Centralized exchange Bitget reported unauthorized transfers totaling $387.5 million on September 25, with preliminary investigations linking the IP addresses to VPN services used by North Korean hacking groups. CEO Gracy Chen publicly called for decentralized exchange THORChain to block the associated addresses, arguing that decentralization should not shield known stolen funds. THORChain declined the request, citing its design principles, though cybersecurity experts noted the protocol had previously paused operations during its own May hack involving $10.7 million in losses. Despite the controversy, THORChain’s native token RUNE surged 50% over the week.
In regulatory news, SEC Commissioner Hester Peirce submitted her formal resignation from the US Securities and Exchange Commission, effective October 2. Known as "Crypto Mom," Peirce advocated for rules-based crypto regulation and criticized excessive KYC data storage, proposing zero-knowledge proofs as a privacy-preserving alternative. Separately, Vitalik Buterin outlined Ethereum’s evolution into a hybrid architecture integrating zero-knowledge proofs and parallel processing, describing it as moving beyond a traditional blockchain. Meanwhile, prediction market Kalshi lost an appeal regarding state gambling laws in Ohio and Tennessee, following conflicting circuit court rulings that may lead to Supreme Court review.
The clash between Bitget and THORChain highlights the persistent friction between centralized compliance expectations and decentralized protocol immutability. While Bitget seeks to mitigate reputational damage by externalizing responsibility for fund recovery, THORChain’s refusal underscores the operational reality that many DeFi protocols lack the technical or governance mechanisms to enforce blacklists without compromising their core value proposition. This incident tests whether institutional pressure can effectively coerce decentralized entities into adopting custodial-style controls, potentially reshaping how exchanges interact with on-chain liquidity providers during security breaches.
Peirce’s departure marks a significant transition in US crypto regulatory oversight, removing a prominent voice advocating for clear, technology-neutral frameworks. Her emphasis on zero-knowledge proofs as a solution to KYC vulnerabilities suggests a future where privacy-preserving verification becomes central to compliance infrastructure. As Ethereum evolves toward a hybrid cryptographic architecture and legal battles over prediction markets intensify across jurisdictions, the industry faces a complex landscape where technological innovation outpaces regulatory clarity, requiring stakeholders to navigate uncertain enforcement priorities and fragmented legal standards.


