A wallet associated with the Bitget hacker converted roughly $6.3 million worth of ether into bitcoin through THORChain on Monday, despite Bitget urging the cross-chain network to reject transactions from addresses connected to its $387.5 million theft.
CoinDesk reviewed THORChain’s publicly available transaction data and identified 27 successful swaps involving approximately 2,390 ETH exchanged for 75.2 BTC. The bitcoin from those completed transactions was sent to a single address. Another four swaps totaling 400 ETH were listed as pending in the data reviewed.
The transactions were submitted between approximately 03:55 and 06:23 UTC Monday from an Ethereum wallet that blockchain tracker Lookonchain had linked to the attacker. Most of the orders were placed in batches of about 100 ETH, with each transaction worth roughly $265,000 at the time.
THORChain Enables Cross-Chain Swaps
THORChain allows users to move between assets on different blockchains without using a centralized cryptocurrency exchange or creating an account.
That structure allows an attacker to deposit stolen ether and receive bitcoin at another wallet without sending the funds through a centralized platform that might be able to freeze them. Because THORChain transactions remain visible onchain, however, investigators can still track the movement of assets between networks.
Bitget suffered a breach on September 24 that resulted in approximately $388 million being stolen after an attacker bypassed security measures protecting the exchange’s wallets.
The exchange later said it had located and addressed the vulnerability, although it has not disclosed publicly how the attacker initially obtained access.
Bitget Asked THORChain to Block the Addresses
Bitget has published wallet addresses associated with the attacker and announced a 5% bounty for qualifying efforts to freeze or recover the stolen assets.
As the stolen funds began moving through other services, Bitget CEO Gracy Chen called on THORChain over the weekend to deny service to the identified addresses.
“Our attacker addresses are publicly listed and actively tracked. We are formally asking @THORChain to refuse service to these addresses,” Chen wrote on X, arguing that decentralization should not prevent platforms from responding to known stolen funds.
THORChain responded Monday by defending its open-access design and explaining that its emergency shutdown mechanisms are different from an address-specific blacklist.
The network said a halt is intended as an emergency security measure for protecting the protocol, rather than a tool for selectively freezing individual funds or blocking a particular swap.
THORChain’s Emergency Controls
THORChain operators have mechanisms capable of stopping trading across the network or limiting activity involving a specific connected blockchain, according to the project’s documentation.
Those controls can halt swaps across all supported chains or restrict transactions involving an individual network, such as Ethereum. However, activating such measures would also affect legitimate users conducting transactions through the same routes.
THORChain demonstrated those emergency controls in May after an attacker stole approximately $10.7 million from one of its own vaults, which hold assets used to facilitate cross-chain swaps.
Operators halted activity while developers investigated the incident and repaired the underlying vulnerability. Trading eventually resumed on June 22, around five weeks after the shutdown.
THORChain said the addresses connected to that May exploit were not blacklisted. The response was instead aimed at protecting the protocol itself, whereas Bitget is asking THORChain to reject assets stolen from an external exchange.
Some Hacker Transactions Were Only Partially Filled
Monday’s transaction records also indicate that the attacker ran into execution limits during some of the swaps.
Two 100 ETH orders were only partially completed because portions of the trades failed to satisfy the minimum price requirements specified by the orders. Approximately 114 ETH was subsequently returned to the originating wallet.
The transactions illustrate the challenge of tracing stolen cryptocurrency through decentralized cross-chain infrastructure: while the activity remains visible on public blockchains, the protocols involved may not have the same address-freezing mechanisms available to centralized exchanges.

More Stories
AI Agents Could Threaten Low-Cost Bank Deposits, Apollo Economist Warns
Bitcoin Slips to $83K as Altcoins Give Back Friday’s Gains
Crypto Bulls Pause as U.S. Jobs Data Takes Center Stage This Week