Chen wants THORChain to block addresses tied to Bitget’s Sept. 24 breach, while the protocol says its emergency controls cannot freeze individual wallets or swaps.

Bitget CEO Gracy Chen is challenging THORChain’s refusal to block wallets tied to the exchange’s Sept. 24 security breach, intensifying a debate over intervention by permissionless cross-chain protocols.

Bitget detected unauthorized transfers at 2:31 p.m. ET (18:31 UTC) on Sept. 24. The exchange initially estimated the affected assets at $351.6 million, then revised the figure to approximately $387.5 million after expanding its accounting to include assets on Zcash and TRON. The revision covered transfers identified through Sept. 25 and did not represent additional unauthorized transfers.

Bitget said the breach involved hot and warm wallets. Private keys were not compromised, and cold wallets were unaffected.

Chen made [an earlier request for THORChain to refuse service](<https://www.tokenpost.com/news/technology/24411>) to the identified attacker addresses on Sept. 26. In a Sept. 28 response, THORChain said its emergency controls can halt the network but cannot selectively freeze an address or an individual swap.

“Decentralization is a design principle, not a shield for facilitating known stolen funds,” Chen said.

The conflict raises broader questions about how permissionless protocols should handle wallets linked to stolen funds. The protocol said its earlier intervention was a network-wide emergency measure rather than an address-level blacklist.

THORChain halted trading, signing, chain observation and churning after a May exploit drained approximately $10.7 million from one of five vaults. The network restarted June 22 after roughly five weeks offline.

“A halt is not a selective freeze of specific funds or an individual swap,” THORChain said.

The dispute centers on whether a cross-chain protocol should deny service to wallets publicly identified as holding stolen assets. Bitget is seeking targeted restrictions, while THORChain maintains that its emergency mechanism applies broadly to the network and does not provide selective control over individual funds.

Bitget offered a bounty equal to 5% of affected funds successfully frozen or recovered through eligible voluntary efforts.

## Links in this article

- [an earlier request for THORChain to refuse service](https://www.tokenpost.com/news/technology/24411)
