BNB $764.79 -2.02%
XRP $1.51 -1.15%
ETH $2,684.47 -0.92%
BTC $83,505.14 -1.74%
BNB $764.79 -2.02%
XRP $1.51 -1.15%
ETH $2,684.47 -0.92%
BTC $83,505.14 -1.74%
BREAKING
Bitcoin News

Bitget Hacker Converts $6.3M in ETH to Bitcoin via THORChain Amid Urgent Plea

THORChain Lets Bitget Hacker Swap 2,390 ETH for 75.2 Bitcoin in 27 Trades
THORChain Lets Bitget Hacker Swap 2,390 ETH for 75.2 Bitcoin in 27 Trades

Community Trust ScoreVerified

80%
Real
Verified10 votes
Updated 3 hours ago

A wallet tied to the Bitget hack moved fast. On Monday, it ran roughly $6.3 million worth of ether through THORChain and came out the other side with bitcoin — while Bitget’s CEO was publicly begging the network to stop it.

The transaction data, tracked by Lookonchain, tells a pretty clear story. Twenty-seven successful swaps converted about 2,390 ETH into 75.2 BTC, all routed to a single bitcoin address. The orders came in batches of around 100 ETH each — about $265,000 a pop. And four more swaps involving 400 ETH were still sitting in pending review when the records were pulled. The attacker’s Ethereum wallet was the origin point for all of it.

Not everything went smoothly for the hacker, though.

Advertisement

Two of those 100 ETH orders got only partially filled. Price constraints hit the swap limits built into THORChain’s system, and roughly 114 ETH ended up returned. It’s a small wrinkle, but it’s worth noting — the platform’s internal mechanics do create some friction, even if they’re not built to stop anyone specifically.

Bitget’s $388 Million Breach and the Blocklist Request

The breach itself happened on September 24. Bitget lost about $388 million in what the exchange called a significant security incident. The exchange has since patched the vulnerability. But it’s stayed quiet on exactly how the attacker got in — no detailed breakdown, no technical post-mortem shared publicly.

What Bitget did do: it published the attacker’s wallet addresses and dangled a 5% reward for anyone who could help freeze or recover the stolen funds. CEO Gracy Chen went further. Over the weekend, she reached out directly to THORChain, asking the network to reject transactions from those flagged addresses. Her position was direct — decentralization shouldn’t be a tool that makes it easier to move stolen money.

THORChain said no.

The network’s response was measured but firm. Its emergency shutdown controls exist for broad, protocol-level security threats — not to freeze specific wallets. A blocklist, per THORChain’s own statement, isn’t what those controls are for. And using a halt on targeted routes would cut off all users on those paths, not just the one bad actor. That’s the line THORChain drew.

THORChain’s No-Blocklist Policy Isn’t New

It’s consistent with how THORChain handled its own crisis, back in May. The network suffered a $10.7 million theft from its vaults — its own funds, not a user’s. Developers shut the whole thing down to investigate. Operations came back online on June 22. But even then, even when the money stolen was THORChain’s, the attacker’s addresses weren’t blacklisted. The network went wide — a full halt — rather than surgical.

That precedent matters here. Chen’s request wasn’t unreasonable on its face, but it ran straight into a wall that THORChain built deliberately. The network doesn’t do selective freezes. That’s not a bug in the policy. It’s the policy.

What makes THORChain useful is also what makes it frustrating in moments like this. It lets users swap assets across blockchains without a centralized account, without KYC, without a middleman who can be called on a weekend and asked to freeze something. The hacker knew that. That’s probably why THORChain was the venue of choice.

The transactions are transparent — Lookonchain tracked them in real time, batches visible, destination address visible, amounts visible. But visibility and intervention are two different things. You can watch the money move. You can’t stop it, not on a network that’s built to resist exactly that kind of outside pressure.

Centralized exchanges have faced this tension for years. When a hack hits a platform like Bitget, the instinct is to call every counterparty and ask them to lock things down. That works sometimes — other centralized exchanges might comply, stablecoin issuers can blacklist addresses, some bridges have admin keys. THORChain doesn’t operate that way, and it’s been pretty upfront about that.

The 5% recovery bounty Bitget offered is still out there. Whether anyone can actually help recover funds that have already been converted from ETH to BTC and sent to a fresh address — unclear. Bitcoin transactions don’t reverse. The address is known, but knowing where money went and getting it back are very different problems.

Bitget hasn’t said publicly whether it’s pursuing any other recovery channels, legal or technical. No details on law enforcement involvement. No named blockchain forensics firm attached to the case, at least not in anything the exchange has shared.

The hacker converted $6.3 million on Monday. Four more swaps were still pending.

Frequently Asked Questions

How much ETH did the Bitget hacker convert through THORChain?

The attacker swapped approximately 2,390 ETH for 75.2 BTC across 27 successful transactions, worth roughly $6.3 million, all directed to a single bitcoin address.

Why didn’t THORChain block the hacker’s wallet addresses?

THORChain said its emergency controls are designed for broad protocol-level halts, not selective address blocking — a stance consistent with how it handled its own $10.7 million vault theft in May, when it shut down network-wide rather than blacklisting the attacker.

Why It Matters

This incident highlights the ongoing challenges of security and liquidity in decentralized finance (DeFi) ecosystems, as hackers increasingly exploit vulnerabilities to convert stolen assets into more stable cryptocurrencies like Bitcoin. The rapid movement of funds from the Bitget hack through platforms like THORChain raises concerns about the effectiveness of existing measures to trace and recover stolen assets, as well as the potential implications for investor confidence in crypto exchanges and DeFi protocols. Additionally, such high-profile hacks underscore the need for enhanced security protocols within the crypto space to protect users and maintain market integrity.

Community Trust IndexModerate Confidence
80%
Real
Real80%20%Fake
10 community signals

James Thorp

James Thorp is a passionate crypto journalist from South Africa specializing in Litecoin, Dash, and emerging digital assets. With years of experience covering the crypto markets, James delivers in-depth analysis and breaking news on altcoins, blockchain adoption, and decentralized payment networks for The Currency Analytics.

Advertisement

Related Stories