After suspected North Korean hackers exploited crypto exchange Bitget for $387.5 million last week, investigators were able to quickly flag and trace the recipient addresses.
Bitget CEO Gracy Chen then controversially demanded that decentralized cross-chain swaps platform THORChain “refuse service to these addresses.”
THORChain responded:
“THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?”
The move was controversial, especially given the protocol was halted immediately in May when $10.7 million of its own funds were exploited. Complicating matters, THORChain has retired its admin key and doesn’t have an easy way to censor addresses, even if it wanted to.

Source: THORChain
This exact controversy has come up before, as THORChain was used to swap around $1.2 billion of the funds stolen in the $1.46 billion hack of Bybit. It just so happened that THORChain’s admin key had been retired just 11 days earlier.
NEAR Intents took the opposite approach to THORChain. Its automated SHIELD program blocked addresses linked to the hack from swapping $50 million on the platform, and even turned down the 5% bounty Bitget was offering for doing so.
Now NEAR Intents is under fire from decentralization maxis for not being permissionless enough.
To discuss the legal issues involved in the case, Magazine spoke with Yuriy Brisov from D&A Partners. This is an edited version of the conversation.
Magazine: Bitget asked THORChain to block funds tied to the hack, and it responded saying it’s decentralized and permissionless. Is that a legal defense? Do they have an obligation to block those addresses?
Brisov: It depends on the level of decentralization. So when they do this — when they block some addresses — they show that their nodes aren’t truly decentralized. It’s good for the community, when they can use this power to prevent some malicious activities. However, at the same time, they open themselves to any other legal claim. Their only protection is “we are decentralized.”
In the Uniswap case, they said ‘we are truly decentralized and there is nothing we can do.’ [Investors sued Uniswap after buying 38 rugpull and scam tokens, but a judge dismissed the case in March —Ed.]
And this is the strongest defense for any DeFi protocol. If they show that they can block, control, or somehow interfere — even in a good faith attempt to prevent fraud — they still open themselves for these kinds of claims. That if you have control, then maybe your control shouldn’t be limited to only obvious fraud cases. You should imply [control over] due diligence matters. You should apply KYC and AML protective measures.
Related: Uniswap beats class action alleging it assisted crypto ‘rug pulls’
Magazine: NEAR Intents blocked those addresses, and Bitget thanked them for doing so. Does that mean NEAR has shown Intents is not decentralized and will therefore need to interfere in lots of other situations?
If you show that you have control over assets, then you potentially open yourself to all potential claims regarding pump-and-dump schemes, volatility, or any other potential claims of any investors who somehow have been damaged and harmed. And they can now say that you have control. Why do you use it in one case and not use it in another case? Why don’t you check all your token issuers on your platform? Why don’t they provide KYC forms like on any centralized exchange?

Source: Gracy Chen
Magazine: THORChain argues the protocol halt in May initially triggered by an automated system and that they don’t have the ability to block certain addresses. If true, is that a defense?
Brisov: It might be. We don’t know yet, because it hasn’t been challenged yet. But any amount of control makes any DeFi project weaker vis-à-vis any claimant.
Magazine: On the other hand, the protocol could upgrade the software if it wished to block certain addresses. Could a project get in legal trouble for being reckless or negligent if they don’t impose something like that?
It depends on how it’s been done from the technical side. Say there is an oracle that can detect any North Korean IP and block it automatically, and there is no person who sits and presses a button — “there’s a North Korean hacker, let’s block him.” Then it’s okay.
If there is a team that oversees the situation and says, “Okay, we can see this is an illicit activity, we block these addresses, we press the button manually.” From the legal point of view, even though it’s a good act and it benefits the community, it still makes the project not fully decentralized from the legal perspective, and it strips you of the protection that regulations like MiCA [EU’s Markets in Crypto Assets laws] or the general understanding the SEC and CFTC provide that if you’re fully decentralized, you cannot be liable for the actions of the…
cointelegraph.com
