Bitget 希望封锁被盗资金。谁能让跨链网络合规?
核心要点
- The reported freeze is a small fraction of the revised loss Bitget announced a recovery bounty of 5% for eligible efforts to freeze directly affected

Bitget has asked THORChain to refuse addresses linked to a $387.5 million wallet breach. THORChain says its emergency halt is for protecting the network, not selectively freezing a user’s swap. The two positions expose different kinds of control: an issuer can immobilise its own stablecoin, an exchange can close an account, and THORChain node operators can pause routes. None is a universal switch for stolen assets once they cross networks.
Summary Bitget revised its September breach estimate from $351.6 million to about $387.5 million.
THORChain responded on Sept. 28 that a network halt is not a selective address freeze.
Circle and Tether reportedly froze 99,990 USDC and 218,023 USDT linked to the incident.
The two reported stablecoin freezes total 318,013 tokens, about 0.082% of the revised dollar loss.
A traced route moved through 4 blockchain stages before roughly 4 BTC reached a CoinJoin round.
The freshest dispute in Bitget’s recovery effort is a question of who controls the next transaction. CEO Gracy Chen called on THORChain to refuse service to addresses linked to the Sept. 24 breach. The protocol’s Sept. 28 public response distinguished the ability to halt its network from a mechanism that targets one address. GoPlus Security disputed the analogy THORChain drew with base chains, pointing to the validator set’s role in managing vaults and pausing network functions.
JUST IN: THORChain responds to calls to block Bitget exploiter addresses
THORChain says it is decentralized and permissionless like Bitcoin, Ethereum and BNB Chain, asking what responsibility those networks should bear when handling known stolen funds. https://t.co/ml6L9zVFR8 — crypto.news (@cryptodotnews) September 26, 2026
The dollar figure needs care. Bitget initially put the loss at $351.6 million, then raised its estimate to approximately $387.5 million after adding Zcash and TRON transactions identified in a fuller accounting. The revision is Bitget’s own estimate of assets moved to attacker-controlled addresses. It is not an independent final loss determination or a statement that another $35.9 million disappeared after the first disclosure. The company says customer balances remain intact and its protection fund will absorb the impact; those are company statements, not an independent audit of recovery.
There is no one entity called a cross chain network with authority over all of those assets. An attacker can hold a token whose issuer has a freeze function, exchange it for an asset without such an issuer, swap between native chains and seek a custodian willing to receive the proceeds. Each step leaves a different intervention point. Bitget’s request makes most sense when those points are separated.
The reported freeze is a small fraction of the revised loss
Bitget announced a recovery bounty of 5% for eligible efforts to freeze directly affected funds and another 5% for recovery. It said Circle and Tether had frozen 99,990 USDC and 218,023 USDT linked to the hack. At their dollar pegs, the two amounts sum to approximately $318,013. Divide that by $387.5 million and the reported freeze is about 0.082%, or roughly eight cents per $100 of the revised transferred-assets estimate.
That calculation is deliberately narrow. It does not say only $318,013 of the proceeds remains identifiable or that Bitget has recovered just that amount. The exchange says other affected assets have been frozen through partners but has not supplied an overall frozen-and-recovered total in the cited update. Its estimate covers multiple asset types and networks. A dollar-denominated numerator from two issuer actions and a broad incident denominator are useful for scale, not a complete recovery ledger.
The mechanisms are different too. A stablecoin issuer may have contract-level powers over a particular token. Freezing USDC at an address can prevent that address from sending the token under the issuer’s terms and controls. It cannot freeze native ETH or BTC merely because those assets were bought using USDC earlier. A centralised exchange can suspend a customer’s account or refuse a deposit tied to flagged addresses. It cannot reach into a self-custodied Bitcoin wallet outside its service. A protocol operator may halt some or all swaps, but that decision can interrupt innocent users alongside suspicious ones.
The strongest practical recovery method is therefore time-sensitive. Investigators identify addresses, follow swaps, pass information to the next issuer or custodial venue and obtain action while the asset is still within that party’s control. If a token has already been converted and withdrawn, the prior issuer’s freeze is too late for that leg. Tracking remains valuable, but tracing a coin and immobilising it are different achievements.
A swap passes through a vault, a consensus process and an outbound chain
THORChain’s technical description of native swaps starts when a user sends an asset, such as BTC, to a protocol vault on its native chain. Nodes observe that inbound transaction. The network prices the swap through its liquidity pools and prepares an outbound transaction in the destination asset. The vault’s outbound transfer is authorised using a threshold signature: multiple node participants contribute, while no one operator holds the whole key.
The protocol’s vault documentation is why the comparison with a simple wallet-to-wallet Bitcoin payment has limits. THORChain’s nodes collectively maintain infrastructure that receives the inbound asset and sends the outbound one. Individual nodes are not human clerks manually approving each swap. But the network does have operational settings that can pause activity on specified chains or globally. Those powers are described in THORChain’s network halt documentation.
A halt is a broad rule about processing. It can stop a route while a vault imbalance or exploit is investigated. An address blacklist is a narrower rule about who may use a route while other transactions continue. THORChain says the former exists and the latter is not its ordinary mechanism. GoPlus says the presence of node-controlled vaults and documented halts means the network is capable of taking responsibility for what passes through. The factual overlap is the ability to interrupt operations. The disagreement is whether that ability should become address-specific screening, and what modification to software and governance such screening would require.
You might also like: Bitget resumes BTC withdrawals after $388M hack
If a swap is still waiting in a queue, a timely pause could interrupt processing before outbound settlement. If the outbound transaction has already settled on Bitcoin, a later halt cannot reverse Bitcoin history. If the inbound has already entered a vault and trading halts, the user may face a delay or a refund process governed by protocol rules. The exact result depends on the transaction state and the halt used. A phrase like “freeze the funds on THORChain” is too vague to explain which asset is held where at the moment of intervention.
The same analysis applies to alternative routes. Stopping one swap venue does not stop a wallet from attempting another bridge, exchange or direct sale. A response across the entire market requires many independent actors to act in time. It may still block meaningful amounts, but it is not a command one team can issue to all chains.
The four-Bitcoin trail crosses several kinds of control
AMLBot traced roughly 4 BTC linked to the incident into a Wasabi CoinJoin round, according to a Sept. 27 report. Its described path began with assets on TRON, moved through USDT0 to Ethereum, used THORChain for an exchange into Bitcoin and then entered a CoinJoin round. That is one observed route, not the route taken by all $387.5 million or proof that every receiving address belongs to the same person.
The path gives a useful intervention map. On a stablecoin leg, the token issuer may be able to act on an address if the contract and legal conditions allow it. During a bridge or cross-chain transfer, the operator’s actual design matters. At THORChain, network operators can affect swap availability under the protocol’s halt controls. At a custodial exchange, account operators may stop deposits or withdrawals. Once native BTC is controlled by an external wallet, THORChain no longer controls that wallet’s balance, even if the BTC came from its outbound vault.
A CoinJoin combines inputs and outputs in a transaction designed to make straightforward tracing harder. It does not necessarily make every coin permanently untraceable or prevent a later custodian from asking a depositor about the funds. The public trail cited by AMLBot shows why investigators race to coordinate across asset types. Each conversion can change which party has a direct technical lever and which data are visible.
There is a ratio worth resisting. Four BTC is a count of one routed tranche. It cannot be divided into the whole incident without a timestamped BTC price, and even that would show only the share of the reported loss in that particular traced leg. The analytical value lies in the sequence of control points, not a claim that those four coins stand for the full hack.
BREAKING: Bitget reports $351.6 million hot wallet incident
The exchange says cold wallets are untouched, user funds are covered by its $464 million protection fund and withdrawals are paused while deposits and trading remain open pic.twitter.com/vxTXSTbJeK — crypto.news (@cryptodotnews) September 24, 2026
THORChain’s May halt proves one power and leaves another untested
THORChain halted functions after its own vault exploit on May 15, which was reported at roughly $10.7 million. Solvency checks identified an imbalance, and node operators later coordinated further measures. Crypto.news covered the 11-step restart plan and the eventual return of trading in June. The history disproves an absolute claim that THORChain cannot pause activity. Its documentation lists controls for chain-specific trading, signing and broader network functions.
It does not show that the system currently maintains a verified list of stolen-fund addresses and screens each inbound swap against it. Halting everyone is technically and economically different from refusing one identified user. A blacklist must specify which source addresses count, how wallets linked through transfers are added, who verifies evidence, who can appeal an incorrect entry and whether the rule applies to a token after it has changed hands. A mistaken designation could block an innocent holder. A narrow rule also invites the attacker to move funds to fresh addresses or use a different entry route.
GoPlus Security’s counterargument is strongest on governance. If a validator set already can coordinate a halt, it has some capacity to choose not to process a category of activity, even if the present mechanism is crude. THORChain’s answer is strongest on implementation. A broad emergency stop does not equal an existing selective freeze, and switching off a whole chain to block one address imposes a cost on unrelated swaps. These claims can coexist. Neither resolves the policy question of whether to add a screening rule and who would maintain it.
JUST IN: Circle and Tether freeze hacker wallet linked to $352M Bitget exploit
The wallet held about $318,000 in $USDC and $USDT. pic.twitter.com/medUQ3TTVb — crypto.news (@cryptodotnews) September 25, 2026
The May episode matters for a second reason. It shows how expensive a blanket interruption can be: trading did not simply resume the following block. Vault and key-share checks were part of the restart process, and liquidity users had to wait. A network security intervention to prevent more funds leaving an impaired vault is a different trade-off from a halt designed to intercept one external attacker’s route. The scale of harm to other users would have to be weighed in the latter case.
The same flagged address means different things on each chain
Bitget published primary receiving addresses for several networks, including EVM-compatible chains, XRP Ledger, Zcash and TRON, according to its recovery update. An address list is a starting set of observations, not a universal identity record. The same person can control many wallets, and a service can receive assets from many unrelated customers into one address. A screening policy that treats every address touched by a flagged wallet as equally culpable would quickly reach funds owned by people with no role in the breach.
The form of the address also changes the task. On Ethereum, an issuer may inspect a contract token balance at a particular account and exercise any freeze function the contract allows. On Bitcoin, a transaction spends specific outputs; there is no USDC-style token administrator to change the spendability of a native bitcoin. At an exchange, the relevant information may be the deposit attribution in the exchange’s own internal ledger, which an outside analyst cannot infer from a public wallet address alone. On a cross-chain swap, the incoming and outgoing addresses may be different because the vault receives the first asset and signs the second leg to a designated destination.
