Breaking
DESuspected terrorist attack on Flydubai flight foiledFRMediterranean episode: red vigilance for Gard and HéraultTRBig betting operation by TFF: 448 managers were referred to PFDKDERomanian Prime Minister Muresan loses confidence voteRUFlyDubai plane makes emergency landing in Saudi Arabia due to conflict between pilotsUSFederal appeals court halts execution of Christa Pike in TennesseeDEMajor raid against Hells Angels: investigations also against police officers and city employeesUSTechCrunch Disrupt 2026 Exhibit Bookings Closing SoonCNPremier League charges against Manchester CityDEFederal Network Agency gives in to e-car rules: breakthrough for bi-directional chargingDESuspected terrorist attack on Flydubai flight foiledFRMediterranean episode: red vigilance for Gard and HéraultTRBig betting operation by TFF: 448 managers were referred to PFDKDERomanian Prime Minister Muresan loses confidence voteRUFlyDubai plane makes emergency landing in Saudi Arabia due to conflict between pilotsUSFederal appeals court halts execution of Christa Pike in TennesseeDEMajor raid against Hells Angels: investigations also against police officers and city employeesUSTechCrunch Disrupt 2026 Exhibit Bookings Closing SoonCNPremier League charges against Manchester CityDEFederal Network Agency gives in to e-car rules: breakthrough for bi-directional charging
NewsgatherNewsgather
All StoriesWorldSportsFinanceTechScience
Sign In
All StoriesWorldSportsFinanceTechScienceHealthCultureClimatePoliticsSpace
NewsgatherNewsgather

Real-time global news intelligence. Curated by humans, powered by data.

Sections

All StoriesWorldSportsFinanceTechScience

More

HealthCultureClimatePoliticsSpace

Company

AboutEditorial StandardsAdvertisingCareersPressContact

©️ 2026 Newsgather. A product by All Software 24. All rights reserved.

Privacy PolicyCookie PolicyImprintTerms of UseContent and Editorial PolicyRemoval RequestDelete Your AccountAdvertising PolicyContact
Back|DeFi protocols face legal scrutiny over handling of stolen crypto funds
DeFi protocols face legal scrutiny over handling of stolen crypto funds
NEWS
Cointelegraph·58 minutes ago·Business·5 min read

DeFi protocols face legal scrutiny over handling of stolen crypto funds

Legal experts weigh in on the tension between decentralization and the responsibility to block illicit transactions following the Bitget hack.

Quick Look

Following a $387.5 million hack of Bitget, a debate has emerged over whether DeFi protocols like THORChain and NEAR Intents are legally obligated to block stolen funds, highlighting the risks of intervention versus the protection of true decentralization.

AI-generated summary

Why It Matters

Bitget was exploited for $387.5 million by suspected North Korean hackers. THORChain previously faced controversy for processing funds from a $1.46 billion Bybit hack.

Font size

After suspected North Korean hackers exploited crypto exchange Bitget for $387.5 million last week, investigators were able to quickly flag and trace the recipient addresses.

Bitget CEO Gracy Chen then controversially demanded that decentralized cross-chain swaps platform THORChain “refuse service to these addresses.”

THORChain responded:

“THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?”

The move was controversial, especially given the protocol was halted immediately in May when $10.7 million of its own funds were exploited. Complicating matters, THORChain has retired its admin key and doesn’t have an easy way to censor addresses, even if it wanted to.

This exact controversy has come up before, as THORChain was used to swap around $1.2 billion of the funds stolen in the $1.46 billion hack of Bybit. It just so happened that THORChain’s admin key had been retired just 11 days earlier.

NEAR Intents took the opposite approach to THORChain. Its automated SHIELD program blocked addresses linked to the hack from swapping $50 million on the platform, and even turned down the 5% bounty Bitget was offering for doing so.

Now NEAR Intents is under fire from decentralization maxis for not being permissionless enough.

To discuss the legal issues involved in the case, Magazine spoke with Yuriy Brisov from D&A Partners. This is an edited version of the conversation.

Magazine: Bitget asked THORChain to block funds tied to the hack, and it responded saying it’s decentralized and permissionless. Is that a legal defense? Do they have an obligation to block those addresses?

Brisov: It depends on the level of decentralization. So when they do this — when they block some addresses — they show that their nodes aren’t truly decentralized. It’s good for the community, when they can use this power to prevent some malicious activities. However, at the same time, they open themselves to any other legal claim. Their only protection is “we are decentralized.”

In the Uniswap case, they said ‘we are truly decentralized and there is nothing we can do.’ [Investors sued Uniswap after buying 38 rugpull and scam tokens, but a judge dismissed the case in March —Ed.]

And this is the strongest defense for any DeFi protocol. If they show that they can block, control, or somehow interfere — even in a good faith attempt to prevent fraud — they still open themselves for these kinds of claims. That if you have control, then maybe your control shouldn’t be limited to only obvious fraud cases. You should imply [control over] due diligence matters. You should apply KYC and AML protective measures.

Magazine: NEAR Intents blocked those addresses, and Bitget thanked them for doing so. Does that mean NEAR has shown Intents is not decentralized and will therefore need to interfere in lots of other situations?

If you show that you have control over assets, then you potentially open yourself to all potential claims regarding pump-and-dump schemes, volatility, or any other potential claims of any investors who somehow have been damaged and harmed. And they can now say that you have control. Why do you use it in one case and not use it in another case? Why don’t you check all your token issuers on your platform? Why don’t they provide KYC forms like on any centralized exchange?

Magazine: THORChain argues the protocol halt in May initially triggered by an automated system and that they don’t have the ability to block certain addresses. If true, is that a defense?

Brisov: It might be. We don’t know yet, because it hasn’t been challenged yet. But any amount of control makes any DeFi project weaker vis-à-vis any claimant.

Magazine: On the other hand, the protocol could upgrade the software if it wished to block certain addresses. Could a project get in legal trouble for being reckless or negligent if they don’t impose something like that?

It depends on how it’s been done from the technical side. Say there is an oracle that can detect any North Korean IP and block it automatically, and there is no person who sits and presses a button — “there’s a North Korean hacker, let’s block him.” Then it’s okay.

If there is a team that oversees the situation and says, “Okay, we can see this is an illicit activity, we block these addresses, we press the button manually.” From the legal point of view, even though it’s a good act and it benefits the community, it still makes the project not fully decentralized from the legal perspective, and it strips you of the protection that regulations like MiCA [EU’s Markets in Crypto Assets laws] or the general understanding the SEC and CFTC provide that if you’re fully decentralized, you cannot be liable for the actions of the participants in your ecosystem.

Magazine: NEAR’s technology is called SHIELD and it’s an automated process that identifies addresses associated with known hacks on public blockchains and then blocks them from accessing Intents automatically. Does that mean it’s more likely to be seen as decentralized?

Brisov: Definitely. They show that they are good-faith actors trying to [add] protective measures into their protocols. There is no compliance team, people who sit there and control the operation manually. This is a smart solution, and that’s what we recommend to all the DeFi companies.

Magazine: In February 2025, THORChain retired the admin key which would allow them to make those sorts of unilateral changes. With the lack of an admin key and the fact they’ve got a hundred validators, does that make them sufficiently decentralized?

Brisov: More likely than not, but we can’t say that for sure. I would say yes.

Magazine: THORChain is not a mixer. You can take stolen Bitget funds and swap them on THORChain, but when it comes out the other end, it will still be transparently linked to the Bitget hackers. How does that fit the definition of money laundering? Or is it receiving stolen goods?

Brisov: I don’t see how they can be liable for money laundering because even Tornado Cash, that was, to a certain extent, made to launder money [avoided US sanctions as immutable smart contracts are not sanctionable property in terms of money laundering—Ed].

American law treats something as either property or not property. And money laundering is illegally moving property through the legal channels. You make proceeds of illicit activity, and it’s property, and then you move it through some channels and try to make it legal. But smart contracts are not property at all. You don’t control them. You don’t own them. That’s how Tornado Cash won their case in court vis-à-vis OFAC sanctions. They just proved that they don’t have any control over their smart contracts.

Magazine: The Bybit hack happened 18 months ago. Does that mean that no legal action is going to be taken against THORChain, or do these cases just take a long time?

Brisov: It might happen in the future, definitely. After the Bybit case, they seriously opened themselves for potential claims.

Open Questions

  • ?Will regulators pursue legal action against THORChain for past transactions?
  • ?Does automated intervention like SHIELD provide sufficient legal protection?

Related Topics

People
Organizations
Topics
This article was originally published by Cointelegraph.

Quick Look

Following a $387.5 million hack of Bitget, a debate has emerged over whether DeFi protocols like THORChain and NEAR Intents are legally obligated to block stolen funds, highlighting the risks of intervention versus the protection of true decentralization.

AI-generated summary

Story signals

News tone
Neutral
Emotional intensity
Medium
News value
High
Follow-up likelihood
Likely
Relevance window
Weeks

Source & Reliability

Source
Cointelegraph
Story type
Analysis
Source quality
Full
Published
58 minutes ago

Related Stories

More on this topic
SEC Tightens Guidance on Crypto Token Buybacks
Business·13 minutes ago

SEC Tightens Guidance on Crypto Token Buybacks

The US SEC updated its guidance on crypto token buybacks, requiring that systems have 'no central party' for buyback announcements to avoid being viewed as promises of managerial effort. The change complicates compliance for projects with human-led decision-making.

CryptoSlate
4 min read
Singapore Crypto Activity Surges 55% as Regional Markets Focus on P2P Stablecoin Use
Business·1 hour ago

Singapore Crypto Activity Surges 55% as Regional Markets Focus on P2P Stablecoin Use

Singapore's crypto economy grew 55.4% to $284 billion in the year ending June 2026, driven by institutional activity. Meanwhile, the Philippines, Thailand, and Vietnam saw a rise in small-value P2P stablecoin transfers for remittances and cross-border payments.

Cointelegraph
3 min read
UK Financial Conduct Authority Opens Applications for New Crypto Regulatory Regime
Business·2 hours ago

UK Financial Conduct Authority Opens Applications for New Crypto Regulatory Regime

The UK's Financial Conduct Authority (FCA) has opened applications for crypto businesses to comply with a new regulatory framework starting October 25, 2027. Firms must apply by February 2027 to ensure continuity of operations under the new oversight rules.

Cointelegraph
1 min read
Robinhood Announces Major Product Expansion at HOOD Summit
Business·2 hours ago

Robinhood Announces Major Product Expansion at HOOD Summit

Robinhood unveiled a suite of new products at its Houston summit, including crypto perpetual futures, 24/7 weekend stock trading, AI trading agents, and prediction market contracts, aiming to capture active trader market share.

Decrypt
4 min read
Altcoin exchange deposits hit highest level since October 2025
Business·3 hours ago

Altcoin exchange deposits hit highest level since October 2025

Altcoin exchange deposits reached 78,000 transactions on Sept. 28, the highest since October 2025. CryptoQuant analysts suggest the surge in inflows from 51,600 addresses indicates that holders may be preparing to sell their assets.

Cointelegraph
2 min read
Coinbase Secures CFTC Approval for Derivatives Clearinghouse
Business·3 hours ago

Coinbase Secures CFTC Approval for Derivatives Clearinghouse

Coinbase has received CFTC approval for its own derivatives clearinghouse, Coinbase Clearing LLC. This allows the exchange to clear fully collateralized futures and swaps internally, though its planned single-stock perpetual futures remain under separate review.

CryptoSlate
3 min read
More on this topic
defi
bitget
thorchain
defi
Gracy Chen
Yuriy Brisov
Alex Shevchenko
Bitget
THORChain
NEAR Intents
D&A Partners
bitget
thorchain
near intents
cryptocurrency
money laundering
decentralization
defi
defi