THORChain, the decentralized cross-chain liquidity protocol, has come under intense scrutiny after refusing to block wallet addresses tied to the $387.5 million Bitget hack, raising thorny legal questions about whether its developers could face criminal exposure for facilitating money laundering.
The Controversy Over Blocked Addresses
The debate centers on THORChain's role in allegedly helping launder proceeds from the massive Bitget breach. Unlike centralized exchanges that can freeze suspicious funds, THORChain operates as a decentralized network, and its developers argue they lack both the ability and the mandate to blacklist addresses.
Critics contend that the protocol became a preferred conduit for moving illicit funds, with hackers exploiting its permissionless design to swap and obscure the origins of stolen crypto. The refusal to intervene has reignited a long-running argument about where responsibility lies when decentralized tools are used for criminal purposes.
When the code refuses to discriminate, the law is left asking who — if anyone — can be held to account.
Can Developers Be Held Liable?
According to crypto lawyer Yuriy Brisov, the answer is far from straightforward. Prosecuting developers of a decentralized protocol hinges on proving intent, control, and knowledge — elements that are notoriously difficult to establish when software runs autonomously across a distributed network.
Brisov notes that legal outcomes vary sharply by jurisdiction. Some regulators may treat protocol contributors as money transmitters subject to anti-money-laundering obligations, while others may find that developers who neither operate nodes nor control funds fall outside traditional liability frameworks.
The case echoes earlier enforcement actions against privacy tools and mixing services, where authorities pursued individuals despite claims of decentralization. Those precedents suggest regulators are increasingly willing to test the boundaries of who counts as an operator versus a mere code author.
Key factors shaping any potential prosecution include:
- Whether developers retain meaningful control over the protocol's operations
- The degree of knowledge that stolen funds were flowing through the system
- Which national jurisdiction claims authority over the alleged conduct
- How courts interpret decentralized governance and validator responsibility
For now, THORChain's stance leaves an unresolved tension between the ideals of censorship-resistant finance and the mounting pressure from regulators determined to close
