GoPlus Security argued on Sept. 27 that THORChain should not compare its cross-chain architecture directly with decentralized Layer 1 networks such as Bitcoin and Ethereum, claiming validators can halt signing through emergency controls and threshold-signature vaults. The criticism came after the security firm linked portions of the September Bitget breach to flows moving through THORChain.
Bitget detected unauthorized transfers from portions of its hot and warm wallet infrastructure at 18:31 UTC on Sept. 24. Cold wallets were not affected. The exchange initially estimated the loss at $351.6 million before raising the figure to roughly $387.5 million after including Zcash and TRON transfers. GoPlus said its investigation found no private-key leak. Instead, attackers compromised a critical wallet backend, manipulated transaction data and caused Bitget’s authorized signing process to approve transfers the exchange never intended. The largest burst moved approximately $185 million in about one minute, while wider draining lasted around two hours and 25 minutes.
Bitget has not publicly confirmed that North Korean actors carried out its September attack, stating investigators had seen preliminary IP and VPN similarities associated with previous North Korean-linked activity but attribution remained unconfirmed. The exchange said it identified the attack path, remediated the flaw and brought in Mandiant and SlowMist to support the investigation. Bitget began offering recovery bounties and plans to restore withdrawals in stages from Sept. 28.
Blockchain analytics firm AMLBot traced one branch of stolen funds from a Bitget-linked TRON wallet through several assets and networks: TRX → USDT → USDT0 → Ethereum → about 145 ETH → THORChain → about 4.59 BTC → Wasabi CoinJoin. AMLBot said it blacklisted associated addresses and was monitoring remaining Bitcoin. GoPlus claimed around 101.5 BTC worth roughly $8.5 million had already exited through THORChain, while another 27.63 million XRP valued near $43 million was being routed toward Bitcoin. Those figures are GoPlus’s tracing, not confirmed by Bitget or THORChain.
GoPlus pointed to THORChain’s documented emergency mechanisms. Node operators can issue a pause command lasting 720 blocks, approximately one hour, and additional nodes can extend the halt. Node operators can then vote on targeted measures through Mimir, the protocol’s on-chain parameter system. THORChain used these controls during its own May exploit, when a malicious validator drained about $10.7 million from one Asgard vault by exploiting the GG20 Threshold Signature Scheme. The network halted within about two hours and remained offline for roughly five weeks before trading resumed June 23.
The dispute echoes the 2025 Bybit hack. The FBI attributed the theft of about $1.5 billion to North Korea and asked virtual asset services to block related transactions. Bybit CEO Ben Zhou said around 72% of roughly $900 million in converted assets had passed through THORChain. In February 2025, three validators briefly voted to halt Ethereum trading, but the action was reversed within minutes. GoPlus now argues THORChain should use its emergency framework for funds tied to addresses officially identified by agencies such as the FBI or OFAC, while THORChain’s documentation says not every third-party theft automatically requires a protocol halt.