Bitget Hacker Moves $6M Into Bitcoin After THORChain Rejects Blocking Request

A wallet linked to the Bitget hacker swapped roughly 2,390 ETH for 75.2 BTC through THORChain on Monday, moving about $6.3 million in value as Bitget continued pressing the network to block addresses tied to its $387.5 million theft.

CoinDesk’s review of THORChain’s public transaction records found 27 swaps that were marked successful. Together, they exchanged approximately 2,390 ETH for 75.2 BTC, with all of the resulting bitcoin sent to a single address.

Four additional swaps involving another 400 ETH were listed as pending in the transaction data reviewed.

The orders were submitted between about 03:55 and 06:23 UTC from an Ethereum wallet that blockchain tracker Lookonchain had associated with the attacker. Most of the transactions were placed in batches of roughly 100 ETH, worth around $265,000 each at the time.

THORChain Provides a Route Around Centralized Exchanges

THORChain allows users to exchange assets across different blockchains without registering with or depositing funds at a centralized exchange.

For an attacker holding stolen ETH, that means the assets can be exchanged for BTC and sent to a separate wallet without first passing through a centralized platform that might freeze the funds. The transactions themselves remain visible on public blockchains, allowing analysts to monitor the movement between networks.

Bitget suffered a security breach on September 24 in which approximately $388 million was stolen after the attacker bypassed protections surrounding the exchange’s wallets.

The company has since said it identified and fixed the vulnerability. Bitget has not publicly disclosed the precise method used to gain access to the affected wallets.

Bitget Calls for Address Restrictions

After the incident, Bitget published wallet addresses associated with the attacker and offered a 5% bounty for qualifying efforts to freeze or recover the stolen assets.

As the attacker began routing funds through external services, Bitget CEO Gracy Chen called on THORChain to reject transactions involving the identified addresses.

Chen said the attacker’s wallets were publicly known and actively monitored. She argued that decentralization should not prevent the network from refusing transactions involving funds identified as stolen.

THORChain pushed back against the request Monday, explaining that its emergency controls are not equivalent to an address-level blacklist.

The protocol said a network halt is intended to serve as an emergency security measure for protecting THORChain itself. It is not designed to selectively freeze specific assets or prevent a particular user from completing a swap.

Network-Wide Controls Come With Broader Effects

THORChain’s documentation outlines controls that allow operators to halt swaps across the network or restrict activity involving a particular blockchain.

Those mechanisms could, for example, stop all swaps or suspend routes involving Ethereum. However, doing so would also affect legitimate users attempting to conduct unrelated transactions through the same network routes.

THORChain previously activated similar emergency controls in May after an attacker stole roughly $10.7 million from one of its own vaults, which contain assets used to facilitate swaps.

Trading was suspended while developers investigated the attack and addressed the vulnerability. The network resumed operations on June 22 after approximately five weeks.

According to THORChain, the addresses associated with that incident were never blacklisted. The May intervention was intended to protect the protocol from a direct compromise, whereas Bitget is asking the network to restrict assets stolen from an outside exchange.

Some ETH Orders Were Not Fully Executed

The hacker’s Monday activity also encountered execution limits on some transactions.

Two separate 100 ETH orders were only partially completed after portions of the swaps failed to meet their minimum price conditions. Approximately 114 ETH was returned to the originating wallet.

The transactions demonstrate how stolen assets can continue moving through decentralized infrastructure even when centralized exchanges are able to identify and flag the associated wallets. While cross-chain swaps remain publicly traceable, protocols such as THORChain do not necessarily provide the same selective freezing tools as centralized platforms.