Following the September 24th security breach that drained $351.6 million from Bitget, attackers have begun converting stolen Ethereum into Bitcoin using the decentralized exchange THORChain. Blockchain investigator ZachXBT reported that these illicit actors are chain-hopping assets across bridges and directing them toward privacy-focused mixing services like Wasabi to obscure their origins. The exploit involved high-level internal credentials being used to insert fraudulent withdrawal commands, bypassing normal risk controls without compromising private keys.
Bitget CEO Gracy Chen stated in a September 28th livestream that the attack was likely linked to North Korean groups based on matching IP and VPN patterns. While Bitget has contained the incident and resumed BTC withdrawals, it faced resistance when urging THORChain to block attacker addresses. THORChain rejected the request, citing its permissionless design which prevents selective censorship of transactions. User funds remain protected by Bitget’s $464 million User Protection Fund, with cold wallets unaffected by the breach.
The utilization of THORChain by Bitget hackers highlights a critical tension between centralized exchange security needs and decentralized protocol neutrality. By leveraging cross-chain swaps, attackers can fragment audit trails and move value into less transparent layers of the crypto ecosystem, such as mixing services. This incident underscores how sophisticated threat actors exploit the interoperability of DeFi infrastructure to launder large sums quickly, challenging the ability of centralized entities to recover assets once they leave the platform's direct control.
From an institutional adoption perspective, the refusal of THORChain to censor specific transactions reinforces the immutability principles central to decentralized finance but raises operational risks for exchanges relying on such networks. The debate involving OKX founder Mingxing Xu regarding validator models versus base-layer designs illustrates the ongoing fragmentation in regulatory expectations for DeFi protocols. As investigations continue with firms like Mandiant and SlowMist, the market will watch whether this event accelerates calls for hybrid compliance mechanisms or further entrenches the divide between permissioned and permissionless financial rails.


