TLDR
- Hackers drained $387.5 million from Bitget exchange on Sept. 24 using a zero-day vulnerability.
- NEAR Intents’ SHIELD security protocol successfully intercepted over $50 million in theft-related transaction attempts.
- The breach exploited a previously unknown flaw in third-party security software, granting administrative privileges and allowing withdrawal manipulation.
- Bitget will deploy its $465 million user protection reserve to compensate victims, with plans to replenish it to $300 million minimum within seven days.
- THORChain declined Bitget’s request to blacklist attacker addresses, maintaining its policy against selective transaction censorship.
A sophisticated cyberattack targeting Bitget exchange resulted in the theft of $387.5 million on Thursday. Following the breach, the stolen cryptocurrency rapidly dispersed across multiple blockchain networks.
NEAR Intents, a cross-chain asset exchange protocol, successfully prevented a significant portion of the stolen assets from being laundered. According to General Manager Alex Shevchenko, the platform’s SHIELD security infrastructure identified and halted over $50 million worth of transfer attempts linked to the security breach.
Shevchenko confirmed the system successfully immobilized $503,000 during active transfers. However, approximately $166,000 in potentially compromised funds managed to evade detection.
Anatomy of the Bitget Security Breach
In a detailed discussion with The Block, Bitget CEO Gracy Chen provided a comprehensive breakdown of the attack sequence. The assault commenced at 6:31 p.m. UTC on Sept. 24 with two preliminary test transactions.
These initial probes consisted of 0.184 ETH and 193 TRX. The perpetrators deliberately kept these amounts below Bitget’s automated risk detection thresholds, allowing them to pass without raising security flags.
Approximately half an hour later, the attackers initiated large-scale fund extractions. Chen detailed that 17 separate transactions spanning eight blockchain networksāincluding Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalancheāresulted in approximately $361 million in losses.
Bitget’s response was swift. The exchange’s reconciliation infrastructure detected irregularities merely seven minutes following the first major withdrawal, prompting an immediate platform-wide suspension of all user withdrawals.
However, by that point, the perpetrators had already penetrated an internal administrative system. Chen explained the attackers leveraged a zero-day vulnerability in external security software to acquire legitimate administrator credentials.
This elevated access enabled the attackers to inject fraudulent withdrawal instructions directly into Bitget’s wallet infrastructure, which processed them as legitimate requests. The intruders subsequently erased their digital footprint, which Chen identified as the most challenging aspect of the forensic investigation.
Bitget emphasized that its private cryptographic keys and cold storage wallets remained secure and untouched. The organization has enlisted security specialists Mandiant and SlowMist and intends to publish a comprehensive incident analysis this week.
While declining to identify specific suspects, Chen indicated that Bitget suspects the same criminal organization responsible for several other recent cryptocurrency thefts.
Contrasting Responses from NEAR Intents and THORChain
The incident has reignited discussions about how decentralized crypto platforms should address illicit funds. Chen reached out to THORChain, a decentralized exchange protocol, requesting the blacklisting of addresses associated with the attackers.
THORChain rejected the request. The protocol maintained that it does not implement selective fund freezing, although it has implemented network-wide pauses during critical situations.
NEAR Intents adopted a contrasting approach. Shevchenko announced his platform would proactively intervene to prevent stolen assets from transiting through its infrastructure.
He further stated NEAR Intents would forgo Bitget’s offered 5% bounty for freezing funds, along with an additional 5% for asset recovery, to maximize the amount returned to Bitget. Meanwhile, Circle and Tether took action on Friday, freezing an attacker-linked wallet containing $318,013 in USDT and USDC.
Bitget’s user protection reserve contained $465 million as of Sept. 25 and will cover the losses. Chen confirmed that corporate reserves exceeding $1.4 billion will restore the fund to a minimum of $300 million within one week.
Bitcoin withdrawal services on Bitget resumed Monday, with over 3,000 BTC processed during the initial hour. Ethereum withdrawal functionality will return on Sept. 29.





