Key Takeaways
- A major security breach at cryptocurrency exchange Bitget resulted in the theft of $387.5 million on September 24.
- NEAR Intents reported that its SHIELD security system successfully prevented over $50 million in transaction attempts linked to the stolen funds.
- The perpetrator exploited an unpatched vulnerability in third-party security software to obtain administrator privileges before erasing evidence of the intrusion.
- The exchange’s user protection reserve, valued at $465 million, will compensate affected users, with plans to replenish it to a minimum of $300 million within seven days.
- THORChain declined requests to blacklist addresses associated with the attacker, maintaining its policy against selective transaction filtering.
Cryptocurrency platform Bitget suffered a devastating security compromise on Thursday that resulted in the unauthorized withdrawal of $387.5 million. In the immediate aftermath, the stolen assets began moving rapidly across multiple blockchain networks.
NEAR Intents, a cross-chain asset exchange protocol, announced it successfully intercepted a significant portion of those funds before they could be laundered. According to general manager Alex Shevchenko, the company’s SHIELD security infrastructure identified and halted more than $50 million worth of transfer attempts related to the security incident.
Shevchenko revealed that the platform managed to freeze $503,000 during transit. However, approximately $166,000 in potentially compromised assets still managed to pass through their detection systems.
The Attack Methodology Behind the Bitget Breach
In a detailed discussion with The Block, Bitget’s chief executive Gracy Chen outlined the sequence of events that led to the massive theft. The assault commenced at 6:31 p.m. UTC on September 24 with two preliminary test transactions.
These initial movements involved 0.184 ETH and 193 TRX—amounts deliberately kept small enough to avoid triggering the exchange’s automated risk monitoring thresholds.
Approximately half an hour later, the perpetrator initiated significantly larger withdrawals. Chen explained that 17 separate transactions spanning eight blockchain ecosystems—including Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche—collectively accounted for around $361 million in losses.
The exchange’s detection capabilities proved rapid. Its reconciliation infrastructure identified the discrepancy within just seven minutes of the initial major transfer, prompting an immediate platform-wide suspension of all user withdrawals.
However, by that point, the attacker had already penetrated an internal administrative system. Chen stated that the intruder leveraged a previously unknown vulnerability in external security software to acquire legitimate administrator credentials.
This elevated access enabled the attacker to inject fraudulent withdrawal instructions directly into Bitget’s wallet management backend, which processed them as authorized requests. The perpetrator subsequently removed digital forensic evidence, creating what Chen described as the most challenging aspect of the investigation.
Bitget has emphasized that its private keys and cold storage solutions remained secure and untouched. The organization is collaborating with cybersecurity specialists Mandiant and SlowMist, with plans to publish a comprehensive incident analysis later this week.
While Chen refrained from identifying specific suspects, she indicated that Bitget has reason to believe the same criminal organization is responsible for several other recent cryptocurrency thefts.
Contrasting Approaches: NEAR Intents Versus THORChain
This security incident has reignited discussions about the appropriate response of decentralized cryptocurrency protocols when confronted with stolen assets. Chen directly approached THORChain, a decentralized exchange protocol, requesting the blacklisting of wallet addresses connected to the perpetrator.
THORChain rejected the request. The protocol maintained that it does not implement selective fund freezing, although it has temporarily suspended network operations during critical emergencies in the past.
NEAR Intents adopted a fundamentally different approach. Shevchenko confirmed his platform will proactively intervene to prevent compromised funds from transiting through its infrastructure.
Additionally, he announced that NEAR Intents will forgo the 5% bounty Bitget offered for freezing stolen assets, as well as an additional 5% for fund recovery, to maximize the amount returned to the exchange. In a separate development, stablecoin issuers Circle and Tether froze a wallet associated with the attacker on Friday, immobilizing $318,013 in USDT and USDC.
As of September 25, Bitget’s protection fund held $465 million, which will be utilized to cover the losses. Chen confirmed that the company’s corporate reserves exceeding $1.4 billion will be used to restore the fund to at least $300 million within the next week.
Bitcoin withdrawal services on Bitget resumed Monday, with over 3,000 BTC processed during the initial hour of operations. Ethereum withdrawals are scheduled to reopen on September 29.


