Skip to content

Invest1 publisher3 min readPublished

NEAR Intents, Tether and Circle froze about 0.2% of the $387.5 million taken from Bitget

Bitget has recovered an estimated 0.2% of the $387.5 million hackers drained on September 24, through freezes by NEAR Intents, Tether and Circle. Its own User Protection Fund is covering the rest, so the protocols that cooperated cut Bitget's bill by less than $1 million.

The Investor · Invest desk

What happened

  • Bitget said on X that some DeFi protocols won't assist when stolen money needs to be got back, and singled out NEAR Intents as the exception.
  • NEAR Intents says its SHIELD system halted over $50 million in laundering attempts tied to the hack, but it froze $503,000, and about $166,000 got through.
  • Bitget says its User Protection Fund, worth over $464 million before the breach, will cover user losses in full, and withdrawals began returning on September 28.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Bitget's own fund carries almost the whole bill, because the $387.5 million loss is about 84% of what the fund held before the breach.
  • contradiction NEAR Intents' $50 million headline and its $503,000 freeze measure different things, and money actually frozen is only about 1% of what it says it halted.
  • exposure A zero-day in a vendor's security tool gave the attackers credentials that could order withdrawals, so the software an exchange buys to protect its hot wallets is part of their risk.
  • precedent Crypto Briefing expects recovery near 0.2% to bring more regulatory scrutiny of how platforms handle illicit flows, and Bitget has already argued in public that a neutral protocol is choosing to let stolen money move.

All the freezes reported so far add up to $503,000 from NEAR Intents' SHIELD system and $320,000 to $340,000 from Tether and Circle [8][10], or $823,000 to $843,000 in total [1]. Against a loss of about $387.5 million [1], the frozen sum comes to 0.21% to 0.22% [2]. Crypto Briefing puts overall recovery at an estimated 0.2% [11], so the freezes account for essentially all of it. NEAR Intents, the one protocol Bitget singled out for praise [12], supplied about 60% of the frozen total [8].

NEAR's two figures have to be kept apart. NEAR Intents reported that SHIELD identified and halted over $50 million in laundering attempts tied to the hack [7]. It froze $503,000 while transactions were still executing, and about $166,000 got through before the system caught on [8][9]. The amount frozen is about 1% of the amount halted [3]. The report counts the two separately. A halted attempt stops the funds moving through NEAR Intents, and only a freeze takes them away from the attacker. NEAR Intents also waived the 5% bounty Bitget had offered on recovered funds [13]. On $503,000, that bounty would have come to about $25,150 [5].

Bitget made its case on X. It argues that refusing to act is itself a choice: a protocol that can spot stolen funds and declines to step in is deciding who gets to use the pipes [14]. The report does not name the protocols Bitget says refused. Their help could have been worth two very different amounts. If they had flagged and frozen at NEAR's rate, the recovery would still have rounded to a fraction of a percent of $387.5 million. If their halts had kept the stolen money in tokens whose issuers can freeze them, as Tether and Circle can [17], they would have fed the only freezes that recovered anything.

I think Bitget is right that cooperation decides recovery, but it overstates how much recovery was ever available here. The counter-thesis is that NEAR's halts were worth the $50 million the attacker could not launder through it. That cost to the attacker never shows up as a recovered dollar. If any of that $50 million is later frozen or returned, the counter-thesis is right and my view is wrong.

Either way, Bitget pays. It told users its User Protection Fund, valued at over $464 million before the breach, would cover their losses in full [6]. The theft equals about 84% of that value [4]. After the freezes, roughly $386.7 million is still missing [6]. Paying that from the fund would leave about $77 million or more in it [7]. The promise to users does not depend on getting money back, and withdrawals started coming back on September 28 [4], four days after the theft [9].

The attackers got in through a zero-day flaw in third-party security software. They used it to take high-level credentials, sent fraudulent withdrawal commands and then erased their tracks [3]. The theft hit chains including Ethereum, Tron and the XRP Ledger [2]. CEO Gracy Chen said the exchange's cold wallets and private keys stayed protected [5]. The money came out of the hot and warm wallets those credentials could reach [1]. Nobody has confirmed who did it. Some theories point to North Korean-linked hackers, but Bitget has not confirmed that [16].

What to watch

  • Whether Bitget names the DeFi protocols it says refused to help, and whether any of them then freeze funds.
  • Whether any of the $50 million NEAR Intents says it halted is later frozen or returned, which would lift recovery above 0.2%.
  • Confirmation of who carried out the attack, and any regulatory scrutiny of how platforms handle illicit flows after a recovery this small.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories