NEAR Intents has blocked more than $50 million in attempted transfers linked to the September 24 Bitget hack, while THORChain has refused to selectively censor attacker-linked addresses, highlighting a sharp divide over how decentralized protocols should handle stolen funds.
The attack on Bitget resulted in a loss of $387.5 million. According to Bitget CEO Gracy Chen, the attacker first ran two small test transfers at 6:31 p.m. UTC on Sept. 24 using 0.184 ETH and 193 TRX, staying below risk-control thresholds. About 30 minutes later, the attacker moved roughly $361 million across 17 transactions on eight networks: Ethereum, XRP, Zcash, BNB Chain, Base, Arbitrum, Optimism, and Avalanche.
Bitget detected a reconciliation mismatch seven minutes after the first large transfer and halted platform-wide withdrawals. The attacker had already exploited a zero-day flaw in third-party security software to obtain admin credentials, inserted fake withdrawal commands into Bitget’s wallet backend, and then deleted digital traces. Bitget said private keys and cold wallets were not touched and is working with Mandiant and SlowMist, with a full incident report expected this week.
NEAR Intents general manager Alex Shevchenko said the platform’s SHIELD risk system flagged and blocked the attempted laundering flows. About $503,000 was frozen, while approximately $166,000 in suspected stolen funds slipped through. NEAR Intents also said it will waive the 5% bounty for freezing funds and another 5% for recovery so more money can be returned to Bitget.
Circle and Tether froze an attacker-linked wallet holding $318,013 in USDT and USDC. Bitget’s $465 million user protection fund will absorb the loss, with corporate reserves of more than $1.4 billion refilling it to at least $300 million within a week. Bitcoin withdrawals resumed Monday with more than 3,000 BTC processed in the first hour, and Ethereum withdrawals are expected to reopen Sept. 29.