What to Know
- A wallet linked to the Bitget hacker swapped about 2,390 ETH, worth about $6.3 million, into 75.2 BTC through THORChain on Monday.
- Public transaction records showed 27 successful swaps, with all bitcoin payouts sent to one address.
- Four additional swaps involving 400 ETH were marked pending in the reviewed records.
- The orders were submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet identified by blockchain tracker Lookonchain as part of the attacker’s activity.
- Most swaps were submitted in roughly 100 ETH batches, worth about $265,000 each.
- Bitget lost about $388 million in a Sept. 24 breach and has said it identified and fixed the vulnerability.
- The exchange has offered a 5% bounty for eligible efforts that freeze or recover stolen funds.
- Bitget CEO Gracy Chen asked THORChain to refuse service to publicly listed attacker addresses.
- THORChain rejected selective blacklisting, saying a network halt is an emergency security mechanism, not a targeted freeze for individual funds or swaps.
- Monday’s records also showed some execution friction, including two 100 ETH orders that were only partly filled after portions failed to meet their specified minimum price, returning about 114 ETH to the sending wallet.
Hacker-Linked Wallet Converts Ether Into Bitcoin
A wallet linked to the Bitget hacker converted about $6.3 million in ether into bitcoin through THORChain on Monday, intensifying scrutiny of how decentralized liquidity networks handle funds tied to major exchange breaches. The swaps moved about 2,390 ETH into 75.2 BTC, with public records showing 27 successful transactions and the bitcoin proceeds routed to a single address.
The movement followed the Sept. 24 breach at Bitget, where the exchange lost about $388 million after an attacker bypassed security controls protecting exchange wallets. Bitget has since said it identified and fixed the vulnerability, though it has not publicly explained in detail how access was gained. The exchange has also published attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen funds.
The latest swaps highlight a familiar tension in crypto markets: decentralized networks can provide open access and censorship resistance, but that same structure can complicate recovery efforts after hacks. THORChain allows users to exchange assets across different blockchains without an account at a centralized exchange. In practice, a user can send ether from an Ethereum wallet and receive bitcoin in a different wallet, without relying on a conventional trading venue that could freeze the account or block the transfer.
Records Show 27 Successful Swaps
The public transaction records reviewed by FXCOINZ showed 27 swaps marked successful, exchanging about 2,390 ETH for 75.2 BTC. Four additional swaps involving 400 ETH were marked pending in the response reviewed. The records covered orders submitted between about 03:55 and 06:23 UTC on Monday from an Ethereum wallet identified by blockchain tracker Lookonchain as part of the attacker’s activity.
Most of the orders were submitted in roughly 100 ETH batches, each worth about $265,000. Splitting activity into repeated batches can help traders manage execution, liquidity, and slippage across automated systems, though in this case the movement is drawing attention because of the wallet’s alleged connection to the Bitget breach. The swaps remained visible on public ledgers, meaning investigators and analysts can continue tracking movement across chains even when no centralized platform is involved.
Monday’s activity also showed that decentralized swapping does not guarantee smooth execution at any price. Two 100 ETH orders were only partly filled after portions failed to meet their specified minimum price. About 114 ETH was returned to the sending wallet. For market participants, that detail underscores the role of trading limits and price protection mechanisms even in cross-chain swap infrastructure.
Bitget Presses for Address Blocking
Bitget’s response has centered on public tracking, recovery incentives, and pressure on infrastructure providers to avoid processing funds linked to the attacker. The exchange has listed attacker addresses and offered a 5% bounty for eligible efforts that freeze or recover stolen assets. As the attacker moved funds through other services, Bitget CEO Gracy Chen publicly asked THORChain to refuse transactions from the identified addresses.
Chen wrote that the attacker addresses were publicly listed and actively tracked, and said Bitget was formally asking THORChain to refuse service to those addresses. She also argued that decentralization is a design principle, not a shield for facilitating known stolen funds. The appeal captured a broader industry debate over whether decentralized protocols should build mechanisms that distinguish ordinary users from wallets publicly tied to hacks, exploits, or stolen assets.
For centralized exchanges, the operational answer is usually straightforward: they can freeze accounts, reject deposits, comply with law enforcement requests, or blacklist addresses in internal monitoring systems. Decentralized protocols face a different set of trade-offs. Any ability to block a specific wallet can create governance, neutrality, and technical questions. Some users see selective intervention as a necessary response to theft, while others view it as incompatible with permissionless infrastructure.
THORChain Defends Its Policy
THORChain’s public response on Monday defended its open-access policy and drew a sharp distinction between emergency shutdown controls and a targeted address blocklist. The project said a THORChain network halt is an emergency security mechanism designed to protect the protocol. It added that a halt is not a selective freeze of specific funds or an individual swap.
The protocol does have controls that can interrupt trading under emergency conditions. THORChain documentation describes settings that can stop swaps across connected blockchains or restrict activity involving a particular chain, such as Ethereum. But using those tools would also interrupt other users’ transactions on the affected routes. That is central to THORChain’s position: its available controls are broad safety mechanisms, not instruments for freezing one wallet while leaving the rest of the network untouched.
THORChain’s stance means the protocol is not treating the Bitget breach as grounds for selective blacklisting. Instead, it is emphasizing that a network halt is reserved for threats to the protocol itself, not for disputes or thefts involving external platforms. That distinction is likely to remain controversial, particularly when the funds are publicly identified and actively tracked.
Past Emergency Halt Shapes the Debate
THORChain has previously used emergency controls when its own infrastructure was at risk. In May, the network used emergency controls after an attacker stole about $10.7 million from one of its vaults, the accounts holding assets used for swaps. Operators coordinated a shutdown while developers investigated and repaired the vulnerability. Trading resumed June 22 after roughly five weeks.
THORChain has said the May attacker’s addresses were never blacklisted. The project framed that intervention as a protocol-protection measure rather than a targeted freeze. In the Bitget case, by contrast, the stolen funds came from an outside exchange. THORChain’s position is that halting or restricting the network to block a third-party attacker would affect unrelated users and would not match the purpose of its emergency controls.
The difference matters because decentralized finance protocols often rely on governance or operator coordination only for exceptional situations. If those tools are used to intervene in external incidents, market participants may begin to question where the line is drawn. If they are not used, exchanges and victims may argue that open protocols are enabling stolen funds to move across chains more easily.
Cross-Chain Swaps Remain Visible but Hard to Stop
THORChain’s architecture creates both traceability and resistance to conventional enforcement. The swaps are publicly visible, so blockchain investigators can monitor the path from ether into bitcoin. However, the absence of an account-based centralized intermediary limits the ability to stop the movement once a wallet submits a transaction and the protocol processes it.
That makes cross-chain liquidity networks an important battleground in post-hack fund flows. Attackers often seek to move assets away from the chain where the theft occurred, especially when addresses are flagged by exchanges and compliance tools. Converting ether into bitcoin can make recovery more complex because investigators must follow funds across different networks and address formats. Still, public blockchains preserve transaction trails that can support future tracing, attribution, and potential recovery efforts if funds later touch venues with blocking authority.
For Bitget, the immediate challenge is that publicly identifying addresses does not automatically prevent decentralized activity. For THORChain, the challenge is reputational and philosophical: maintaining permissionless access while responding to criticism that open rails can be used by wallets tied to known stolen funds. The Monday swaps show that this debate is not theoretical. It is playing out in live transactions involving millions of dollars and publicly tracked attacker wallets.
Market Implications for Crypto Infrastructure
The incident arrives at a time when crypto infrastructure providers continue to face pressure to balance decentralization, user protection, and compliance expectations. Centralized exchanges, bridges, swap networks, and wallet providers each occupy different points on that spectrum. The more a system depends on accounts, operators, and custodial controls, the easier it is to freeze activity. The more a system relies on permissionless smart contracts and validator-driven settlement, the harder it becomes to single out one participant without affecting broader network activity.
Technical traders and on-chain analysts are likely to keep watching the bitcoin address that received the payouts, along with any remaining ether associated with the sending wallet. The pending swaps involving 400 ETH and the returned 114 ETH from partly filled orders may also remain in focus, depending on whether the wallet attempts additional conversions or moves funds elsewhere.
For the wider market, the key issue is not the price of ether or bitcoin in isolation, but the operational resilience and governance philosophy of cross-chain liquidity. The Bitget-linked swaps through THORChain show how quickly stolen funds can seek new forms and new networks, while also demonstrating that public ledgers allow those movements to be observed in detail. Whether observation is enough, or whether decentralized systems should offer stronger blocking tools, remains one of the most difficult questions facing the industry.
Frequently Asked Questions (FAQs)
What happened with the Bitget-linked wallet on THORChain?
A wallet linked to the Bitget hacker swapped about 2,390 ETH, worth about $6.3 million, into 75.2 BTC through THORChain on Monday. Public records showed 27 successful swaps, with all bitcoin payouts sent to one address.
How many swaps were successful?
The reviewed public transaction records showed 27 swaps marked successful. Four additional swaps involving 400 ETH were marked pending in the records reviewed.
When were the swap orders submitted?
The orders were submitted between about 03:55 and 06:23 UTC on Monday. They came from an Ethereum wallet identified by blockchain tracker Lookonchain as part of the attacker’s activity.
Why did Bitget ask THORChain to block the addresses?
Bitget lost about $388 million in a Sept. 24 breach and has published attacker addresses. The exchange asked THORChain to refuse service to those addresses as part of its effort to freeze or recover stolen funds.
What bounty has Bitget offered?
Bitget has offered a 5% bounty for eligible efforts that freeze or recover stolen funds. The offer is part of the exchange’s response after the breach.
Why did THORChain reject selective blacklisting?
THORChain said its network halt mechanism is an emergency security tool designed to protect the protocol. It said a halt is not a selective freeze of specific funds or an individual swap.
Can THORChain stop trading activity?
THORChain has controls that can interrupt swaps across connected blockchains or restrict activity involving a particular chain, such as Ethereum. However, those controls would also affect other users’ transactions on the affected routes.
Has THORChain used emergency controls before?
Yes. In May, THORChain used emergency controls after an attacker stole about $10.7 million from one of its vaults. Trading resumed June 22 after roughly five weeks.
Were all of Monday’s ETH orders fully executed?
No. Two 100 ETH orders were only partly filled after portions failed to meet their specified minimum price. About 114 ETH was returned to the sending wallet.
