A wallet associated with the recent Bitget security breach transferred approximately $6.3 million worth of Ethereum into Bitcoin through the decentralized exchange THORChain. The transaction involved 27 swaps totaling 2,390 ETH exchanged for around 75.2 BTC, occurring between 03:55 and 06:23 UTC on Monday. This activity followed a public request by Bitget CEO Gracy Chen for THORChain to refuse service to addresses connected to the September 24 breach, which resulted in nearly $352 million being stolen.
THORChain rejected the request to freeze specific funds, stating that its emergency controls are designed to protect the protocol rather than selectively block individual wallets or swaps. The network noted that halting trading would impact legitimate users. While some swap orders were partially unfilled due to minimum price requirements, causing approximately 114 ETH to return to the sender's wallet, the majority of the conversion succeeded. Bitget has offered a 5% bounty for good faith attempts to recover the stolen assets, while blockchain researchers continue to trace the on-chain movements.
The incident highlights the friction between centralized exchange recovery efforts and decentralized infrastructure protocols. By utilizing THORChain, the attacker leveraged cross-chain liquidity to obscure the trail of stolen assets, moving them from Ethereum to Bitcoin without passing through a centralized intermediary. This underscores the operational challenge exchanges face when trying to contain breaches within the broader, permissionless crypto ecosystem, where individual nodes or protocols may not align with the compliance or recovery objectives of centralized entities.
From an institutional adoption perspective, this event serves as a stress test for the interoperability of decentralized finance (DeFi) tools with traditional security expectations. THORChain’s refusal to implement selective freezes reinforces its commitment to decentralization principles, even when faced with known malicious actors. However, it also exposes a gap in the market structure where legal recourse against stolen funds is limited by the technical design of underlying protocols. Stakeholders must now consider how regulatory frameworks might evolve to address such conflicts between privacy, decentralization, and asset recovery.

