Home/news/Bitget Urges THORChain to Block Wallets Linked to $387.5 Million Hack
news
Bitget Urges THORChain to Block Wallets Linked to $387.5 Million Hack
Payments High Risk
30 Sep 2026 · 2 min read
Bitget CEO Gracy Chen has asked THORChain to stop processing transactions tied to wallets linked to the exchange’s $387.5 million breach. The practical issue for high-risk crypto operators is familiar: once stolen funds move through permissionless infrastructure, recovery becomes a coordination problem, not just a security one.
Bitget said it detected unauthorized transfers from parts of its hot and warm wallet infrastructure on September 24. The exchange first put the loss at $351.6 million, then raised it to approximately $387.5 million after including transactions involving Zcash and TRON.
According to Bitget, the attackers did not obtain private keys. The exchange said a backend system in its wallet infrastructure was compromised, which allowed attackers to manipulate transaction data and trigger Bitget’s own authorization process. The stolen assets were spread across Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BNB Chain and Base.
Bitget said around $102.9 million worth of XRP made up the largest share of the stolen assets. The exchange also said its cold wallets were not affected, and that customer balances are covered by a protection fund exceeding $464 million.
The exchange said it has been working with Mandiant, SlowMist and law enforcement agencies. It has also launched a 5% recovery bounty and set up a public tracker for recovered funds, which is the sort of operational detail compliance and recovery teams actually care about when a breach goes public.
Some of the stolen crypto has already moved through THORChain and been converted into Bitcoin. Chen said Bitget formally asked the cross-chain protocol to block the identified attacker addresses. THORChain replied that its infrastructure is permissionless, drawing a line between its model and centralized exchanges that can freeze withdrawals or block specific users.
Bitget has preliminarily linked the attack to patterns associated with North Korean hacking groups, though no government has officially attributed the incident. TRM Labs and Elliptic also identified connections between the stolen funds and wallets previously associated with North Korean laundering activity. Bitget began restoring withdrawals in stages, with Bitcoin withdrawals reopening on September 28 and other assets scheduled to follow through October 2.
The broader point for PSPs and crypto infrastructure providers is not subtle: decentralized routing does not stop sanctions pressure, recovery demands, or attribution work. It just changes where the friction lands.