The platform said it will compensate users affected by the hack, which stemmed from a bug that affected deposits and withdrawals. Cross-chain protocol NEAR Intents reported a security breach that resulted in the loss of $3.8 million in user funds. In a Thursday X post, the protocol said that the incident was the result of a “bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.” NEAR said that it would compensate users in full for the lost funds, and the “contract-side vulnerability has been patched” to prevent similar attacks. “The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery,” said the platform. “A detailed report will be shared publicly in the following days.” Read more
Crypto security losses reached $1.26 billion in Q3 across 247 incidents, with September alone accounting for roughly $769 million. Losses from crypto security incidents climbed to $1.26 billion in the third quarter of 2026, largely driven by the $387.5 million hack of crypto exchange Bitget. Losses rose 53.9% from $819.4 million in Q2, while the number of security incidents increased about 13% from 219 to 247, according to data from blockchain security company CertiK. The Bitget hack accounted for about 31% of Q3 losses, making it the quarter’s largest recorded incident under CertiK’s methodology. Liquid Network’s $319 million exploit on Sept. 6 ranked second, followed by Tectonic at $120 million and the $112.7 million Coldcard theft. Read more
Bitget CEO Gracy Chen said that a protection fund created by the company in 2022 “absorbed the financial impact of the incident“ that resulted in $388 million in user losses. The CEO of cryptocurrency exchange Bitget reported a gradual return to normal operations following a security breach that resulted in the loss of $388 million of user funds. In a Wednesday X post, Bitget CEO Gracy Chen said withdrawals for all tokens would resume on Friday, and the exchange has already restored access to users’ Bitcoin (BTC), Ether (ETH), and USDt (USDT). As part of recovery efforts, Bitget’s ‘Protection Fund’ also reached $309 million. The fund, initially set up by Bitget in January 2022 with 5,500 BTC, was intended to reimburse users’ potential losses that were “not a result of any misconduct from the user or the platform itself,” presumably including some security breaches. According to the company, funds were available “for instant deployment whenever the need arises.” Read more
THORChain will not — or can not — block addresses linked to the $387.5 million Bitget hack. Can the devs be prosecuted for money laundering? It’s complicated, says crypto lawyer Yuriy Brisov. After suspected North Korean hackers exploited crypto exchange Bitget for $387.5 million last week, investigators were able to quickly flag and trace the recipient addresses. Bitget CEO Gracy Chen then controversially demanded that decentralized cross-chain swaps platform THORChain “refuse service to these addresses.” THORChain responded: The move was controversial, especially given the protocol was halted immediately in May when $10.7 million of its own funds were exploited. Complicating matters, THORChain has retired its admin key and doesn’t have an easy way to censor addresses, even if it wanted to. Read more
SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool. SlowMist traced the earliest logged malicious activity linked to Bitget’s $388 million theft to Aug. 31, when an attacker exploited a zero-day vulnerability affecting a third-party security product. Attackers stole the funds from Bitget’s hot wallets on Sept. 24 (UTC), transferring assets to addresses they controlled across several blockchains. SlowMist’s investigation identified malicious activity involving two third-party security products and a wallet application host. According to a SlowMist progress report, the attacker used a hidden script to access the database of what SlowMist called “Product A,” after retrieving its password from an environment variable. Similar activity was later detected on two other nodes on Sept. 23 and Sept. 25. The dates and times in the report are in UTC+8. Read more
Gracy Chen said she saw the 2025 Bybit hack as a “good reference point” for Bitget’s security breach, noting that only a small percentage of funds had been frozen or recovered. The CEO of crypto exchange Bitget isn’t sure that the company can fully freeze or recover all the assets compromised in a security breach last week that resulted in the loss of $388 million in crypto. Speaking on Cointelegraph’s Chain Reaction released Tuesday, Bitget CEO Gracy Chen said she was looking at the February 2025 hack of crypto exchange Bybit as a “good reference point” for Thursday’s breach. Hackers stole about $1.5 billion worth of Ether (ETH) from Bybit, and the company reported only freezing and recovering a combined $80 million. “I’m actually not very optimistic because after a year or so of Bybit’s hack, they’ve only [been able to freeze] about 3.5% of the total stolen funds,” said Chen. “That’s only the freezing. It’s not about recovery yet.” Read more
The cross-chain protocol said it actively prevents stolen funds from being laundered, drawing a contrast with THORChain’s position that it does not selectively censor transactions. NEAR Intents said it blocked more than $50 million in attempted transfers linked to the Bitget hack. Attackers stole $387.5 million from Bitget on Thursday. A significant portion of these funds moved across chains to Ethereum, according to Alex Shevchenko, general manager of NEAR Intents, a protocol that lets users swap crypto assets across blockchains. Shevchenko said its SHIELD system detected and blocked more than $50 million in attempted transfers, which subsequently went to other providers. It managed to freeze $503,000 in funds during execution, while around $166,000 in suspected stolen funds passed through. Read more
Some stolen assets have been frozen, but Bitget has yet to disclose how much has been recovered as investigators continue to assess a possible North Korea link. Bitget CEO Gracy Chen said the crypto exchange’s recent $388 million exploit stemmed from a vulnerability in a third-party security product that allowed the attacker to obtain “high-level internal credentials.” In comments to Cointelegraph, Chen said the attacker used those credentials to issue fraudulent withdrawal commands. Bitget’s private keys were not compromised, and its cold wallets were not affected, she said. Bitget said it has since addressed the security flaw and tightened its withdrawal controls, including restricting internal access, adding independent verification for withdrawals and increasing monitoring for unusual activity. Read more
Ether withdrawals are scheduled to return Tuesday and USDt on Wednesday as Bitget restores services following last week’s $388 million hack. Crypto exchange Bitget is resuming withdrawals after a security breach affecting nearly $388 million in assets, as the attacker continues moving stolen crypto through THORChain. Bitget said it resumed Bitcoin (BTC) withdrawals Monday after suspending them following last week’s security incident, with additional assets and networks set to follow over the coming days. The Sept. 24 breach compromised part of Bitget’s hot and warm wallet infrastructure, while its cold wallets remained secure, according to the exchange. Read more
THORChain refuses to blacklist addresses linked to the Bitget hack. Vitalik Buterin says Ethereum is evolving from being a mere blockchain, into a world cryptographic computer. Stop me if you’ve heard this before: A centralized exchange with lax security gets hacked by the North Koreans for $387.5 million, and then somehow shifts the blame game onto a decentralized exchange for not blacklisting the addresses. The drama began on September 25 when the Asian focused exchange Bitget revealed $351.6 million in “unauthorized transfers” but it later upgraded the tally to $387.5 million. It said a preliminary investigation had linked the IP addressees to VPN services used by a North Korean hacking group. While that isn’t firm proof, CEO Gracy Chen said its investigators had flagged other similarities with previous thefts. North Korean hackers were believed to be behind the $1.5 billion Bybit exchange hack, and much of the funds from that attack were then swapped on the decentralized exchange THORChain (which is not a...
The Bitget breach announced on Thursday affected about $35 million more than previously reported, based on an analysis of assets on Zcash and TRON. Crypto exchange Bitget released an updated incident report on Thursday’s security breach, clarifying that about $388 million in assets had been affected and not $352 million as previously reported. In a Friday update, Bitget said it would continue to pause withdrawals following the security breach, and the company had launched a bounty program to incentivize freezing or recovering the assets. The exchange confirmed that “$387.5 million were transferred to attacker-controlled addresses” based on onchain tracing — about $35 million more than reported on Thursday. “The revised figure reflects a more complete accounting of transfers that occurred during the incident, adding affected assets on Zcash and TRON that were not included in the initial estimate,” said Bitget. “It does not reflect further unauthorized transfers. The incident remains contained and no further u...