{"id":1862,"date":"2026-09-30T14:23:46","date_gmt":"2026-09-30T14:23:46","guid":{"rendered":"https:\/\/xesi.net\/?p=1862"},"modified":"2026-09-30T14:23:46","modified_gmt":"2026-09-30T14:23:46","slug":"the-decentralization-dilemma-how-the-bitget-exploit-and-thorchain-near-clash-are-redefining-defi-legal-liability","status":"publish","type":"post","link":"https:\/\/xesi.net\/?p=1862","title":{"rendered":"The Decentralization Dilemma: How the Bitget Exploit and THORChain-NEAR Clash Are Redefining DeFi Legal Liability"},"content":{"rendered":"<p>Last week, the cryptocurrency ecosystem was rocked by a major security breach when suspected North Korean hackers successfully exploited the crypto exchange Bitget, making off with an astounding $387.5 million in digital assets. In the immediate aftermath of the exploit, blockchain investigators swung into action, quickly flagging the attacker&#8217;s recipient addresses and tracing the flow of the stolen funds across public networks. What followed, however, has ignited a fierce industry-wide debate over the responsibilities, vulnerabilities, and legal realities of decentralized finance (DeFi).<\/p>\n<p>Bitget CEO Gracy Chen stepped into the controversy by publicly demanding that decentralized cross-chain swaps platform THORChain &quot;refuse service to these addresses.&quot; The demand placed a spotlight on the friction points between centralized exchange security requirements and the core ethos of permissionless, immutable protocols. <\/p>\n<p>THORChain did not mince words in its refusal, responding publicly with a pointed comparison: &quot;THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?&quot;<\/p>\n<p>The standoff quickly drew intense scrutiny across the crypto community. The controversy is particularly sharp given THORChain\u2019s own history; the protocol was forced to halt operations immediately in May following a separate $10.7 million exploit of its own funds. Complicating matters further, THORChain permanently retired its admin key in February 2025, meaning the protocol no longer possesses an easy, centralized mechanism to censor or block specific addresses even if its developers or community wished to do so.<\/p>\n<p>This is not the first time THORChain has found itself at the center of such a storm. The protocol was previously utilized to swap roughly $1.2 billion of the funds stolen during the massive $1.46 billion hack of Bybit\u2014an incident that coincidentally unfolded just 11 days after THORChain had retired its admin key.<\/p>\n<p>In stark contrast to THORChain\u2019s hands-off stance, NEAR Intents adopted the exact opposite approach. Utilizing its automated SHIELD program, NEAR Intents successfully blocked addresses linked to the Bitget hack from swapping $50 million on its platform. In a demonstration of its commitment to blocking illicit funds, NEAR Intents even turned down the 5% bounty offered by Bitget for intercepting the transactions.<\/p>\n<p>While praised by centralized entities like Bitget, NEAR Intents&#8217; intervention has drawn sharp criticism from &quot;decentralization maximalists,&quot; who argue that programmatic interference undermines the core tenet of permissionless finance. <\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/s3-images.ctmedia.io\/media\/article-covers\/2026\/09\/01M3QSRG3BHR6KAP15GVPERVEN\/thorchain-yuriy.png\" alt=\"Could THORChain face prosecution over stolen Bitget funds?\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>To unpack the complex legal landscape governing these diverging philosophies, Cointelegraph&#8217;s Magazine sat down with Yuriy Brisov from D&amp;A Partners to discuss the liabilities, risks, and regulatory precedents shaping the modern DeFi space. Below is an edited version of that conversation.<\/p>\n<p><strong>Magazine: Bitget asked THORChain to block funds tied to the hack, and it responded saying it\u2019s decentralized and permissionless. Is that a legal defense? Do they have an obligation to block those addresses?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> It depends on the level of decentralization. So when they do this \u2014 when they block some addresses \u2014 they show that their nodes aren\u2019t truly decentralized. It\u2019s good for the community, when they can use this power to prevent some malicious activities. However, at the same time, they open themselves to any other legal claim. Their only protection is \u201cwe are decentralized.\u201d <\/p>\n<p>In the Uniswap case, they said \u2018we are truly decentralized and there is nothing we can do.\u2019 [Investors sued Uniswap after buying 38 rugpull and scam tokens, but a judge dismissed the case in March \u2014 Ed.] <\/p>\n<p>And this is the strongest defense for any DeFi protocol. If they show that they can block, control, or somehow interfere \u2014 even in a good faith attempt to prevent fraud \u2014 they still open themselves for these kinds of claims. That if you have control, then maybe your control shouldn\u2019t be limited to only obvious fraud cases. You should imply [control over] due diligence matters. You should apply KYC and AML protective measures.<\/p>\n<p><strong>Magazine: NEAR Intents blocked those addresses, and Bitget thanked them for doing so. Does that mean NEAR has shown Intents is not decentralized and will therefore need to interfere in lots of other situations?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> If you show that you have control over assets, then you potentially open yourself to all potential claims regarding pump-and-dump schemes, volatility, or any other potential claims of any investors who somehow have been damaged and harmed. And they can now say that you have control. Why do you use it in one case and not use it in another case? Why don\u2019t you check all your token issuers on your platform? Why don\u2019t they provide KYC forms like on any centralized exchange?<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/s3-images.ctmedia.io\/media\/content\/2026\/09\/01M3QSZNVG03NNJ7SKS02DRM3T\/thorchain-no.jpg\" alt=\"Could THORChain face prosecution over stolen Bitget funds?\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p><strong>Magazine: THORChain argues the protocol halt in May initially triggered by an automated system and that they don\u2019t have the ability to block certain addresses. If true, is that a defense?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> It might be. We don\u2019t know yet, because it hasn\u2019t been challenged yet. But any amount of control makes any DeFi project weaker vis-\u00e0-vis any claimant.<\/p>\n<p><strong>Magazine: On the other hand, the protocol could upgrade the software if it wished to block certain addresses. Could a project get in legal trouble for being reckless or negligent if they don\u2019t impose something like that?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> It depends on how it\u2019s been done from the technical side. Say there is an oracle that can detect any North Korean IP and block it automatically, and there is no person who sits and presses a button \u2014 \u201cthere\u2019s a North Korean hacker, let\u2019s block him.\u201d Then it\u2019s okay. <\/p>\n<p>If there is a team that oversees the situation and says, \u201cOkay, we can see this is an illicit activity, we block these addresses, we press the button manually.\u201d From the legal point of view, even though it\u2019s a good act and it benefits the community, it still makes the project not fully decentralized from the legal perspective, and it strips you of the protection that regulations like MiCA [EU\u2019s Markets in Crypto Assets laws] or the general understanding the SEC and CFTC provide that if you\u2019re fully decentralized, you cannot be liable for the actions of the participants in your ecosystem.<\/p>\n<p><strong>Magazine: NEAR\u2019s technology is called SHIELD and it\u2019s an automated process that identifies addresses associated with known hacks on public blockchains and then blocks them from accessing Intents automatically. Does that mean it\u2019s more likely to be seen as decentralized?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> Definitely. They show that they are good-faith actors trying to [add] protective measures into their protocols. There is no compliance team, people who sit there and control the operation manually. This is a smart solution, and that\u2019s what we recommend to all the DeFi companies.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/s3-images.ctmedia.io\/media\/content\/2026\/09\/01M3QTFZ11FGNG19F92RGAAJ1T\/gracy-chen-post.jpg\" alt=\"Could THORChain face prosecution over stolen Bitget funds?\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p><strong>Magazine: In February 2025, THORChain retired the admin key which would allow them to make those sorts of unilateral changes. With the lack of an admin key and the fact they\u2019ve got a hundred validators, does that make them sufficiently decentralized?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> More likely than not, but we can\u2019t say that for sure. I would say yes.<\/p>\n<p><strong>Magazine: THORChain is not a mixer. You can take stolen Bitget funds and swap them on THORChain, but when it comes out the other end, it will still be transparently linked to the Bitget hackers. How does that fit the definition of money laundering? Or is it receiving stolen goods?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> I don\u2019t see how they can be liable for money laundering because even Tornado Cash, that was, to a certain extent, made to launder money [avoided US sanctions as immutable smart contracts are not sanctionable property in terms of money laundering \u2014 Ed]. <\/p>\n<p>American law treats something as either property or not property. And money laundering is illegally moving property through the legal channels. You make proceeds of illicit activity, and it\u2019s property, and then you move it through some channels and try to make it legal. But smart contracts are not property at all. You don\u2019t control them. You don\u2019t own them. That\u2019s how Tornado Cash won their case in court vis-\u00e0-vis OFAC sanctions. They just proved that they don\u2019t have any control over their smart contracts.<\/p>\n<p><strong>Magazine: The Bybit hack happened 18 months ago. Does that mean that no legal action is going to be taken against THORChain, or do these cases just take a long time?<\/strong><\/p>\n<p><strong>Brisov:<\/strong> It might happen in the future, definitely. After the Bybit case, they seriously opened themselves for potential claims.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week, the cryptocurrency ecosystem was rocked by a major security breach when suspected North Korean hackers successfully exploited the crypto exchange Bitget, making off with an astounding $387.5 million in digital assets. In the immediate aftermath of the exploit, blockchain investigators swung into action, quickly flagging the attacker&#8217;s recipient addresses and tracing the flow [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1861,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[933],"tags":[3239,935,1030,934,3482,3486,3483,3484,1306,3487,346,1443,3485,936],"class_list":["post-1862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency-and-web3","tag-bitget","tag-blockchain","tag-clash","tag-crypto","tag-decentralization","tag-defi","tag-dilemma","tag-exploit","tag-legal","tag-liability","tag-near","tag-redefining","tag-thorchain","tag-web3"],"_links":{"self":[{"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/posts\/1862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1862"}],"version-history":[{"count":0,"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/posts\/1862\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/media\/1861"}],"wp:attachment":[{"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}