Trending

    Bitget suffers $387.5 million hack prompting DeFi accountability discussions

    Section editor: ·Low4 articles covering this·2 news sources·Updated 2 hours ago·World
    Share:
    A visual representation of the Bitget breach and its implications for DeFi accountability and security measures.

    Why it matters

    This breach underscores vulnerabilities in cryptocurrency exchanges and the ongoing debate about the responsibilities of DeFi protocols in asset recovery.

    What happened (in 30 seconds)

    • On September 24, 2026, Bitget suffered a $387.5 million hack due to a vulnerability in third-party security software.
    • NEAR Intents' SHIELD system blocked over $50 million in laundering attempts, contrasting with other DeFi protocols that did not assist in recovery.
    • Bitget's User Protection Fund is covering user losses, but overall recovery rates remain low at approximately 0.2%.

    The context you actually need

    • The breach follows patterns seen in previous hacks, particularly those linked to North Korean actors, raising concerns about the security of exchanges.
    • Bitget attributed the breach to a third-party vendor vulnerability, maintaining that its cold wallets and private keys were secure.
    • The incident has sparked debates over the accountability of permissionless DeFi protocols in tracing and freezing stolen funds.

    What's really happening

    On September 24, 2026, Bitget, a prominent cryptocurrency exchange, experienced a significant security breach that resulted in the unauthorized drainage of approximately $387.5 million from its hot and warm wallets. This incident was made possible by a zero-day vulnerability in third-party security software, which allowed attackers to exploit high-level credentials for fraudulent withdrawals. The breach affected multiple blockchains, including Ethereum, Tron, and the XRP Ledger, highlighting the interconnected nature of the cryptocurrency ecosystem.

    In the aftermath, Bitget suspended withdrawals and initiated recovery efforts, which included leveraging its User Protection Fund, valued at over $464 million prior to the breach. This fund is designed to cover user losses, and Bitget has committed to ensuring that affected users are compensated. As of now, the recovery rate stands at a mere 0.2%, indicating the challenges faced in tracing and reclaiming stolen assets.

    The incident has drawn attention to the role of decentralized finance (DeFi) protocols in asset recovery. Bitget publicly criticized certain permissionless DeFi protocols for their lack of cooperation in tracing or freezing the stolen funds. In contrast, NEAR Intents' SHIELD system demonstrated its effectiveness by blocking over $50 million in laundering attempts, including freezing $503,000 mid-execution. This stark difference in response has ignited discussions about the responsibilities of DeFi protocols, particularly regarding their accountability in preventing and addressing theft.

    The breach also raises questions about the security measures employed by cryptocurrency exchanges and the reliance on third-party vendors. Bitget's assertion that its cold wallets and private keys remained secure suggests that the vulnerability was not within its core infrastructure but rather in the external software it utilized. This incident serves as a reminder of the importance of robust security protocols and the need for exchanges to thoroughly vet their third-party partners.

    As investigations continue, the implications of this breach extend beyond Bitget. The incident may lead to increased regulatory scrutiny on DeFi protocols and their asset recovery practices. Additionally, stablecoin issuers like Tether and Circle have demonstrated their ability to freeze funds, further complicating the landscape of asset recovery in the cryptocurrency space. Overall, this breach highlights the ongoing challenges faced by the industry in balancing security, decentralization, and accountability.

    Who feels it first (and how)

    • Cryptocurrency exchanges: Increased scrutiny on security practices and third-party vendor relationships.
    • DeFi protocol developers: Pressure to enhance accountability and cooperation in asset recovery efforts.
    • Investors and users: Heightened awareness of risks associated with exchanges and DeFi protocols, influencing their investment decisions.

    What to watch next

    • Regulatory developments: Monitor potential regulations targeting DeFi protocols and their responsibilities in asset recovery, which could reshape the industry.
    • Security audits: Watch for increased demand for comprehensive security audits among exchanges and DeFi protocols to prevent similar breaches.
    • Market reactions: Observe how the market responds to this incident, particularly in terms of asset consolidation towards perceived safer options like Bitcoin.
    Known:

    Bitget suffered a $387.5 million breach due to a third-party vulnerability.

    Likely:

    Increased regulatory scrutiny on DeFi protocols and exchanges will emerge as a result of this incident.

    Unclear:

    The full extent of the attackers' identities and the long-term impact on user trust in cryptocurrency exchanges.

    Frequently Asked Questions

    Why it matters?
    This breach underscores vulnerabilities in cryptocurrency exchanges and the ongoing debate about the responsibilities of DeFi protocols in asset recovery.
    What happened (in 30 seconds)?
    On September 24, 2026, Bitget suffered a $387.5 million hack due to a vulnerability in third-party security software. NEAR Intents' SHIELD system blocked over $50 million in laundering attempts, contrasting with other DeFi protocols that did not assist in recovery. Bitget's User Protection Fund is covering user losses, but overall recovery rates remain low at approximately 0.2%.
    What's really happening?
    On September 24, 2026, Bitget, a prominent cryptocurrency exchange, experienced a significant security breach that resulted in the unauthorized drainage of approximately $387.5 million from its hot and warm wallets. This incident was made possible by a zero-day vulnerability in third-party security software, which allowed attackers to exploit high-level credentials for fraudulent withdrawals. The breach affected multiple blockchains, including Ethereum, Tron, and the XRP Ledger, highlighting the
    Who feels it first (and how)?
    Cryptocurrency exchanges: Increased scrutiny on security practices and third-party vendor relationships. DeFi protocol developers: Pressure to enhance accountability and cooperation in asset recovery efforts. Investors and users: Heightened awareness of risks associated with exchanges and DeFi protocols, influencing their investment decisions.
    What to watch next?
    Regulatory developments: Monitor potential regulations targeting DeFi protocols and their responsibilities in asset recovery, which could reshape the industry. Security audits: Watch for increased demand for comprehensive security audits among exchanges and DeFi protocols to prevent similar breaches. Market reactions: Observe how the market responds to this incident, particularly in terms of asset consolidation towards perceived safer options like Bitcoin.
    4 Articles
    Crypto Briefing

    Bitget calls out DeFi protocols after $387.5 million hack, credits NEAR Intents

    Bitget, a cryptocurrency exchange, has reported a significant hack resulting in unauthorized transfers totaling approximately $387.5 million, raising concerns about vulnerabilities in decentralized finance (DeFi) protocols. The incident has prompted ...

    12 hours ago
    Read Full Article
    Cointelegraph

    NEAR Intents says it’s identified the hacker, gives 48-hour ultimatum

    NEAR Intents has identified the hacker responsible for a recent exploit that resulted in a loss of $3.8 million, issuing a 48-hour ultimatum for the individual to respond. General manager Alex Shevchenko confirmed the identification on October 1, 202...

    Cointelegraph

    NEAR Intents suffers $3.8M exploit after assistance with Bitget breach

    NEAR Intents has reported a significant exploit resulting in a loss of $3.8 million, which is linked to a bug affecting deposits and withdrawals. This incident follows a major security breach at Bitget, where unauthorized transfers totaled approximat...

    Cointelegraph

    Bitget’s $388M hack pushes Q3 crypto security losses past $1B

    Bitget, a cryptocurrency exchange, suffered a significant security breach resulting in unauthorized transfers totaling approximately $388 million. This incident contributed to a staggering $1.26 billion in crypto security losses in Q3 2026, with Sept...