A wallet tied to the Bitget hacker converted approximately $6.3 million in ether into bitcoin via THORChain on Monday, executing 27 successful swaps that moved 2,390 ETH into 75.2 BTC—all directed to a single address. Four additional swaps involving 400 ETH remained pending during the window.
The conversion orders hit between 03:55 and 06:23 UTC on Monday. Blockchain tracker Lookonchain identified the Ethereum wallet as part of the attacker's broader movement of stolen assets, with most swaps processed in batches of roughly 100 ETH each, valued at approximately $265,000 per swap.
Bitget suffered a security breach on Sept. 24 that drained about $388 million from its exchange wallets. The company said it identified and resolved the vulnerability but has not disclosed how the attacker gained access. Following the breach, Bitget published the attacker's wallet addresses and offered a 5 percent bounty for recovery efforts.
Bitget CEO Gracy Chen publicly appealed to THORChain over the weekend, posting on X: "Our attacker addresses are publicly listed and actively tracked. We are formally asking to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds."
THORChain responded Monday by defending its open-access policy. The project stated: "A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap."
The protocol's operators do possess emergency controls to halt trading. THORChain's documentation outlines settings that can stop swaps across all blockchains or restrict activity on a specific chain like Ethereum. Activating those controls would disrupt legitimate transactions on the affected routes.
THORChain previously invoked emergency shutdown in May after an attacker stole approximately $10.7 million from one of its own vaults holding swap assets. Operators coordinated a network shutdown while developers repaired the vulnerability. Trading resumed on June 22, roughly five weeks later.
The distinction matters for traders and holders: THORChain's refusal to selectively block addresses means decentralized protocols cannot be compelled to freeze stolen funds, but all transactions—attacker and legitimate user alike—remain publicly visible on-chain. That visibility allows investigators and chain analysis firms to track and monitor fund movements in real time, even if the protocol won't intervene.
