Back to news

Bitget CEO Gracy Chen: Requests THORChain to Refuse Service to Attack Addresses

Bitget CEO Gracy Chen stated that the addresses of attackers related to the platform's security incident have been made public and are under continuous tracking. She officially requests THORChain to refuse service to these addresses.

She wrote that decentralization is a design principle and should not serve as a shield for facilitating the flow of known stolen funds. The entire industry is watching how THORChain handles this. On September 24 at 18:31 (UTC), Bitget discovered unauthorized transfers from its hot and warm wallets, initially reporting an amount of approximately $351.6 million, which was later revised to about $387.5 million after accounting for Zcash and TRON, with cold wallets unaffected. The company stated that the attacker accessed the wallet backend, forged transaction data, and triggered internal authorization, while the private keys themselves were not stolen, with the method highly consistent with patterns associated with North Korean organizations.

The user protection fund reported over $464 million to cover the gap. Stablecoin issuers have frozen part of the USDT and USDC. On-chain visibility shows that stolen assets entered the THORChain vault for exchange and cross-chain transactions, with large amounts of XRP appearing with notes. She also mentioned last year's Bybit theft case, where nearly $1.2 billion reportedly passed through the same protocol. OKX also stated that security is not a competition but a shared responsibility.

In market mechanisms, buyers aim to convert stolen funds from marked chains to attack addresses with hard-to-freeze assets, while sellers provide cross-chain liquidity for these addresses under permissionless rules. The event was driven by exchanges making the list public and naming the protocol. Beneficiaries are centralized issuers that can freeze assets and tracking networks with established bounties, while those under pressure are cross-chain nodes that insist on protocol neutrality and may continue to process blocks for known addresses. Funds are seeking Bitcoin and other exits through cross-chain exchanges from hot wallets.

Public tracking shows that most stolen positions remain in marked addresses, with a small portion completing exchanges.

Source: Public Information

ABAB AI Insight

Gracy Chen escalates the theft of a hot wallet due to backend authorization fraud into a public ruling on cross-chain protocol governance. Bitget can change its risk control but cannot alter THORChain's permissionless exchanges. Naming amounts to requiring nodes to selectively refuse known addresses, rewriting "decentralization" from a technical attribute to a moral stance. The memory of approximately $1.2 billion bridging in the Bybit old case is used to prove this is not the first time, but rather the same exit being used repeatedly.

The capital path involves stolen funds first scattering to multi-chain addresses like ETH, BTC, XRP, ZEC, and then exchanging through THORChain's memorandum into harder-to-freeze Bitcoin. Exchanges use protection funds to internalize user losses, then outsource tracking to the entire industry with a 5% freeze and 5% recovery bounty. Stablecoin issuers can freeze contract balances, but native coins and cross-chain exchanges cannot. If the protocol cooperates, it effectively acknowledges that on-chain neutrality yields to list politics; if it does not cooperate, friction between centralized exchanges and cross-chain infrastructure shifts from private coordination to public judgment.

The benchmark is the node split after Tornado Cash sanctions, the freezing competition between mixers and exchanges, and the temporary interceptions by various chain foundations after the Bybit theft. The industry is moving from "post-event tracking" to "requiring protocols to pre-screen addresses."

Structural changes belong to industry self-enforcement before regulatory changes. Without a court order, there is first a public opinion order. The mechanism is that the theft of hot wallets externalizes centralized custody risks to the permissionless liquidity layer; if decentralization refuses to look at the list, it becomes the last mile for stolen funds; if it accepts the list, it turns into a bridge with scrutiny. Pricing power shifts from protocol neutrality to who controls the list of stolen addresses.

ABAB News · Cognitive Laws

  1. Decentralization can block censorship but cannot block named lists.
  2. What can be frozen is contract balances, but cross-chain exits cannot be frozen.
  3. Protection funds buy users but cannot buy the protocol's neutral stance.

Source

·ABAB News
·
5 min read
·5 hrs ago
分享: