The Bitget Hack and the $387 Million Question: Should a Public Chain Freeze Stolen Funds?

Bitget lost about $387.5M on September 24, 2026. NEAR Intents blocked $50M and froze $503K; THORChain refused to act. The fight is not about hacking — it is about who enforces the rules on a permissionless chain.
The Bitget Hack and the $387 Million Question: Should a Public Chain Freeze Stolen Funds?
Approval to move, or approval to stop? Photo: MarkBuckawicki, CC0, via Wikimedia Commons.

On September 24, 2026, attackers drained roughly $387.5 million from the crypto exchange Bitget. It was one of the larger exchange losses of the year — but the amount is not what turned it into the week’s loudest argument. What turned it into an argument was the money that came back, and the question of who decides, when stolen assets move across a permissionless network, whether anyone can stop them at all.

Two projects answered that question in opposite ways. THORChain, the decentralized cross-chain swap network that the attacker’s funds are being routed through, refused to intervene. NEAR Intents, a competing cross-chain system, quietly blocked more than $50 million in attempted transfers and froze about $503,000 of the proceeds. Both published a rationale. The rationales do not fit together.

The result is the cleanest test yet of a question the industry has deferred for years: on a public blockchain, is refusing to censor a stolen asset a principle, or an excuse?

Key takeaways

  • Bitget lost roughly $387.5 million on September 24, 2026 — not through stolen keys, but through forged withdrawal instructions written into its wallet system.
  • About $840,000, or 0.2% of the loss, was frozen: $318,000–$340,000 by Tether and Circle, and about $503,000 by NEAR Intents.
  • Stolen stablecoins were swapped into native tokens within 41 minutes and are being consolidated into Bitcoin, largely via THORChain.
  • THORChain refused to block attacker-linked addresses on the grounds that it is permissionless by design; NEAR Intents screened and blocked automatically.
  • The real dispute is not whether stolen funds should be spendable — everyone agrees they should not — but who should have the power to make that true, and under what rules.

What happened at Bitget

The attack was not a stolen key. Attackers wrote forged withdrawal instructions into Bitget’s wallet system, reportedly through a zero-day in a third-party security product. Bitget says its private keys and cold wallets were never compromised. That distinction matters, because it tells you where the weakness sat: not in the cryptographic backing of the money, but in the software that decides which transactions to sign.

What happened next was fast and mechanical. Within 41 minutes, the stolen stablecoins were swapped into native tokens across multiple chains, and the funds began consolidating into Bitcoin — largely through THORChain, a network built specifically to move value between chains without a central operator. The speed is the point. By the time any centralized issuer could act, most of the money had already left the tokens that can be frozen.

This is the modern template for a large exchange theft: take what can be moved fastest, convert it immediately into assets no one controls, and bridge it into the deepest, most liquid asset on the other side. Bitcoin is the exit because it has no issuer, no freeze function, and no compliance desk — and THORChain is the door because it has no gatekeeper either.

The $840,000 that came back

Of a $387.5 million loss, roughly $840,000 — about 0.2% — was frozen. Tether and Circle froze between $318,000 and $340,000 of stablecoins, using the centralized control each issuer keeps over its token. NEAR Intents added about $503,000. Everything else kept moving.

The ratio is the story. On a network where assets move without permission, the only recoverable money is the money that touches a system someone can switch off. Stablecoins have issuers; native tokens do not. Bitcoin has no switch at all. That is why the recovery rate on a cross-chain hack is not a measure of effort — it is a measure of how much of the stolen value happened to still be sitting in a form that a company controls.

The Bitget Hack and the $387 Million Question: Should a Public Chain Freeze Stolen Funds?
Chart: BBVN Markets. Source: incident reporting and on-chain analysis, late September 2026.

THORChain’s answer: we can’t, and we won’t

Bitget CEO Gracy Chen publicly asked THORChain to refuse service to attacker-linked addresses, warning that “the industry is watching.” THORChain declined. Its position is that it is “decentralized and permissionless like Bitcoin, Ethereum and BNB Chain,” and that it has no function to screen individual addresses or transactions by policy. That is presented not as a limitation but as the design itself — a claim made more credible by the fact that THORChain revoked its admin keys before the 2025 Bybit hack, deliberately removing its own off-switch.

Critics point to a contradiction. In May 2026, THORChain halted its chain after a vault exploit worth more than $10 million. If the network can pause for its own emergency, the argument goes, it can pause to stop laundering. THORChain’s reply is that a halt is a liveness decision by validators — a pause the protocol allows — whereas address-level censorship is a different act entirely, one the protocol does not support. That distinction is technically real and, to a victim watching funds walk out the door, entirely academic.

There is a deeper asymmetry here that both sides tend to skip. THORChain is not arguing it cannot build screening; it is arguing it should not. The engineering is not the hard part. The governance is: once you add a function that decides whose transfers to block, you have to answer who controls it, on what evidence, with what appeal, and how it behaves when a government asks for someone who is not a thief at all.

NEAR Intents’ answer: screening, not surveillance

NEAR Intents took the other path. It deployed SHIELD, an automated risk layer that flagged and blocked more than $50 million in attempted transfers tied to the hack, freezing about $503,000 mid-execution. Only around $166,000 slipped through. It also waived Bitget’s 5% recovery bounty, declining to profit from returning the money.

Its general manager, Alex Shevchenko, framed the choice in property terms: “Property rights are fundamental to functioning markets. A financial system where stealing an asset gives you an unrestricted right to monetize it isn’t a freer system — it simply protects the thief.”

The design detail matters more than the slogan. SHIELD is automated and rule-based, not a human compliance desk making discretionary calls. That is deliberate. A system that applies published rules to every transaction is arguably more defensible — legally and politically — than one where an operator decides, case by case, whose funds to freeze. The first looks like a protocol property; the second looks like a bank deciding whether to honor a withdrawal.

The legal fault line

Crypto lawyer Yuriy Brisov’s read is that demonstrated control may create liability: if a system can stop a transfer and chooses not to, that choice can be scrutinized. On this view, automated, rule-based screening is far more defensible than human adjudication, precisely because it is predictable and even-handed — the same rule fires for the same inputs, every time.

The libertarian counterpoint, from Dash’s Joël Valenzuela, is that if you can censor, you are no longer permissionless, and the ability itself “opens Pandora’s box” — because the next request will not be for stolen funds, but for something far easier to justify and far harder to reverse. Bitwise Europe’s Max Shannon split the difference: refusing to launder hack proceeds is a “sound stance,” and if THORChain will not do it, the laundering will simply migrate to THORChain and to every other venue that will not either.

Strip away the labels and the disagreement narrows to one sentence. Everyone agrees stolen funds should not be spendable. They disagree about who should hold the power to make that true — and about whether building that power in the first place is worth the risk of it being used for something else later.

Why this is not really about hacking

This is a debate about two architectures of a blockchain, and the hack is only the occasion.

  • The bearer model. Whoever holds the key holds the asset. No third party can reverse a transfer. Recovery is limited to what victims can negotiate and what law enforcement can seize at the edges — an exchange deposit, a fiat off-ramp, a frozen stablecoin.
  • The permissioned-in-practice model. Some operator — an issuer, a bridge, a venue — keeps the technical ability to screen and block, and uses it under a published policy. Transfers are still “yours,” but they pass through a system that can say no.

Stablecoins already live in the second model: every issuer can freeze, and did here. The question this week was whether the first model should quietly adopt the second’s tools. NEAR Intents said yes, with rules. THORChain said no, on principle. Both answers are internally coherent, and both carry a cost: the first accepts a censor that must be governed; the second accepts a thief who cannot be stopped.

The cross-chain blind spot

Cross-chain systems are where anti-money-laundering breaks down, and not by accident. On a single chain, a stolen asset is visible to everyone and spendable only by whoever holds the key; the one lever anyone has is a governance decision to freeze. When value crosses a bridge or a swap network, it passes through a component whose entire value proposition is that it does not ask who you are. The faster the bridge, the less time any counterparty has to react — and the 41-minute conversion window in the Bitget case is fast by design.

That leaves a shrinking set of chokepoints. In practice, recovery now depends on three things: stablecoin issuers that can freeze, centralized exchanges that run know-your-customer checks on deposits, and the small number of cross-chain venues willing to screen. Everything else in the stack is built to be indifferent. The Bitget case is instructive precisely because it exercised all three chokepoints and still recovered 0.2%.

What a rulebook would have to contain

NEAR Intents did not simply decide to be helpful; it implemented a policy. Anyone proposing that permissionless venues adopt screening has to answer five questions first:

  • The rule set. What evidence triggers a block — a law-enforcement list, an on-chain attribution, a victim’s assertion? Each carries a different error rate.
  • The operator. Who maintains the rules: the protocol’s validators, a foundation, or a third party? The answer determines how decentralized the network still is.
  • The appeal. How does an address prove it was wrongly blocked? Without an appeal process, screening becomes a permanent and unaccountable ban.
  • The scope creep. Today it is stolen funds. Tomorrow it is sanctioned entities, then politically exposed persons, then anyone a jurisdiction dislikes.
  • The exit. Can users move to a venue that does not screen? If yes, screening routes around itself; if no, permissionlessness was always a story.

These are not rhetorical objections. They are the reason automated, published, uniformly applied screening is easier to defend than case-by-case judgment: it answers all five by construction, even if imperfectly. A human compliance desk answers none of them on the record.

What to watch

  1. Where the funds end up. If THORChain remains the last open door, laundering routes concentrate there — turning a philosophy into a single point of failure that regulators and victims will target next.
  2. Whether THORChain changes its policy. Any move to add an address-screening hook, even an opt-in one, would signal that even the most permissionless venues are shifting under pressure.
  3. Whether cross-chain screening standards appear. An industry standard — automated, published, and applied uniformly — would resolve the legal-defensibility problem without leaving each operator to decide for itself.

FAQ

Did the attacker steal Bitget’s private keys?

No. Attackers wrote forged withdrawal instructions into Bitget’s wallet system, reportedly through a vulnerability in a third-party security product. Bitget says private keys and cold wallets were not compromised.

How much was actually recovered?

About $840,000 of roughly $387.5 million — around 0.2%. Tether and Circle froze between $318,000 and $340,000; NEAR Intents froze about $503,000.

Why could stablecoins be frozen but not Bitcoin?

Stablecoins are issued by companies that retain a freeze function; the token is a claim on an issuer. Bitcoin has no issuer and no freeze function, so once stolen value is swapped into BTC, there is no switch to flip — only addresses to watch.

What is THORChain’s argument?

That it is permissionless by design and has no mechanism to screen individual addresses or transactions. Pausing for its own liveness emergency, it argues, is a different act from address-level censorship.

What is NEAR Intents’ argument?

That property rights are foundational to a functioning market, and that automated, rule-based screening can stop laundering without giving a human operator discretion over whose funds to freeze.

Does freezing funds set a precedent for censorship?

That is the core of the objection. Critics argue that any freeze capability, once built, will be requested for purposes beyond stolen funds — sanctions, political pressure, or simple regulatory caution. Defenders counter that the capability already exists at the stablecoin and exchange layer, and that the only real choice is whether it is governed by published rules or by whatever the loudest request happens to be.

Is this a one-off?

No. As more value moves cross-chain, the question of who can freeze what will recur — and each incident becomes a precedent the next one cites. The 2025 Bybit hack already shaped THORChain’s design decisions; the 2026 Bitget hack will shape the next round.

Bottom line

The Bitget hack cost $387.5 million and returned about $840,000. The money is a rounding error; the fight is not. A permissionless network’s strongest claim — that no one can stop your transaction — is also its weakest, because no one can stop a thief’s either. NEAR Intents built a rulebook and enforced it automatically. THORChain refused to write one. The next hack will show which answer the market rewards — and which one regulators decide to test first.

Sources

Analysis

The CLARITY Act Failed. Crypto Now Runs on a Rulemaking Calendar.

2026-10-2 2:50:40

Analysis

How to Spot a Crypto Scam: Six Shapes, and the Step That Takes the Money

2026-10-3 14:00:50

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search