THORChain Faces Backlash After Bitget's $387M Hack
Hackers drained $387.5 million (USD) from Bitget on 24 September 2026, then swapped stolen tokens through THORChain into bitcoin. Everyday wallet users should watch this case, since it may decide which cross-chain bridges get treated as safe or risky going forward.
What actually happened
Bitget confirmed a loss of roughly $387.5 million (USD) from its hot and warm wallets on 24 September 2026, according to Wu Blockchain. The exchange said its backend wallet system was manipulated, not its private keys, and pointed to a possible North Korea linked group. Bitget detected the breach at 18:31 UTC, but funds kept leaving accounts until about 21:23 UTC. Two days later, AMLBot reported that 88% of the stolen assets remained untouched. Bitquery calculated that THORChain swaps had already converted about 126.71 BTC, near $10.6 million (USD), with BNB conversions alone producing roughly 51.26 BTC. Bitget's CEO, Gracy Chen, publicly urged THORChain to cut off the attacker's wallets, saying, "Decentralization is a design principle, not a shield for facilitating the movement of known stolen funds. The entire industry is watching."
How we got here
THORChain went live in 2022, built on cross-chain swap work started in 2019 by John-Paul Thorbjornsen and Chad Barraford. Its design relies on rotating validator groups holding shared control of funds through threshold signatures, with no single custodian. This is not the network's first brush with stolen money. After the 2025 Bybit breach, MistTrack traced almost $1.2 billion (USD) in stolen assets passing through THORChain. In May 2026, thieves took about $10.7 million (USD) directly from THORChain's own vaults, forcing validators to pause the network for 39 days. That pause now fuels arguments that the protocol can intervene when its own funds are at stake.
Why this matters for you
For everyday holders, this dispute matters beyond the headlines. Exchanges may tighten rules on THORChain linked addresses, and regulators could push wallets to screen transactions before they settle. Builders of cross-chain tools, including AR and hardware wallet makers, may face pressure to flag risky addresses earlier. For bonuz.market users, it is a reminder that cross-chain convenience carries counterparty risk. Checking where liquidity comes from matters as much as checking the destination address.
The bigger question
If THORChain could pause itself for 39 days to protect its own stolen funds, should it use that same power to block other victims' stolen assets? Or does true permissionless design mean treating every transaction the same, no matter its origin? The answer may decide how much trust regulators place in decentralized infrastructure.
What to watch
AMLBot, Bitquery, and MistTrack keep tracing the stolen funds across chains. As of 26 September 2026, THORChain had announced no policy change since Chen's request. Watch for governance proposals on address screening, and regulator statements citing this case. bonuz.market will track how exchanges and wallet builders react as pressure builds.






