The crypto streets are buzzing after hackers allegedly linked to North Korea swiped $387.5 million from the exchange Bitget. Bitget CEO Gracy Chen tried to get the cross-chain swap platform THORChain to blacklist the hackers' addresses, but the protocol basically said, "we can't—and we won't."
The decentralization dilemma
THORChain has retired its admin keys, meaning there isn't a central "off" switch to freeze funds even if the team wanted to. This stance has sparked a massive debate about what true decentralization actually looks like in the eyes of regulators.
Crypto lawyer Yuriy Brisov from D&A Partners explains that while staying decentralized is a major W for privacy, it's also a legal minefield. "If they show that they can block, control, or somehow interfere... they still open themselves for these kinds of claims," Brisov noted. Essentially, if a protocol acts like a centralized bank by policing transactions, it loses the "we're just code" defense that usually keeps regulators at bay.
Automated vs. Manual: What’s the vibe?
While THORChain stayed hands-off, NEAR Intents took the opposite path. Their automated SHIELD program blocked the hackers' addresses from swapping funds. Brisov argues that automation is a total power move for legal safety because it removes the "human in the loop" aspect that makes regulators suspicious of central control. By relying on smart contracts rather than a team manually hitting a block button, projects can maintain a stronger claim to being fully decentralized.
Is it money laundering?
When it comes to potential prosecution, the waters are murky. Since THORChain isn't a privacy mixer, funds moving through it remain transparent on-chain. Brisov suggests that because smart contracts aren't technically "property" that anyone owns or controls, holding a decentralized protocol liable for how bad actors use code is a tough sell in court—much like how Tornado Cash previously pushed back against sanctions.
Why it matters
As DeFi projects scale, they’re being forced to pick a lane: either stay permissionless and risk regulatory scrutiny, or build in guardrails and face accusations of being centralized. For the average user, it’s a reminder that not all "decentralized" protocols are built the same, and the legal reality of on-chain activity is still being written in real-time. NFA, but always DYOR before parking your bags in any protocol.





