Bitget calls out DeFi protocols after $387.5 million hack, credits NEAR Intents
Bitget is still cleaning up after one of the largest exchange breaches of the year. The exchange now has a pointed message for parts of the DeFi world.
In a post on X, Bitget argued that some DeFi protocols refuse to help recover stolen funds. NEAR Intents, a cross-chain protocol, was the notable exception.
How the breach unfolded
On September 24, 2026, attackers drained approximately $387.5 million from Bitget’s hot and warm wallets. The theft spanned several blockchain networks, including Ethereum, Tron and the XRP Ledger.
The entry point was a zero-day vulnerability in third-party security software. That flaw let the attackers grab high-level credentials and issue fraudulent withdrawal commands. They then erased their digital footprints.
CEO Gracy Chen said the exchange’s cold wallets and private keys stayed protected throughout the incident.
Bitget suspended withdrawals after the breach and began gradually restoring them on September 28. The exchange told users their losses would be fully covered by its User Protection Fund, which was valued at over $464 million before the breach.
NEAR Intents and the freeze math
NEAR Intents reported that its SHIELD risk-intelligence system identified and halted over $50 million in illicit laundering attempts tied to the Bitget hack.
Actual freezes were smaller. SHIELD froze $503,000 while transactions were still executing. Around $166,000 slipped through before the system caught on.
Bitget had offered a 5% bounty on recovered funds. NEAR Intents waived it.
Stablecoin issuers also stepped in. Tether and Circle froze between $320,000 and $340,000 linked to the stolen funds.
Overall recovery is estimated at just 0.2% of total losses.
The neutrality argument
Bitget’s criticism lands on a long-running fault line in crypto. Bitget’s view is that refusing to act is itself a choice. If a protocol can spot stolen funds and declines to intervene, it is effectively deciding who gets to use the pipes.
The incident has sparked debate about how cross-chain protocols should respond to stolen funds. NEAR Intents landed firmly in the first camp. Tether and Circle, as centralized stablecoin issuers, have long had freezing powers built into their tokens.
Attribution remains open. Theories point to possible involvement by North Korean-linked actors, but Bitget has not confirmed any specific affiliation, and investigations are ongoing.
What this means
For Bitget customers, the User Protection Fund is covering losses, and withdrawals have been resuming since September 28.
The failure sat in third-party software with privileged access. A vendor’s zero-day can become your $387.5 million problem.
With only about 0.2% of stolen funds recovered, the weak state of asset recovery may invite more regulatory scrutiny of how these platforms handle illicit flows.
Disclosure: This article was edited by John Chen. For more information on how we create and review content, see our Editorial Policy.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)