Bitget now says $387.5 million walked out the door in last week's breach, up from the $351.6 million it first disclosed. The revised figure, confirmed September 25, grew after the exchange added Zcash and Tron assets to the tally. CEO Gracy Chen has spent the days since trying to get someone — anyone — to freeze it.
The someone she wants is THORChain. On September 26, Chen formally asked the cross-chain protocol to refuse service to attacker addresses, writing that "decentralization is a design principle, not a shield for facilitating known stolen funds" and that "the industry is watching." THORChain's reply landed about as warmly as you'd expect.
What Bitget says happened
The exchange disclosed the breach on September 24 and pinned it on a backend system inside its wallet setup — not a stolen private key. That distinction matters to Bitget's users, but it doesn't change the money. Bitget's public tracker lists 2,377 attacker addresses holding $378 million, and 1,497 of them are marked as having moved funds through THORChain. Withdrawals, halted after the attack, are restarting in phases: BTC first, at 08:00 UTC on September 28.
There's some good news buried in the ledger. Chen thanked Circle and Tether for moving quickly to freeze about $318,000 tied to the hack, and Bitget is offering 5% bounties on frozen and recovered funds. Three hundred eighteen thousand against $387.5 million is a rounding error, but it's the first actual clawback on the board.
THORChain's answer: go ask Bitcoin
The protocol didn't blink. It responded that it's decentralized and permissionless, exactly like Bitcoin, Ethereum, and BNB Chain — then turned the question around, asking what responsibility those networks would bear in the same situation. It's a fair point wrapped in a frustrating non-answer for anyone trying to recover stolen funds. THORChain has spent its existence arguing it's infrastructure, not a sheriff. Being asked to act like one now is new territory.
Monahan wades in
Security researcher Taylor Monahan made the dispute personal, claiming the THORChain team has secretly reallocated assets before, failed to decentralize in seven years, been hacked seven times, and was built by North Korean IT workers. The Grok chatbot, asked to weigh in, called her claims partly accurate — citing at least three exploits in 2021 worth roughly $416 million and a paused lending product carrying about $200 million in liabilities. It found no evidence for the North Korea claims or for rug pulls done for operator profit. That's a messy scorecard, and it's now circulating far beyond the people who can actually verify it.
This has happened before
THORChain's own track record complicates its defense. In May, validators reportedly halted the network within hours of a $10.7 million exploit, and trading and withdrawals stayed unavailable for roughly five weeks, until June 22. So the chain can move fast when it wants to. Separately, MistTrack wrote that nearly $1.2 billion from the 2025 Bybit hack had already been traced through THORChain — meaning this is not the first time someone has asked the protocol to do something about dirty money flowing across it.
The immediate question is whether the remaining phased withdrawals come off without a hitch on September 28. After that, it's whether THORChain's validators hold the line on permissionlessness, or whether the pressure from a publicly named exchange changes what "decentralized" means in practice. Chen's letter asked for an answer. So far, she's gotten a philosophy lecture.




