# protocol exploit — X 热门讨论 (2026-09-27 04:48 UTC)

## @anndylian (Anndy Lian) · 09-27 01:24 · ♥31 ↻15 💬3 Blaming @THORChain and saying they are not helpful and decentralized will not solve the problems.

Let’s me break this down.

Technical actions are possible to stop it but just are not precise enough.

THORChain nodes can halt trading, halt signing of outbounds, or pause an entire connected chain.

More likely a single node can pause trading for about an hour; a few more nodes can extend it. Operational parameters like these only need a handful of node votes (sometimes as few as three) to take effect. They have used exactly these tools before, including during their own May 2026 exploit.

What they cannot do easily is surgically block only the flagged Bitget or Bybit addresses the way a centralized exchange can.

There is no built-in per-address blacklist at the protocol level. Stopping those specific funds would require either:

- halting all swaps on the relevant chains (ETH, BNB, etc.), which punishes every user, or

- shipping a code upgrade that adds address filtering, then getting two-thirds of nodes to run it.

Nodes are supposed to stay anonymous and the protocol is built to be permissionless, so coordinated, selective censorship is deliberately hard. That is the actual constraint and not that “nothing can be done.”

The choice they have made so far is to treat those blunt tools as last-resort emergency measures, not as a way to police known stolen funds.

PS: I am not a fan of THOR and I am not against ABY and Slowmist. Just sharing my fair opinion.

We cannot use a centralized mind to fault a somewhat decentralised solution. And then flip it our advantage. > 引用 @MistTrack_io: THORChain and Stolen Funds: The Industry Needs Answers

After the $1.46B @Bybit_Official hack last year, nearly $1.2B in stolen funds was reportedly traced through @THORChain as the attackers moved assets across chains.

Today, following another major security incident at @Bitget , we are once again observing Bitget Exploiter funds being sent into the THORChain for asset swaps and cross-chain transfers.

The question is no longer:

“Does THORChain know these funds are associated with hackers?”

The attacker addresses have already been publicly flagged and are being actively tracked by exchanges, blockchain security/aml firms, and the wider crypto industry.

The real question is:

When a protocol is aware that funds originate from a publicly identified major hack, yet continues to facilitate large-scale cross-chain swaps, how should the industry view this under the banner of “decentralization”?

Decentralization should not become a blanket excuse when dealing with known stolen funds.

If, after every major crypto hack, attackers can continue using THORChain as a route to move funds from ETH → BTC, BNB → BTC, and across other chains, the industry needs to seriously ask:

What responsibility should THORChain bear when handling known stolen funds? @GracyBitget @xiejiayinBitget @benbybit https://x.com/anndylian/status/2104019311572783269