The hack targeting Bitget has renewed scrutiny of cross-chain protocol THORChain. The discussion goes beyond the security of one exchange: it also concerns how quickly stolen assets can move across chains and how much protocols and trading platforms can do to trace or intercept them.
Bitget has not disclosed the scale of the incident
Public information so far does not specify how much was stolen, which assets were affected, when the attack took place, or whether Bitget has frozen or recovered any funds. Those details will be central to assessing the incident’s scale, the exchange’s losses and any impact on users.
The attack has nevertheless brought THORChain back into focus. The protocol provides infrastructure for exchanging assets across different blockchains. When stolen funds move through cross-chain routes, blockchain investigators, exchanges and protocol participants may need to identify them using address labels, transaction paths and the flow of assets. Moving funds between chains can make tracking more difficult and involve more parties in any effort to stop or address the transactions.
Why the Bybit dispute is back in focus
Some of the renewed attention on THORChain stems from controversy surrounding the Bybit incident. The cross-chain movement of funds linked to that theft prompted debate about how THORChain handles such transactions. At the heart of the dispute is whether an open cross-chain protocol should, and can, identify and restrict assets potentially connected to a hack without relying on centralized screening.
That does not establish that the Bitget and Bybit incidents involved the same attackers, transaction routes or amounts. Available information has not confirmed a direct link between them. What the latest exchange security incident has done is reopen questions about the role of cross-chain protocols in unusual fund flows and how protocol governance, on-chain monitoring and centralized exchange controls work together.
Losses and response measures remain unclear
Traders and investors will be watching for three sets of details: Bitget’s disclosure of losses and affected users; whether the assets moved through THORChain or another cross-chain route; and whether exchanges, blockchain security teams or protocol participants took steps to freeze, flag or restrict transactions.
Until those details emerge, the hack alone is not enough to determine specific responsibility for THORChain, Bitget or Bybit. The incident highlights an operational challenge that persists across the sector: when assets move across multiple networks, exchange security teams, on-chain investigators and protocol governance may need to act in coordination. Gaps in information at any stage can make it harder to establish where funds went and how users were affected.