Bitget Hack Exposes Weakness in DeFi Protocols
Bitget, a cryptocurrency exchange, has been left to clean up the mess after a massive hack on September 24, 2026, that drained approximately $387.5 million from its hot and warm wallets. The breach, which spanned multiple blockchain networks including Ethereum, Tron, and the XRP Ledger, was attributed to a zero-day vulnerability in third-party security software.
The attackers used the flaw to grab high-level credentials and issue fraudulent withdrawal commands, erasing their digital footprints in the process. CEO Gracy Chen confirmed that the exchange's cold wallets and private keys remained protected throughout the incident.
Bitget suspended withdrawals after the breach and gradually resumed them on September 28, with users' losses being fully covered by the exchange's User Protection Fund, valued at over $464 million before the breach.
NEAR Intents, a cross-chain protocol, stood out as a notable exception in its response to the hack. Its SHIELD risk-intelligence system identified and halted over $50 million in illicit laundering attempts tied to the Bitget hack, with actual freezes totaling $503,000 and $166,000 slipping through before the system caught on.
Bitget had offered a 5% bounty on recovered funds, but NEAR Intents waived it. Stablecoin issuers Tether and Circle also stepped in, freezing between $320,000 and $340,000 linked to the stolen funds.
The incident has sparked debate about how cross-chain protocols should respond to stolen funds, with Bitget arguing that refusing to act is itself a choice. The neutrality argument raises questions about the responsibility of protocols in preventing illicit flows.