CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

THORChain Refuses to Block Bitget Hack Funds: AML and Accounting Implications

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING THORChain Refuses to Block Bitget HackFunds: AML and Accounting Implications

THORChain, the decentralised cross-chain liquidity protocol, has formally declined to block wallet addresses tied to the theft of more than $380 million from centralised exchange Bitget. The refusal places the protocol at the centre of a widening debate about whether "permissionless by design" is a coherent compliance position or a convenient excuse, and it creates concrete audit and AML documentation obligations for any accounting firm or CFO whose clients touch DeFi.

THORChain Refuses to Block Bitget Hack Funds: AML and Accounting Implications

What Happened: The Bitget Hack and THORChain's Response

Bitget suffered a major breach that its CEO, Gracy Chen, described as "highly consistent with known patterns of North Korean hacker organisations." On-chain analysts drew connections to wallet clusters associated with prior state-linked thefts, and a blockchain security firm supporting Bitget's tracing effort publicly appealed to THORChain to act, arguing that "decentralisation should not become a blanket excuse when dealing with known stolen funds."

THORChain's stated position

THORChain acknowledged being "devastated" by the hack but held that it is "decentralised and permissionless." It drew a comparison to Bitcoin, Ethereum, and BNB Chain, questioning whether those base-layer networks would be expected to halt when stolen funds transited them. The protocol made no move to block the flagged addresses.

Why that comparison is contested

THORChain's own history undercuts the analogy. In May, after the protocol itself was exploited for approximately $10 million, its validators voted to pause trading. That halt was reactive and self-protective, but it demonstrated clearly that THORChain's validators can and do intervene when motivated to do so. The protocol has since argued the pause was about protecting the system rather than censoring a specific actor, and that it has never selectively blacklisted any address. Critics, however, read the two episodes together as evidence of a double standard: the protocol acts when its own treasury is at risk, but not when a third party's stolen funds are flowing through it at volume.

The BNB Chain precedent is also instructive. Following a significant exploit in 2022, BNB Chain validators did halt the chain, successfully preventing the attacker from extracting the bulk of the stolen assets. The outcome showed that validator-governed networks are capable of coordinated intervention; the question is whether they choose to apply that capability.

The Volume Spike: $678 Million in Two Days

THORChain's own data tells a striking story. In the two days immediately following the Bitget breach, the protocol processed $678 million in swap volume. In the week before the hack, daily volume had been running at $20 million to $60 million. That surge translated into close to $1.2 million in gross system income over the same window.

A recurring pattern

This is not the first time THORChain has seen volume spike after a major theft. When the Bybit exchange was hacked in February of the prior year, a significant portion of the funds moved through THORChain swaps. That episode triggered a similar governance debate, and a former THORChain developer publicly resigned from the project in response. More recently, volume spiked again following an April exploit of Kelp DAO worth approximately $280 million, with on-chain investigators noting the pattern in real time. The repeated correlation between large thefts and THORChain volume is now a documented feature of the post-exploit laundering playbook, not an anomaly.

AML Implications for Accounting Firms and CFOs

For firms that handle crypto-native clients, this episode is not background noise. It has direct consequences for how you document counterparty risk, structure AML procedures, and advise clients on DeFi interaction.

The "permissionless" defence does not transfer to regulated entities

THORChain may be able to argue, within its own governance framework, that the protocol has no gating mechanism. That argument is irrelevant to a regulated accounting firm or CFO. If a client's funds pass through a protocol that processed known stolen assets linked to a sanctioned actor, the compliance question is not whether the protocol had a blacklist. The question is whether the firm conducted adequate counterparty due diligence before that interaction occurred, and whether it can demonstrate that in writing.

Financial Action Task Force guidance on virtual assets is clear that the risk-based approach applies to all points in the transaction chain accessible to regulated entities. "Decentralised" does not mean "outside scope." FATF's guidance on DeFi explicitly covers situations where a DeFi protocol has identifiable controlling parties or profit-generating validators, both of which THORChain demonstrably has.

Sanctions screening and tainted-fund tracing

Bitget's CEO and multiple on-chain analysts have publicly attributed the hack to a North Korean-linked threat group. North Korea's cyber units operate under active OFAC, UK OFSI, and EU sanctions designations. Any regulated firm that processes, records, or audits transactions that can be traced to those funds without first conducting sanctions screening is exposed. The fact that the transit route was a permissionless DEX aggregator does not create a safe harbour.

Firms should review whether their crypto compliance reporting procedures include a documented protocol for flagging client positions or transactions that intersect with known exploit wallets, and whether they retain evidence of that screening. For context on how centralised stablecoin issuers handled the same event, see our piece on how Circle and Tether froze stablecoins in response to the same Bitget hack. The contrast is instructive: centralised issuers moved within hours; a protocol generating millions in fees from the resulting volume flow did not.

Audit trail obligations for DeFi-touching clients

If your client used THORChain swaps in the period following the Bitget breach, you have an obligation to determine whether those swaps involved tainted assets. The on-chain record is public. Blockchain tracing tools can identify whether a client's transaction interacted with wallets in the flagged cluster. That analysis should be completed, documented, and retained. Any crypto accounting software or digital asset accounting software your firm uses should be capable of pulling the raw transaction data needed to support that trace; if it is not, that is a gap to address before the next engagement.

For the detailed background on the breach itself, our full breakdown of the Bitget breach and its AML accounting implications covers the initial classification and the steps firms should take at the client-asset level.

Governance Risk: What THORChain's Inconsistency Signals

Beyond the immediate AML question, this episode surfaces a structural risk that firms should be pricing into their DeFi due diligence: the governance unpredictability of validator-controlled protocols.

Validators as a governance variable

THORChain's validators chose to pause the protocol in May to protect their own economic interests. They chose not to act in September when the reputational and legal pressure came from outside. That asymmetry is relevant to any firm assessing whether a DeFi protocol is a reliable, governable counterparty. If validator economic incentives align with inaction, inaction is what you should expect, regardless of the external harm being caused.

For accounting and audit purposes, this means that DeFi protocol risk assessments cannot rely solely on stated design principles. They need to account for how the validator community has actually behaved in past crises, what economic incentives drove those decisions, and whether the outcome aligned with the stated principles. In THORChain's case, the answer to that last question is, at best, contested.

Reputational and regulatory contagion risk

Regulators across the FATF member jurisdictions are watching episodes like this closely. If enforcement action eventually targets a DeFi protocol for facilitating the movement of state-linked stolen assets, any regulated entity with documented exposure to that protocol during the relevant period will need to demonstrate that its compliance procedures were adequate at the time. "We did not know the funds were tainted" is a weak defence when the information was publicly available from on-chain analysts within hours of the breach.

THORChain Refuses to Block Bitget Hack Funds: AML and Accounting Implications

Practical Steps for Compliance and Audit Teams

Three actions are worth prioritising now, regardless of whether your clients have a direct THORChain position.

Review and update DeFi counterparty risk classifications

Protocols that have demonstrated willingness to facilitate large-volume flows in the immediate aftermath of a publicly attributed state-linked hack should be flagged in your risk register. That does not necessarily mean advising clients to exit those protocols, but it does mean the risk classification needs to reflect observed behaviour, not just stated design.

Establish a post-exploit triage procedure

When a major DeFi exploit is publicly attributed to a sanctioned actor, your firm should have a documented procedure for checking client exposure within a defined window. That procedure should include: identifying whether any client wallet interacted with flagged addresses or routed through the affected protocol in the relevant period; escalating any hits for legal review; and retaining the evidence of both the check and its outcome.

Verify your crypto bookkeeping software captures DeFi flows

Many crypto bookkeeping software implementations handle centralised exchange data well but under-capture DeFi interactions, particularly cross-chain swaps conducted through aggregators. If your tooling does not pull THORChain swap history into the audit trail automatically, that is a manual gap that needs a documented workaround until it is resolved. The transaction volume data THORChain itself published after the Bitget hack underscores how significant those flows can be in a short window.

Source: Protos

Frequently Asked Questions

Does THORChain's permissionless design give regulated firms a compliance exemption?

No. Regulated entities are bound by their own jurisdiction's AML and sanctions obligations regardless of how the underlying protocol is architected. If a client's transaction can be traced to funds linked to a sanctioned actor, the firm's obligation to screen and report is triggered at the point the firm has access to that information, not by the protocol's governance model.

What is the significance of THORChain's $678 million volume spike?

The volume data, published by THORChain itself, confirms that the protocol processed a materially elevated flow of assets in the immediate days after the Bitget hack. For compliance teams, that data point is relevant when assessing whether a client's THORChain activity in that window warrants additional scrutiny and tainted-asset tracing.

How should auditors treat DeFi swap transactions in their working papers?

Each cross-chain swap should be documented with the originating wallet, the destination wallet, the protocol used, the timestamp, and the asset values at the time of the transaction. Where a swap occurred on a protocol that processed known tainted funds in the same period, the working papers should include a note on the screening performed and its outcome.

Is THORChain under any obligation to screen for OFAC-designated addresses?

THORChain itself, as a decentralised protocol, does not hold a regulated status in most jurisdictions and does not operate under a traditional compliance framework. However, any centralised entity, exchange, or firm that interacts with THORChain and is registered in an FATF member jurisdiction remains subject to its own sanctions screening obligations for transactions it facilitates or records.

What does this episode mean for firms evaluating DeFi protocol risk?

It reinforces that governance behaviour in past crises is a better predictor of future conduct than stated design principles. Firms conducting DeFi due diligence should review a protocol's actual validator decisions during previous exploits, not just its documentation. Where validator incentives favour inaction in the face of external harm, that should be reflected as an elevated risk classification in the firm's counterparty register.

GLOBAL#defiEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Lazarus Group Behind $540M Ronin Bridge Heist: AML and Accounting Implications for Firms
AML/KYC & Licensing
Drift Protocol Hacked for $286M in Suspected DPRK Operation
AML/KYC & Licensing
Crypto in Conflict: Sanctions Risk, DeFi Fundraising, and What Firms Must Know
AML/KYC & Licensing
Cross-Chain Crime: What the Elliptic Report Means for Crypto AML and Accounting