THORChain spurns blacklist request tied to $387.5M Bitget hack as RUNE rallies
Bitget's CEO wants the cross-chain protocol to freeze hacker-linked addresses, but the network recently destroyed the admin key that could do it.
Illustration · generated, not a photograph
A week after a North Korean-linked hack drained $387.5 million from centralized exchange Bitget, cross-chain swap protocol THORChain has declined a public demand to blacklist the attacker's addresses — setting off a fierce argument over whether the network could comply even if it wanted to, and over just how decentralized it really is.
Bitget disclosed $351.6 million in unauthorized transfers on September 25, later revising the total to $387.5 million. Its preliminary investigation tied the attackers' IP addresses to VPN services associated with a North Korean hacking group. CEO Gracy Chen acknowledged that was not conclusive, but said investigators had identified other traits consistent with earlier thefts from the sector.
The hackers' playbook echoed the record $1.5 billion breach at Bybit, widely attributed to North Korea, after which much of the loot was laundered through THORChain swaps. Chen appealed directly to the protocol. "Decentralization is a design principle, not a shield for facilitating known stolen funds," she said. THORChain refused. Cointelegraph reported that the refusal ignited a broader dispute about whether compliance with such requests is technically possible or politically desirable; decentralization advocates, including Bitcoiner Joel Valenzuela, argued that freezing funds would betray crypto's founding principles.
Whether THORChain could act at all is doubtful. The protocol said in February 2025 that it had permanently removed the administrative key that would enable address blacklisting. Critics note, though, that THORChain's governance is far less distributed than Bitcoin's or Ethereum's. When hackers stole $10.7 million from THORChain itself in May, the network paused operations almost immediately through coordination. Cybersecurity researcher Tay* van put it more bluntly in widely shared comments, describing THORChain as a small group of developers coordinating privately, with substantial emergency powers, while collecting fees from the flow of stolen funds.*
Ironically, the controversy coincided with a price surge. THORChain's RUNE token climbed roughly 50 percent during the week.
Meanwhile, Ethereum co-founder Vitalik Buterin published a lengthy vision for the network's next phase, arguing it should evolve past its identity as a simple blockchain into what he called "the cryptographic world computer" — a hybrid system blending blockchains with zero-knowledge proofs, parallel processing, cryptographic privacy tools and post-quantum defenses. "It's really not just a blockchain anymore," Buterin wrote. He added that upcoming network upgrades — including the Hegota fork planned for next year — could mark the end of Ethereum's traditional hard-fork cycle.
Several prominent builders amplified the thesis. Coinbase CEO Brian Armstrong, who infrequently weighs in on Ethereum topics, boosted a detailed analysis from a smaller account that argued Buterin's framing effectively redefines the term "onchain." Aave founder Stani Kulechov said Ethereum's verifiability features could extend far beyond finance applications, reducing reliance on trusted intermediaries across many use cases.
Elsewhere in the industry, SEC Commissioner Hester Peirce — nicknamed "Crypto Mom" for advocating clearer digital-asset rules — formally announced her resignation, effective October 2. In a Friday post on X sharing her departure letter, Peirce criticized the industry's growing practice of stockpiling customer identity documents online, calling such databases a hack magnet that adds little enforcement value. She pointed instead toward zero-knowledge tools that let institutions verify a user's eligibility without seeing their personal details. She has reportedly accepted a position at Regent University's law school in Virginia beginning in November.
Source reporting
The outlets whose reporting this account was written from.
Written from the reporting and primary documents credited at the foot of this story. Facts are credited to the outlet or document that established them. How Chainpress works



