The furious debate over Bitget’s $387.7M of hacked funds comes down to whether ideals around “permissionless and decentralized” tech means never intervening — even if you could. After Bitget got hacked on Sept. 24, $387.5 million of stolen funds quickly began moving across chains, with some headed to decentralized cross chain swaps platform THORChain. Chief executive Gracy Chen publicly appealed to the platform to refuse service to attacker-linked addresses. “The industry is watching,” she said. Yet THORChain refused. And that refusal has kicked off a furious debate between those who believe protocols have a moral obligation to block stolen funds, and those hold the cypherpunk ideals of decentralized, permissionless technology sacrosanct. Having previously watched on as the Bybit hackers funneled $1.2 billion through the protocol, it’s pretty clear which side of the argument THORChain is on. Developer Boone Wheeler tells Magazine: Critics argue that THORChain wasn’t quite so idealistic when validators voted t...
Ether withdrawals are scheduled to return Tuesday and USDt on Wednesday as Bitget restores services following last week’s $388 million hack. Crypto exchange Bitget is resuming withdrawals after a security breach affecting nearly $388 million in assets, as the attacker continues moving stolen crypto through THORChain. Bitget said it resumed Bitcoin (BTC) withdrawals Monday after suspending them following last week’s security incident, with additional assets and networks set to follow over the coming days. The Sept. 24 breach compromised part of Bitget’s hot and warm wallet infrastructure, while its cold wallets remained secure, according to the exchange. Read more
THORChain refuses to blacklist addresses linked to the Bitget hack. Vitalik Buterin says Ethereum is evolving from being a mere blockchain, into a world cryptographic computer. Stop me if you’ve heard this before: A centralized exchange with lax security gets hacked by the North Koreans for $387.5 million, and then somehow shifts the blame game onto a decentralized exchange for not blacklisting the addresses. The drama began on September 25 when the Asian focused exchange Bitget revealed $351.6 million in “unauthorized transfers” but it later upgraded the tally to $387.5 million. It said a preliminary investigation had linked the IP addressees to VPN services used by a North Korean hacking group. While that isn’t firm proof, CEO Gracy Chen said its investigators had flagged other similarities with previous thefts. North Korean hackers were believed to be behind the $1.5 billion Bybit exchange hack, and much of the funds from that attack were then swapped on the decentralized exchange THORChain (which is not a...
The third-wave Coldcard exploiter moved about 10% of stolen funds through THORChain as researchers traced the assets to a new Ethereum address. A hacker linked to the third wave of Coldcard wallet thefts has started swapping stolen Bitcoin for Ether through THORChain. Galaxy head of research Alex Thorn took to X on Wednesday to report that the third-wave exploiter moved about 10% of the stolen funds, with 90% remaining untouched. Thorn said it marked the first time funds from any of the three waves had moved onchain from the original hacker addresses. “The hacker appears to be having some issues swapping all the funds through THORChain — they keep getting refunded and he keeps retrying,” he said. Read more
The $10.7 million THORChain exploit was caused by a GG20 vulnerability, which allowed a malicious node to reconstruct a full private key to one of its vaults. THORChain said a malicious node operator exploited a vulnerability in its GG20 threshold signature system to drain about $10.7 million from one of the protocol’s vaults. The GG20 threshold signature scheme is used to secure THORChain vaults by splitting key control across multiple node operators, meaning no single node normally holds the full private key. The vulnerability allowed the malicious node operator to reconstruct a full private key for one vault, through “progressive key material leakage,” the protocol said in a post-mortem report released on Wednesday. Read more
THORChain has launched a recovery portal following a $10 million exploit, allowing affected users across four chains to revoke malicious approvals and claim refunds. THORChain has confirmed a $10 million exploit and launched a recovery portal, giving affected users a self-custodial path to revoke malicious token approvals and submit refund claims backed by a treasury-provisioned refund pool of equal size. In a Saturday post on X, THORChain Foundation introduced the recovery portal, saying that “affected users are now able to check what they will be paid as compensation following the exploit.” The portal, citing a PeckShield post-mortem, claims that the attack was detected at 02:14 UTC on May 11, when node operators flagged anomalous outbound transactions. Trading and outbound signing were paused within eight minutes. In total, attackers drained 36.75 BTC, worth around $3 million, and approximately $7 million in tokens across BNB Chain, Ethereum and Base, hitting 12,847 wallets across four chains. Read more
THORChain paused trading after ZachXBT flagged a suspected $10 million exploit spanning Bitcoin, Ethereum, BNB Chain and Base. Decentralized liquidity protocol THORChain halted trading after blockchain investigator ZachXBT flagged a suspected exploit of more than $10 million. A THORChain alerts Telegram channel showed all trading and signing halted, with a global node pause extended until block 26191149, or roughly 12 hours and 42 minutes. The halt came shortly after ZachXBT said the protocol had likely been exploited across Bitcoin, Ethereum, BNB Chain and Base. A wallet labeled by Arkham as the THORChain exploiter showed $10.8 million in holdings, transferred across several smaller transactions in the 30 minutes before 10:11 am UTC. Read more
The wallet linked to the Kelp DAO exploit appears to have laundered most of the $175 million worth of stolen Ether, while another $71 million remains frozen by Arbitrum’s security council. The exploiter behind the roughly $293 million Kelp DAO hack appears to have laundered nearly all of the unfrozen Ether stolen in the attack, narrowing recovery efforts to the tranche Arbitrum’s security council managed to freeze. The Kelp Dao hacker appears to have laundered nearly all of the 75,700 Ether (ETH) stolen from the protocol on Saturday. The hacker primarily used the THORChain to swap the Ether for Bitcoin (BTC), generating about $910,000 in fee revenue for the protocol, according to blockchain analyst EmberCN in a Thursday X post. The attacker began moving the funds on Tuesday, sending roughly 75,700 ETH, worth about $175 million at the time, into newly created wallets before routing the assets through THORChain and privacy protocol Umbra. Arkham data showed the attacker’s tagged main wallet had been largely emp...