
A wallet associated with the Bitget hacker exchanged approximately $6.3 million in ETH for Bitcoin through the THORChain network. This occurred after THORChain rejected a request from the exchange to halt addresses linked to the attack that took place on September 24. The wallet completed 27 exchanges, converting about 2,390 ETH into 75.2 BTC. Bitget requested THORChain to deny transactions from addresses it believed belonged to the attacker. However, THORChain explained that its emergency measures could stop network activity but could not freeze an individual exchange. As a result, Bitget raised its estimate of assets transferred to addresses controlled by the attacker to $387.5 million.
Analysts from the CoinDesk platform, who analyzed THORChain's transaction records, noted that the 27 completed exchanges sent all 75.2 BTC to a single receiving address. The orders came from an Ethereum wallet that blockchain tracker Lookonchain identified as part of the attack activity. Four other transactions totaling 400 ETH were pending when CoinDesk conducted its analysis. The exchanges took place between approximately 03:55 and 06:23 UTC on Monday, with most orders consisting of 100 ETH each. CoinDesk estimated each batch to be worth approximately $265,000. The completed transactions exchanged about 2,390 ETH for 75.2 BTC, with the pending 400 ETH not included in this amount. While THORChain rejected Bitget's request to block the attacker's addresses, Bitget CEO Gracy Chen issued a statement asserting that decentralization should serve as protection against known stolen funds and cannot be used as an excuse to ignore it.
The Bitget case also drew attention to the issue of THORChain's system design, which is based on decentralization and permissions. THORChain indicates that stopping the network – is an emergency security tool to protect the protocol, not a selective freeze of specific funds or individual exchanges. The controversy is exacerbated by OKX founder Mingxing Xu pointing out differences in THORChain's validator model and threshold signature compared to Bitcoin's basic design. In response to the incident, Bitget raised the damage estimate from the breach to approximately $387.5 million, identifying new assets that were not included in the initial estimate. The exchange halted withdrawals after detecting unauthorized transfers and engaged Mandiant and SlowMist for further checks. Nevertheless, Bitget continues to ensure the security of its cold wallets and assets. As a recovery measure, Bitget announced a 5% reward program for efforts aimed at freezing and returning the stolen assets. The exchange has already notified the freezing of attack-related funds in USDC and USDT at Circle and Tether, respectively. A phased reopening program is planned; Bitcoin withdrawals are expected on September 28 at 08:00 UTC, with additional ETH and USDT withdrawals scheduled for September 29 and 30, respectively. The final phase for all other tokens and services will be set for October 2.



