Bitget lost about $387.5 million on September 24 after attackers used stolen admin credentials to inject withdrawals that its risk checks treated as internal. Its first alarm halted user withdrawals while the backend kept signing, according to a dev.to analysis.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence35
Chainalysis tied the $387 million Bitget hack to North Korea-linked hackers, saying it pushed their 2026 crypto theft past $1 billion. Its AI cut more than 20 hours of tracing to minutes, while the bill falls on a Bitget user fund the exchange puts above $464 million.
Perspective Coverage
3 publishers
- Builder
- Builder 32%
- Operator
- Operator 41%
- Investor
- Investor 27%
Reality
- Evidence70
- Adoption25
- Hype gap+35
- Incentives60
- Confidence65
NEAR Intents' SHIELD layer refused all but $166,000 of a $50 million-plus attempt by Bitget's hackers. That makes screening policy the clearest difference between NEAR and THORChain. Each protocol carries a different exposure because of it.
Perspective Coverage
4 publishers
- Builder
- Builder 36%
- Operator
- Operator 35%
- Investor
- Investor 29%
Reality
- Evidence58
- Adoption35
- Hype gap+25
- Incentives66
- Confidence58
Suspected North Korean hackers have moved $3.8 million of Bitget's $387.5 million into Zcash's shielded pool, about 1% of the haul. About $24 million of stolen ZEC remains in transparent addresses that exchanges and police can still freeze.
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+12
- Incentives50
- Confidence60
Wallets tied to the $387.5 million Bitget hack moved 2,746 ZEC, about $3.9 million, into Zcash's Ironwood shielded pool on September 30. The deposit is about 1% of the theft, and across every route tracked so far roughly 13 dollars have gone dark for each dollar frozen.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence65
NEAR Intents' SHIELD blocked $50 million of Bitget hack funds while THORChain declined Bitget's request to stop the flow. Lawyer Yuriy Brisov says claimants can use that shown control against NEAR in cases far beyond this one.
Reality
- Evidence40
- Adoption30
- Hype gap+30
- Incentives40
- Confidence35
Bitget CEO Gracy Chen said the exchange's $387.5 million breach ran through a vulnerability in a third-party security product that gave attackers internal credentials to sign off fraudulent withdrawals. The loss was about 83% of its $464 million Protection Fund.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives70
- Confidence60
Bitget CEO Gracy Chen publicly asked THORChain to refuse service to the wallets that took $387.5 million, after Circle and Tether stopped nearly $318,000. Much of the rest now depends on a no-KYC swap protocol that has declined to block stolen funds in earlier hacks, including its own.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 40%
- Investor
- Investor 22%
Reality
- Evidence57
- Adoption44
- Hype gap+12
- Incentives68
- Confidence55
Bitget now puts its September breach at $387.5 million, and AMLBot estimates $343 million of it sat untouched in 13 attacker wallets on Sept. 25. The phased withdrawals due from Sept. 28 are the better guide to whether customer money is safe.
Perspective Coverage
15 publishers
- Builder
- Builder 25%
- Operator
- Operator 43%
- Investor
- Investor 32%
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence62
THORChain turned down Bitget's request to block addresses tied to a suspected North Korean theft, though it paused its own chain over a $10.7 million hack in May. That pause showed its operators move fast when the loss is theirs. Exchanges downstream are left to screen what THORChain lets through.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence40
Bitget CEO Gracy Chen asked Thorchain to refuse service to the hackers behind a theft the exchange now puts at $387.5 million. After the Bybit breach, Thorchain's validators reversed a trading halt within 30 minutes, so recovery plans have little reason to count on the protocol's help.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence55
GoPlus Security says THORChain validators can halt the swaps that moved about $51.5 million of Bitget's stolen bitcoin and XRP. If that power exists, each DPRK-linked transfer the network signs is a choice made by its roughly 100 node operators.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+12
- Incentives
- Insufficient
- Confidence35
Cosmos Hub validators moved 1,227,121 ATOM, about $2.1 million, from the Neutron exploiter's wallet at restart with no signature from its owner. Anyone treating a Hub balance as settled now relies on the validators as well as the key.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence50
Version 3.20 lets Monero and Zcash trade against bitcoin, ether and stablecoins inside THORChain's own pools, which makes pool depth rather than the 8.9% price pop the figure that decides how much of this route is usable.
Reality
- Evidence26
- Adoption28
- Hype gap+34
- Incentives61
- Confidence31
CertiK puts Maya Protocol's direct loss at $1.7 million. A developer tracking the incident puts total impact near $11 million. The gap is the part audit tooling cannot see.
Reality
- Evidence52
- Adoption44
- Hype gap+18
- Incentives63
- Confidence45
Six bugs, none fatal alone, drained Maya Protocol and took CACAO down about 89 percent. THORChain lived through the same chained-logic pattern in May.
Reality
- Evidence55
- Adoption48
- Hype gap+18
- Incentives62
- Confidence46