The $387.5 million Bitget hack has turned into something larger than another crypto asset-recovery operation. It is forcing decentralized finance protocols to answer a question the industry has spent years avoiding: if a protocol can stop known stolen funds, does choosing to exercise that power create new legal responsibilities?
Bitget CEO Gracy Chen brought that question directly to THORChain after investigators identified addresses holding assets stolen in the September 24 attack. Chen publicly asked the cross-chain swap protocol to refuse service to the addresses, arguing that decentralization should not become a shield for facilitating known stolen funds.
THORChain refused.
“THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?”
The exchange says approximately $387.5 million ultimately reached attacker-controlled addresses, revising its initial estimate after additional Zcash and TRON assets were identified. Bitget says the attackers exploited a vulnerability in a third-party security product, obtained access to internal systems and used forged withdrawal instructions to bypass existing controls. Private keys and cold wallets were not compromised.
SlowMist and Mandiant have since conducted independent investigations broadly supporting the disclosed attack path. Bitget and security researchers have pointed to indicators consistent with previous North Korean operations, although Bitget has not published a final definitive attribution.
THORChain Says a Halt Is Not the Same as Censoring an Address
Critics immediately challenged THORChain’s position because the protocol has demonstrated that its network can be halted.
When THORChain itself suffered an approximately $10.7 million exploit in May, node operators used emergency controls to pause parts of the network while the vulnerability was addressed. That followed other examples across crypto where projects have taken extraordinary action after security failures, including Zano’s recent decision to roll back roughly a month of blockchain history following its Gateway Address vulnerability.
THORChain argues that the comparison is misleading. A network-wide security halt protects the protocol from malfunction or continued exploitation; it is not the same thing as selectively refusing transactions from particular users.
The distinction is technically meaningful.
THORChain removed its Admin Mimir capability with the February 10, 2025 mainnet upgrade, 11 days before the Bybit hack. No administrator now has a straightforward blacklist button capable of unilaterally rejecting a particular wallet. Operational controls instead sit with node operators, which can coordinate pauses through the protocol’s governance mechanisms.
So THORChain is not claiming that nothing can ever stop. Its stronger argument is that selective address censorship is not built into the protocol in the way it would be at a centralized exchange.
NEAR Intents Chose the Exact Opposite Model
NEAR Intents responded to the Bitget attackers very differently.
Its SHIELD risk-intelligence system identified more than $50 million in attempted flows associated with the stolen funds. NEAR Intents says most were rejected before execution, approximately $503,000 was frozen during execution and around $166,000 successfully passed through.
The system combines transaction-monitoring data and external intelligence to identify suspicious addresses automatically. Transactions can then receive no quote or be stopped while execution is underway.
NEAR Intents also waived the 5% recovery bounty Bitget was offering for funds successfully frozen or recovered.
The approach resembles the active intervention seen elsewhere after crypto infrastructure exploits: once operators believe stolen assets are moving through systems they influence, they choose containment over absolute neutrality.
That earned NEAR Intents praise from Bitget but criticism from decentralization purists. If a supposedly permissionless protocol can determine that one address should not receive service, critics ask what prevents the same infrastructure from eventually blocking sanctioned wallets, politically controversial users or addresses identified incorrectly by blockchain-analysis providers?
The Bybit Hack Already Put THORChain Through This Debate
THORChain faced almost the same controversy after the February 2025 Bybit hack.
U.S. authorities attributed that attack to North Korea’s TraderTraitor operation, and around $1.2 billion of the stolen assets was subsequently reported to have moved through THORChain as attackers converted Ether into Bitcoin and other assets.
Attempts by some node operators to pause Ethereum-related activity did not survive the network’s decentralized voting process.
The timing made the episode particularly significant: THORChain had eliminated its administrative control key just 11 days earlier.
The Bitget dispute therefore is not really about whether stolen cryptocurrency can be traced. Modern blockchain forensics can often follow funds through enormous numbers of transactions.
The harder question is who has both the technical power and legal responsibility to act once those funds arrive.
Control Can Protect a Protocol and Create a Legal Target
Crypto lawyer Yuriy Brisov of D&A Partners argues that THORChain’s strongest defense is the extent to which nobody actually controls it.
That creates an uncomfortable paradox for DeFi.
The more power developers retain to stop fraud, blacklist addresses or reverse harmful activity, the easier it becomes for someone to argue that those developers should have exercised that power in another situation.
If a platform can block a hacker, why did it not block a sanctioned wallet? If it can identify obviously stolen assets, should it also perform broader anti-money-laundering screening? If its operators can decide who receives access, at what point does a supposedly decentralized protocol begin looking more like an intermediary?
NEAR Intents attempts to navigate that problem through automation. SHIELD is designed to make risk decisions from predefined intelligence rather than requiring a compliance employee to manually approve or reject every transaction.
That may strengthen the argument that intervention is protocol behavior rather than discretionary custody, but automation does not make legal responsibility disappear. Someone still designs the rules, chooses intelligence providers and decides what happens when an address is flagged.
Tornado Cash Does Not Give DeFi Blanket Immunity
The Tornado Cash litigation is frequently invoked in this debate, but its meaning is narrower than some crypto commentary suggests.
In Van Loon v. Department of the Treasury, the U.S. Court of Appeals for the Fifth Circuit ruled that Tornado Cash’s immutable smart contracts were not “property” that could be blocked under the International Emergency Economic Powers Act because nobody could own, alter or control them.
That was an important decentralization ruling. It was not a declaration that every decentralized protocol is immune from sanctions, anti-money-laundering law or criminal liability.
The distinction matters enormously for THORChain because its architecture is not identical to an immutable Tornado Cash smart contract. THORChain uses validator-operated vaults and threshold signatures, and its nodes retain certain operational powers.
Exactly how a court would characterize that structure has not been tested in this context.
The Most Decentralized Outcome May Also Be the Least Comfortable One
This is where the Bitget dispute becomes genuinely difficult.
NEAR Intents’ response feels intuitively responsible. A hacker allegedly steals hundreds of millions of dollars, everyone can see the addresses, and the protocol refuses to help move the money. That sounds like an obvious win.
But it establishes that intervention is possible.
THORChain’s position is harder to accept emotionally because known stolen assets can continue moving. Yet removing discretionary control is exactly what permissionless infrastructure is supposed to accomplish.
Crypto cannot easily have both absolute censorship resistance and guaranteed intervention whenever the community agrees that intervention would be morally desirable.
We’ve already seen similar tensions when projects take drastic measures after their own security failures. A blockchain rollback can protect holders, but it also proves that supposedly final transactions can become negotiable when enough participants agree the circumstances justify it.
The Real Regulatory Test Will Be Who Actually Has Control
The Bitget case could eventually become an important test of how regulators distinguish software from financial intermediaries.
The useful question will not simply be whether a project calls itself decentralized.
It will be who controls the assets, who can alter the software, who can halt transactions, how many independent parties must cooperate, whether individual users can be selectively rejected and whether developers retain meaningful influence after deployment.
That makes THORChain and NEAR Intents almost perfect opposing experiments.
THORChain has deliberately removed administrative power and is defending the consequences of doing so. NEAR Intents has deliberately built automated controls and is defending the idea that permissionless infrastructure does not have to provide neutral passage for stolen property.
Neither model has received a definitive legal blessing.
And that may be the most important lesson from the Bitget hack. As DeFi becomes capable of moving hundreds of millions of dollars across chains in hours, decentralization is no longer only a philosophical argument about censorship resistance.
It is becoming a question of legal architecture.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

