What primary sources establish
Bitget said it identified a security incident on September 24, remediated the underlying vulnerability, and engaged independent specialists for the investigation. In later updates, the exchange also described tracing affected assets and pursuing recovery efforts.
THORChain's September network report recorded a sharp rise in swap volume between September 25 and 29 and associated that window with flows linked to the Bitget incident. That supports the observation of network activity, but it is not a court finding on the origin of every address or the identity of those responsible.
Why the cross-chain route matters
A cross-chain swap changes both the asset form and the network on which it is recorded. An asset on Ethereum can, for example, be swapped into BTC without using the usual interface of a centralized exchange. That means an investigation must correlate addresses and transactions across several chains.
Moving between chains does not make a transaction invisible. Records remain on the relevant public blockchains, and analysts can build probabilistic links from timing, amounts, and known addresses. Those links still need validation: a matching route alone does not prove control of an address.
What a permissionless protocol can and cannot do
THORChain describes itself as a network whose swaps are executed by protocol rules rather than a single operator manually accepting each request. A request to block an address is therefore different from freezing funds at a custodial service: the available controls and responsibilities depend on code, validators, and applicable law, not on a social-media statement alone.
Neutral execution does not remove the need to monitor risks. It also does not automatically make a protocol an accomplice to someone else's crime. That conclusion would require established facts, legal analysis, and an assessment of specific conduct, not merely the presence of a swap on a public network.
What users should take from this
Major security incidents are a useful reminder of the difference between holding funds with a service and controlling keys independently. For crypto operations, verify the domain, destination address, selected network, and who controls withdrawals and account recovery.
A public route is not an instruction to use a cross-chain service and does not guarantee asset recovery. Rely on official notices from the affected service, avoid links in unverified messages, and remember that final conclusions may only emerge after an investigation is complete.