Could THORChain face legal risk over stolen Bitget funds?
After suspected North Korean hackers exploited Bitget for $387.5 million, investigators traced the recipient addresses and Bitget CEO Gracy Chen publicly asked THORChain to “refuse service to these addresses.” THORChain said it is “decentralized and permissionless,” but the episode raises a very practical question for PSPs and DeFi infrastructure providers: once a protocol has the ability to intervene, does that create legal exposure as well as operational power?
- THORChain said it could not simply block the addresses because the protocol is decentralized and permissionless “like Bitcoin, Ethereum, and BNB Chain.” It also pointed out that its admin key has been retired, which means it does not have an easy way to censor addresses even if it wanted to.
- The controversy is not new. THORChain was previously used to swap around $1.2 billion of the funds stolen in the $1.46 billion hack of Bybit. In that case, its admin key had been retired just 11 days earlier.
- The protocol had also halted immediately in May when $10.7 million of its own funds were exploited. That detail matters because it shows the protocol can stop in one context, while claiming it has no practical control in another.
- NEAR Intents took the opposite approach. Its automated SHIELD program blocked addresses linked to the hack from swapping $50 million on the platform, and it even turned down the 5% bounty Bitget offered for doing so. The platform is now being criticized by decentralization maximalists for not being permissionless enough.
- Yuriy Brisov of D&A Partners said the legal position depends on the level of decentralization. In his view, if a protocol can block some addresses, that shows its nodes are not truly decentralized, and that same ability can open the door to claims that the protocol should also apply KYC and AML protective measures. He noted that “we are decentralized” remains the strongest defense for DeFi protocols.
For high-risk operators, the real takeaway is simple: the line between “cannot intervene” and “chooses not to intervene” can become the line between a technical explanation and a legal argument. Once a protocol demonstrates any ability to block or control flow, counterparties, investigators, and plaintiffs start asking what else it can do.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!