THORChain co-founder says acting against Bitget hacker was possible but difficult

THORChain co-founder says acting against Bitget hacker was possible but difficult

THORChain co-founder Chad Barraford said validators could ultimately vote to block laundering, but coordinating a response can take days as attackers move funds between addresses.

THORChain could have taken steps to disrupt funds linked to the Bitget hack, according to co-founder Chad Barraford. However, he said implementing an effective response would have been difficult, as coordinating validators can take days while attackers can quickly move funds to new addresses.

Barraford discussed the issue during an Unchained interview hosted by Laura Shin alongside onchain analyst and investigator Taylor Monahan. The debate centered on whether THORChain could have done more after Bitget asked the protocol to stop serving addresses linked to wallets that drained $387.5 million from the exchange.

Barraford said THORChain does not currently have a mechanism that allows the protocol to immediately censor individual transactions or wallets. He said creating one would still leave validators with the problem of coordinating quickly enough to act before stolen funds move elsewhere.

Reaching the two thirds validator consensus needed for certain actions takes about three days on average and can sometimes take as long as two weeks, Barraford said. A faster response, he argued, would require redesigning THORChain to give a smaller group more control.

The problem becomes more complicated once transactions are already underway.

Barraford said halting trading with swaps in progress would require reallocating those funds through a vault migration, which itself needs two thirds consensus and could take one to two weeks.

Validators could theoretically block a known Ethereum address before its funds entered the protocol, he added, but the attacker could simply switch to another address and continue trading.

ā€œYou can’t have the fast enough response because the protocol is decentralized,ā€ Barraford said.

The discussion nevertheless showed that THORChain was not entirely without options.

Shin pointed to existing functions capable of halting Ethereum or Bitcoin trading. She argued that the Ethereum halt function could have sent certain swaps associated with stolen funds back to their sender rather than allowing them to continue through the protocol.

She also highlighted THORChain’s MakePause function, which she said allows a single node to temporarily halt chains for 720 blocks, or roughly an hour, potentially giving validators time to discuss a response.

Barraford’s argument was not that THORChain can never stop trading. Instead, he argued that using those mechanisms against an active hacker creates practical problems because a broad halt affects legitimate users while validators coordinate a more permanent response.

Advertisement

That coordination is easier when THORChain itself is under threat.

Barraford said validators tend to quickly reach consensus when an exploit threatens the protocol because protecting THORChain is part of their responsibility.

ā€œWhen there’s a bug or an exploit on ThorChain, there is a wide consensus immediately amongst all validators that we need to pause trading,ā€ he said.

Monahan challenged that distinction by pointing to previous instances in which THORChain had been willing to interrupt its own operations.

She cited the ThorFi incident, when an admin key was used as an interim measure to pause lending before validators approved further action through consensus. Barraford stressed that the key itself could only change configuration and could not directly reallocate user funds.

Shin also compared the situation with the response to the DAO hacker years earlier.

She said ShapeShift repeatedly reacted as the hacker attempted to convert stolen funds into Bitcoin. Although the attacker could continue switching addresses, Shin argued that responding still made moving the funds harder and appeared to cause the hacker to give up at certain points.

Barraford responded that ShapeShift was centralized at the time, allowing it to react far more quickly than a validator driven protocol such as THORChain.

Taylor Monahan pushed the broader argument that THORChain’s inability to perfectly stop stolen funds should not prevent validators from trying to make laundering more difficult.

She argued that the protocol had mechanisms available to intervene and questioned the use of decentralization as a justification for taking no action when a large share of activity on a route consisted of stolen funds.

The same disagreement had already surfaced following the Bybit hack.

Barraford said some THORChain validators attempted to pause Ethereum trading when stolen Bybit funds moved through the protocol, but the effort failed because most validators opposed the action.

ā€œA few did it, but the vast majority didn’t want to do that,ā€ Barraford said.

He later said roughly 20 validators may have left around the disagreement, although he stressed that he did not remember the exact number and said the network has since added more operators.

The previous vote illustrates the distinction at the center of the Bitget debate. THORChain validators can attempt to interrupt trading, but doing so does not guarantee that enough operators will agree or that they can coordinate before an attacker moves the funds.

Later in the interview, Barraford acknowledged more directly that validator consensus could ultimately be used to block laundering.

Asked by Shin what would happen if enough node operators joined THORChain and supported censoring illicit transactions, Barraford replied, ā€œThen laundering would be blocked.ā€

ā€œIf you get a two third majority agreeing that we should censor transactions, then sure, that would be the way of the community,ā€ he said.

Shin also raised NEAR Intents as an example of a protocol taking a more active approach.

She said the project’s Shield risk layer can refuse quotes or halt swaps during execution and had blocked an attempted $50 million in laundering. According to Shin, the system also froze roughly $500,000 during a swap and planned to return $340,000.

Asked whether THORChain could introduce something similar, Barraford said it was technically possible if validators supported it.

ā€œMaybe. If the nodes want to deploy something like that, it’s up for validators to determine,ā€ Barraford said.

ā€œIf the nodes wanted to do that, they could. My guess is they wouldn’t, but I don’t speak for them.ā€

The exchange ultimately narrowed the dispute from whether THORChain can intervene at all to how quickly and effectively it could do so.

The protocol has mechanisms capable of interrupting trading, and validators could adopt stronger controls through consensus. Barraford’s position, however, is that coordinating those measures quickly enough to stop an active hacker is difficult under THORChain’s current design.

He summarized that governance limitation later in the interview by acknowledging that validator consensus can ultimately change the protocol.

ā€œYes, if you get consensus behind any change, you could change anything,ā€ Barraford said.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.
THORChain co-founder says acting against Bitget hacker was possible but difficult
THORChain co-founder says acting against Bitget hacker was possible but difficult

THORChain co-founder Chad Barraford said validators could ultimately vote to block laundering, but coordinating a response can take days as attackers move funds between addresses.

THORChain could have taken steps to disrupt funds linked to the Bitget hack, according to co-founder Chad Barraford. However, he said implementing an effective response would have been difficult, as coordinating validators can take days while attackers can quickly move funds to new addresses.

Barraford discussed the issue during an Unchained interview hosted by Laura Shin alongside onchain analyst and investigator Taylor Monahan. The debate centered on whether THORChain could have done more after Bitget asked the protocol to stop serving addresses linked to wallets that drained $387.5 million from the exchange.

Barraford said THORChain does not currently have a mechanism that allows the protocol to immediately censor individual transactions or wallets. He said creating one would still leave validators with the problem of coordinating quickly enough to act before stolen funds move elsewhere.

Reaching the two thirds validator consensus needed for certain actions takes about three days on average and can sometimes take as long as two weeks, Barraford said. A faster response, he argued, would require redesigning THORChain to give a smaller group more control.

The problem becomes more complicated once transactions are already underway.

Barraford said halting trading with swaps in progress would require reallocating those funds through a vault migration, which itself needs two thirds consensus and could take one to two weeks.

Validators could theoretically block a known Ethereum address before its funds entered the protocol, he added, but the attacker could simply switch to another address and continue trading.

ā€œYou can’t have the fast enough response because the protocol is decentralized,ā€ Barraford said.

The discussion nevertheless showed that THORChain was not entirely without options.

Shin pointed to existing functions capable of halting Ethereum or Bitcoin trading. She argued that the Ethereum halt function could have sent certain swaps associated with stolen funds back to their sender rather than allowing them to continue through the protocol.

She also highlighted THORChain’s MakePause function, which she said allows a single node to temporarily halt chains for 720 blocks, or roughly an hour, potentially giving validators time to discuss a response.

Barraford’s argument was not that THORChain can never stop trading. Instead, he argued that using those mechanisms against an active hacker creates practical problems because a broad halt affects legitimate users while validators coordinate a more permanent response.

Advertisement

That coordination is easier when THORChain itself is under threat.

Barraford said validators tend to quickly reach consensus when an exploit threatens the protocol because protecting THORChain is part of their responsibility.

ā€œWhen there’s a bug or an exploit on ThorChain, there is a wide consensus immediately amongst all validators that we need to pause trading,ā€ he said.

Monahan challenged that distinction by pointing to previous instances in which THORChain had been willing to interrupt its own operations.

She cited the ThorFi incident, when an admin key was used as an interim measure to pause lending before validators approved further action through consensus. Barraford stressed that the key itself could only change configuration and could not directly reallocate user funds.

Shin also compared the situation with the response to the DAO hacker years earlier.

She said ShapeShift repeatedly reacted as the hacker attempted to convert stolen funds into Bitcoin. Although the attacker could continue switching addresses, Shin argued that responding still made moving the funds harder and appeared to cause the hacker to give up at certain points.

Barraford responded that ShapeShift was centralized at the time, allowing it to react far more quickly than a validator driven protocol such as THORChain.

Taylor Monahan pushed the broader argument that THORChain’s inability to perfectly stop stolen funds should not prevent validators from trying to make laundering more difficult.

She argued that the protocol had mechanisms available to intervene and questioned the use of decentralization as a justification for taking no action when a large share of activity on a route consisted of stolen funds.

The same disagreement had already surfaced following the Bybit hack.

Barraford said some THORChain validators attempted to pause Ethereum trading when stolen Bybit funds moved through the protocol, but the effort failed because most validators opposed the action.

ā€œA few did it, but the vast majority didn’t want to do that,ā€ Barraford said.

He later said roughly 20 validators may have left around the disagreement, although he stressed that he did not remember the exact number and said the network has since added more operators.

The previous vote illustrates the distinction at the center of the Bitget debate. THORChain validators can attempt to interrupt trading, but doing so does not guarantee that enough operators will agree or that they can coordinate before an attacker moves the funds.

Later in the interview, Barraford acknowledged more directly that validator consensus could ultimately be used to block laundering.

Asked by Shin what would happen if enough node operators joined THORChain and supported censoring illicit transactions, Barraford replied, ā€œThen laundering would be blocked.ā€

ā€œIf you get a two third majority agreeing that we should censor transactions, then sure, that would be the way of the community,ā€ he said.

Shin also raised NEAR Intents as an example of a protocol taking a more active approach.

She said the project’s Shield risk layer can refuse quotes or halt swaps during execution and had blocked an attempted $50 million in laundering. According to Shin, the system also froze roughly $500,000 during a swap and planned to return $340,000.

Asked whether THORChain could introduce something similar, Barraford said it was technically possible if validators supported it.

ā€œMaybe. If the nodes want to deploy something like that, it’s up for validators to determine,ā€ Barraford said.

ā€œIf the nodes wanted to do that, they could. My guess is they wouldn’t, but I don’t speak for them.ā€

The exchange ultimately narrowed the dispute from whether THORChain can intervene at all to how quickly and effectively it could do so.

The protocol has mechanisms capable of interrupting trading, and validators could adopt stronger controls through consensus. Barraford’s position, however, is that coordinating those measures quickly enough to stop an active hacker is difficult under THORChain’s current design.

He summarized that governance limitation later in the interview by acknowledging that validator consensus can ultimately change the protocol.

ā€œYes, if you get consensus behind any change, you could change anything,ā€ Barraford said.

Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.