NEAR Blocks $50M From Bitget Hackers

NEAR Intents blocked over $50M in attempted flows linked to Bitget’s $387.5M hack, freezing funds as attackers tried moving stolen assets.

NEAR Blocks $50M From Bitget Hackers
NEAR Blocks $50M From Bitget Hackers

Bitget's recovery effort following its massive September 24 security breach has entered a new phase, with more than $50 million in attempted stolen-fund flows identified through NEAR Intents as attackers tried to move assets across crypto infrastructure.

NEAR Intents' SHIELD risk-detection system identified activity connected to the Bitget exploit and shared the intelligence with participants in the network. Another approximately $503,000 was frozen during execution and remains restricted pending legal and asset-recovery procedures.

NEAR Intents Flags Over $50M Linked to Bitget Hack

Bitget initially estimated the affected assets at $351.6 million. Subsequent transaction classification expanded that figure to approximately $387.5 million after additional activity involving Zcash and TRON was included.

The affected assets included ETH, XRP, USDT, USDC, ZEC, BNB, AVAX, TRX and other tokens distributed across Ethereum, EVM networks, XRP Ledger, Zcash and TRON. Bitget later said its investigation determined that a critical backend system within its wallet infrastructure had been compromised.

According to the exchange, attackers were able to spoof transaction data and trigger unauthorized transfers through its authorization infrastructure. Bitget has said that private keys themselves were not compromised.

EtherWorld previously documented how April alone recorded more than $635 million in DeFi exploits, while August emerged as another damaging month for DeFi security. Once the Bitget assets began moving, investigators observed attempts to distribute them across different chains and services.

According to NEAR ecosystem participants, its SHIELD system detected more than $50 million in attempted flows associated with the incident. After duplicate transactions were filtered, only a relatively small amount reportedly passed successfully through the infrastructure.

SHIELD Shows How Permissionless Systems Can Respond to Hacks

NEAR co-founder Illia Polosukhin argued that permissionless infrastructure means users do not require authorization to own or transfer assets or deploy contracts. It does not necessarily mean every application or liquidity provider must blindly process every transaction.

The system provides shared, real-time risk intelligence that participants can use to identify suspicious activity associated with hacks and other security incidents. Partners can both consume and contribute information, allowing threat intelligence to spread while an incident is unfolding.

Cross-chain infrastructure has repeatedly emerged as both an attack surface and a laundering route. EtherWorld previously covered how KelpDAO migrated away from LayerZero following a $292 million exploit, an incident that exposed risks around cross-chain verification infrastructure.

The response to that attack also demonstrated how ecosystem participants can coordinate after an exploit. As EtherWorld reported in DeFi Unites After KelpDAO $292M Hack, emergency actions included freezing assets connected with the exploiter while investigators followed funds across different ecosystems.

More recently, an Ethereum Safe wallet lost $7.73 million in rsETH after an authorized third-party module was exploited. In that case, the incident involved a public multicall, attacker-controlled liquidity and intervention around the stolen assets.

Cross-Chain Laundering Is Becoming a Security Battleground

Unlike funds moving through a single blockchain, cross-chain laundering can involve bridges, decentralized exchanges, liquidity providers, swaps and multiple intermediary addresses. Every additional step makes coordination more complicated.

On-chain investigator ZachXBT alleged that some funds connected to the Bitget attack were being laundered through over-the-counter traders operating through public Discord and Telegram channels. Those allegations remain part of an ongoing tracing effort and should not be interpreted as proof that every identified account knowingly participated in laundering.

EtherWorld previously reported that North Korean-linked hackers allegedly stole $285 million from Drift Protocol, highlighting how sophisticated attackers increasingly combine technical compromise, social engineering and rapid asset movement. North Korea-linked threat actors have also increasingly targeted infrastructure outside smart contracts.

The Lazarus Group's Mac-focused crypto malware campaigns demonstrated how attackers can target credentials, browser sessions, wallet access and operational systems rather than attempting to break blockchain cryptography itself. Other incidents have exposed similarly unconventional attack surfaces.

EtherWorld reported how legacy Ethereum wallets lost more than $800,000 after compromised private keys were linked to older wallet-generation practices. A more recent crypto RAT malware campaign reportedly drained $235,000 within 48 hours, showing how endpoint compromise and session manipulation can bypass protections without exploiting a blockchain protocol.

Bitget Recovery Could Test a New Model for Crypto Security

Bitget says the vulnerability involved in the September 24 incident has now been identified and remediated, with Mandiant and SlowMist assisting its investigation and fund-tracing efforts. The exchange has also begun restoring withdrawal services after temporarily suspending them following the attack.

Bitget CEO Gracy Chen publicly thanked NEAR Intents and SHIELD for identifying attempted laundering flows, freezing funds during execution and supporting the recovery process. She also said NEAR Intents waived its own bounty share so additional resources could go toward recovery.

Permissionless infrastructure is valuable precisely because users do not need centralized approval to transact. At the same time, applications interacting with that infrastructure can still develop mechanisms for identifying assets associated with confirmed security incidents.

As attackers become faster at moving assets between chains, the industry's response may need to become equally fast. For Bitget, the investigation and recovery process remains ongoing.


To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Sponsored
ETHShala

Understand Ethereum. Shape the Future — learn EIPs with ETHShala.

Inviting Web3 projects to partner with EtherWorld and increase visibility across the Ethereum ecosystem.

EIPs Insight

Track Ethereum protocol upgrades, EIPs & governance — all in one place.

EtherWorld.co × Avarch

Gain hands-on Web3 experience with our internship program.

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free