The attacker behind Bitget’s $387.5 million hack has converted roughly $6.3 million of stolen ether into bitcoin through THORChain, after the swap protocol publicly refused the exchange’s request to block the attacker’s wallets. THORChain’s own transaction records show 27 successful swaps moving about 2,390 ETH into 75.2 BTC, with every bitcoin payout landing at a single address.
Bitget lost the funds in a Sept. 24 breach after an attacker bypassed the security controls protecting its exchange wallets. The company has since said it identified and fixed the vulnerability but has not explained publicly how access was gained. It published the attacker’s addresses, offered a 5 percent bounty for freezing or recovering stolen funds, and reopened customer withdrawals this week.
The swap records cover orders submitted between roughly 03:55 and 06:23 UTC from an Ethereum wallet blockchain tracker Lookonchain tied to the attacker. Most orders came in batches of about 100 ETH, worth around $265,000 each. Four additional swaps involving another 400 ETH were still pending in the records CoinDesk reviewed. Two 100 ETH orders were only partly filled after portions failed to meet their minimum price, returning about 114 ETH to the sending wallet, a sign the attacker is running into the protocol’s liquidity limits as well as its politics.
The request and the refusal
Bitget CEO Gracy Chen made the block request on Saturday, posting on X: “Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses. Decentralization is a design principle, not a shield for facilitating known stolen funds.”
THORChain’s answer came Monday, in public: “A THORChain network halt is an emergency security mechanism designed to protect the protocol. A halt is not a selective freeze of specific funds or an individual swap. THORChain is permissionless and doesn’t censor by design.”
The distinction is technical but real. THORChain’s operators can trigger emergency halts that stop swaps across every connected chain or restrict activity on a particular chain, such as Ethereum. The project used exactly that power in May after an attacker stole about $10.7 million from one of its own vaults, coordinating a five-week shutdown while developers repaired the vulnerability. Trading resumed June 22, and RUNE, the protocol’s token, had dropped 12 percent during the halt. What THORChain cannot do, the team says, is freeze one address or one transaction, because no such control exists in the protocol at all.
The difference between the two cases is who got robbed. The May halt protected THORChain itself. Bitget is asking the network to reject funds stolen from a third party, and the protocol’s position is that this is not a job it is built for, and that building it in would change what the network is.
Why bitcoin, and why it works
Converting stolen ether into bitcoin through THORChain is a known laundering path, and it works because the protocol requires no account, no identity check and no cooperation from any company. An attacker sends in ether from one chain and receives bitcoin on another without touching a centralized exchange that could block the transfer. Once the funds are bitcoin, no issuer can freeze them, and mixing services become the next hop rather than any exchange.
The swaps stay publicly visible, which is cold comfort for investigators but real comfort anyway: the full trail remains traceable across both chains, and bitcoin’s transparent ledger means the coins can be followed even if they cannot be stopped. Blockchain tracker MistTrack points out this exact playbook ran after the $1.46 billion Bybit hack last year, when nearly $1.2 billion was traced through THORChain the same way. Exchanges have had some success blacklisting bitcoin addresses tied to that theft, but the coins themselves kept moving.
Where the funds can still be caught
Bitget is not out of options. The attacker has already been blocked elsewhere: NEAR Intents reported its SHIELD system stopped more than $50 million in attempted transfers tied to the same theft, and those funds remain stuck on the NEAR side of the attempted swaps. That system screens destination addresses against known hack-linked wallets and rejects the transfers before settlement, an approach THORChain has rejected as a matter of design rather than capability.
The contrast between the two protocols is now the clearest illustration yet of a split running through decentralized finance, between systems that build in the ability to interdict flagged funds and systems that treat any such ability as a design flaw. Neither camp is small, and the Bitget case gives both a live test case to point at: NEAR can show $50 million frozen, THORChain can show a network that behaved exactly as its documentation promised.
For Bitget customers, the immediate picture is better than it was. Withdrawals resumed with USDT transfers reopening at 08:00 UTC, and customers pulled a record $463 million in the first day, a run the exchange covered without interrupting service. Its reserve report shows 131 percent coverage, though the protection fund has fallen below $200 million, a figure that will matter if the attacker keeps converting and confidence wobbles again. The fund exists to cover shortfalls in exactly this kind of event, and it has already taken a hit from the breach.
Chen’s bounty offer stands at 5 percent of whatever is frozen or recovered. On $387.5 million, that is nearly $19 million for whoever finds a lever THORChain says does not exist. The remaining stolen ether sits in tracked wallets, and every conversion the attacker makes from here is another public record of where the money went.
