A wallet tied to the Bitget breach moved roughly $6.3 million in ether into bitcoin through THORChain on Monday, even as Bitget asked the cross-chain network to block addresses associated with the $387.5 million theft.
CoinDesk’s review of THORChain’s public transaction data found 27 completed swaps involving approximately 2,390 ETH for 75.2 BTC. The bitcoin received from all 27 transactions was directed to the same address. Four other transactions totaling 400 ETH were still shown as pending in the records examined.
The orders were submitted between roughly 03:55 and 06:23 UTC on Monday from an Ethereum wallet that blockchain analytics firm Lookonchain had identified as connected to the attacker. Most of the transactions involved approximately 100 ETH, equivalent to around $265,000 per swap at the time.
Stolen ETH Moves Through THORChain
THORChain provides cross-chain asset swaps without requiring users to create accounts or deposit funds with a centralized exchange.
That setup enables someone holding stolen ether to exchange it for bitcoin and send the resulting BTC to another wallet without first passing through a centralized platform that could potentially stop the transaction. At the same time, the underlying blockchain transactions remain public, allowing researchers to trace the flow of funds.
Bitget was breached on September 24, with the attacker stealing approximately $388 million after circumventing security protections around the exchange’s wallets.
The exchange later said it had discovered and fixed the security vulnerability but has not publicly explained the specific method used to compromise the wallets.
Bitget Presses THORChain to Reject the Funds
Following the breach, Bitget released addresses linked to the attacker and announced a 5% bounty for eligible attempts to freeze or recover the stolen assets.
As the funds began moving through external services, Bitget CEO Gracy Chen publicly appealed to THORChain over the weekend to stop processing transactions from the identified addresses.
Chen said the addresses were already public and being monitored, and asked THORChain to refuse service to them. She also argued that decentralization should not be treated as a reason to facilitate transactions involving known stolen assets.
THORChain responded Monday by drawing a distinction between its emergency network controls and a selective address blacklist.
The protocol said its ability to halt the network exists to protect THORChain during security emergencies. It is not designed to freeze particular funds or prevent an individual user from executing a specific swap.
Emergency Halts Affect Broader Activity
THORChain does have mechanisms that can suspend swaps across the entire network or restrict activity involving a particular blockchain, according to its documentation.
For example, operators can halt all cross-chain swaps or limit transactions involving Ethereum. Such measures, however, would also prevent unrelated users from completing legitimate transactions through the affected routes.
The protocol previously used these emergency mechanisms in May after an attacker stole about $10.7 million from one of THORChain’s own vaults.
Operators paused trading while developers investigated the incident and fixed the vulnerability. Swaps resumed on June 22 after roughly five weeks.
THORChain said it did not blacklist the addresses associated with that attack. Instead, the halt was intended to protect the protocol from an active security incident, while Bitget’s current request concerns funds stolen from an external centralized exchange.
Hacker Encounters Swap Restrictions
The Monday transaction history also shows that not every attempted swap was completed in full.
Two orders involving 100 ETH each were partially filled after portions of the transactions failed to satisfy their required minimum prices. Around 114 ETH was returned to the wallet that initiated the swaps.
The episode highlights the difference between transaction visibility and intervention capabilities in decentralized infrastructure. Although THORChain activity can be traced publicly across blockchains, its operating model does not provide the same type of account-level freezing mechanism available to centralized exchanges.

































