News linked to both this project and an event.
Odaily News: Today, THORChain officially posted on X platform stating, "We have noticed the recent Bitget hack and are deeply saddened by it. We can imagine this is a difficult time for everyone in the industry. (However,) THORChain is as decentralized and permissionless as Bitcoin, Ethereum, and BNB Chain. When dealing with known stolen funds, what responsibility should Bitcoin, Ethereum, and BNB Chain bear?" Subsequently, it called out OKX CEO Star and Bitget CEO Gracy.However, crypto community members in the comments pointed out that when THORChain previously suffered an attack, it once suspended services for 39 days, and they are deeply ashamed of the differentiated treatment between the two situations.
According to CoinDesk, a Gnosis Safe wallet on Ethereum was attacked, with approximately 2,900 rsETH (valued at around $7.8 million) transferred. Security firms BlockSec, Blockaid, and SlowMist pointed out that the root cause of the attack lies in an authorization check flaw within the wallet-approved Multicall contract—the contract is intended to verify caller permissions, but the vulnerability allows anyone to bypass validation simply by targeting the contract itself. The attacker subsequently moved the rsETH into a liquidity pool based on the valueless token "Permissionless Attacker Token." An automated bot named "yoink" paid approximately $47,000 to frontrun the transaction, transferring 2,882 rsETH to a separate address. rsETH issuer Kelp DAO stated that its smart contracts are secure and rsETH is fully collateralized, and has implemented a 24-hour pause measure on the relevant addresses.