Bitget Blames DeFi After $387.5M Hack, Praises NEAR Intents
UpGateNeutralSecurity & hacks

Bitget Blames DeFi After $387.5M Hack, Praises NEAR Intents

Reading time: 3 min

Bitget Criticizes DeFi Protocols for Refusing to Aid in Stolen Fund Recovery

Cryptocurrency exchange Bitget is still grappling with the aftermath of one of the year’s most significant security breaches, and it has issued a pointed message to certain segments of the decentralized finance (DeFi) world. The exchange contends that some DeFi protocols have been unwilling to assist in the recovery of stolen assets, with NEAR Intents, a cross-chain protocol, standing out as a notable exception.

The Breach and Its Aftermath

The incident occurred on September 24, 2026, when attackers siphoned approximately $387.5 million from Bitget’s hot and warm wallets. The theft affected multiple blockchain networks, including Ethereum, Tron, and the XRP Ledger. The attackers exploited a zero-day vulnerability in third-party security software, which granted them access to high-level credentials, enabling them to issue fraudulent withdrawal commands before erasing their digital tracks.

Bitget CEO Gracy Chen confirmed that the exchange’s cold wallets and private keys remained secure throughout the event. Following the breach, Bitget temporarily suspended withdrawals, gradually restoring them on September 28. The exchange assured users that all losses would be fully compensated by its User Protection Fund, which held over $464 million prior to the incident.

NEAR Intents’ Role in Recovery Efforts

NEAR Intents reported that its SHIELD risk-intelligence system successfully identified and blocked over $50 million in illicit laundering attempts linked to the Bitget hack. While SHIELD managed to freeze $503,000 in transactions as they were in progress, an additional $166,000 had already slipped through before the system could fully intervene. Bitget had offered a 5% bounty for recovered funds, a reward that NEAR Intents ultimately waived.

Stablecoin Issuers Step In

Centralized stablecoin issuers also played a role in the recovery efforts. Tether and Circle collectively froze between $320,000 and $340,000 in funds associated with the stolen assets.

Despite these interventions, the overall recovery rate is estimated to be a mere 0.2% of the total losses.

A Divide in the DeFi Community

Bitget’s criticism highlights a long-standing tension within the cryptocurrency space. The exchange’s stance is that refusing to act when stolen funds are identifiable constitutes a deliberate choice, effectively determining who can access and utilize network resources.

The incident has intensified the debate surrounding how cross-chain protocols should respond to instances of stolen funds. NEAR Intents aligned itself with proactive intervention, while centralized stablecoin issuers like Tether and Circle have long possessed the built-in capability to freeze their tokens.

Ongoing Investigations and Future Implications

Attribution for the hack remains uncertain, with theories suggesting potential involvement by actors linked to North Korea. However, Bitget has not confirmed any specific affiliations, and investigations are ongoing.

For Bitget customers, losses are being covered by the User Protection Fund, and withdrawal services have been progressively reinstated since September 28. The breach originated from a vulnerability in third-party software with privileged access, underscoring how a vendor’s security lapse can lead to substantial financial losses for other entities.

With a recovery rate of approximately 0.2%, the limited success in asset recovery may prompt increased regulatory scrutiny into how these platforms manage illicit financial flows.

Tags:UpGateNeutralSecurity & hacks
Copied