Could THORChain face prosecution over stolen Bitget funds? Legal opinion
After a suspected North Korean group stole $387.5 million from crypto exchange Bitget, Bitget asked THORChain to refuse service to addresses linked to the theft. THORChain replied that it is permissionless and cannot easily censor addresses; crypto lawyer Yuriy Brisov told Magazine that legal exposure depends on how decentralized a protocol actually is and whether any blocking is automated or manually controlled.
Why It Matters
The dispute highlights a growing legal tension in DeFi between preventing illicit activity and preserving decentralization as a defense against liability. How courts treat selective blocking or retained control by protocols could affect future obligations around AML/KYC and technical design choices across the sector.
Key Facts
- Hack amount: $387.5 million
- Requester: Bitget CEO Gracy Chen asked THORChain to refuse service to addresses tied to the hack
- THORChain response: Said it is decentralized and permissionless and compared itself to Bitcoin, Ethereum, and BNB Chain
- THORChain admin key: Retired in February 2025
- THORChain prior incident: Protocol halted in May when $10.7 million was exploited
Following a $387.5 million theft from Bitget attributed to suspected North Korean hackers, Bitget publicly urged THORChain to block addresses receiving the stolen funds. THORChain answered that it is a decentralized, permissionless protocol and questioned what obligations chains like Bitcoin or Ethereum should bear when known stolen funds are transacted. The exchange’s request and the protocol’s reply reopened debate about whether DeFi projects can — or should — censor tainted addresses.
THORChain’s position is complex because the protocol retired its admin key in February 2025 and operates with a large validator set, which the core team says limits its ability to perform address-level censorship. The protocol had previously been halted in May after a separate $10.7 million exploit, and investigators note THORChain was used to move roughly $1.2 billion of funds in the $1.46 billion Bybit hack — an episode that coincidentally followed retirement of THORChain’s admin key.
NEAR Intents, by contrast, used an automated system called SHIELD to block addresses linked to the Bitget hack and prevented about $50 million from being swapped on its platform. NEAR declined Bitget’s offered 5% bounty and has since faced criticism from decentralization purists for taking a permissioned, interventionist stance. The two responses illustrate the trade-offs between automated protective measures and claims of full permissionlessness.
In an interview with Magazine, crypto lawyer Yuriy Brisov said the legal exposure of a protocol depends on how much control it demonstrably retains. If a project shows it can and does block addresses, that evidence can undermine a decentralization defense and open the project to broader legal claims, including expectations around due diligence, KYC, and AML. Brisov distinguished automated, non-manual systems — like SHIELD — as more likely to support a claim of decentralized operation than manual, discretionary interventions.
Brisov also noted that technical design matters: an oracle-driven automatic block triggered without human intervention is less likely to be seen as centralized control than a manual process where people press a button to block addresses. He said that with THORChain’s retired admin key and a hundred validators, it is "more likely than not" to be considered sufficiently decentralized, though he did not assert that as definitive. The debate underscores how protocol design choices on censorship and automation could shape future legal liability for DeFi platforms.
Keep Reading

Singapore crypto activity grows 55% as broader region contracts

Evernorth clears shareholder vote ahead of Nasdaq debut with 473M XRP treasury

Bitget ‘gradually back to usual’ as protection fund reaches $309M
