Cryptocurrency exchange Bitget has raised concerns regarding the willingness of certain decentralized finance protocols to assist in recovering stolen funds following a major security breach.
On September 24, 2026, attackers drained approximately $387.5 million from Bitget's hot and warm wallets across the Ethereum, Tron, and XRP Ledger networks. According to the exchange, the breach originated from a zero-day vulnerability in third-party security software that allowed attackers to obtain high-level credentials, issue fraudulent withdrawal commands, and erase their digital footprints. Chief Executive Officer Gracy Chen noted that the exchange's cold wallets and private keys remained secure during the incident.
Following the breach, Bitget suspended withdrawals and began gradually restoring them on September 28. The exchange stated that user losses would be fully covered by its User Protection Fund, which held a value of over $464 million prior to the incident.
Recovery Efforts and Industry Response
Bitget publicly criticized parts of the DeFi sector for refusing to help recover stolen assets, arguing that declining to intervene when illicit funds are identified represents an active choice in how transaction networks are utilized. However, the exchange credited cross-chain protocol NEAR Intents as a notable exception.
NEAR Intents reported that its SHIELD risk-intelligence system identified and halted over $50 million in illicit laundering attempts connected to the hack. While transactions were executing, SHIELD froze $503,000, though approximately $166,000 escaped before being caught. NEAR Intents also waived a 5% recovery bounty offered by Bitget.
Additionally, centralized stablecoin issuers Tether and Circle froze between $320,000 and $340,000 linked to the stolen assets. Despite these interventions, total recovered funds are estimated at roughly 0.2% of the overall losses.
Ongoing Investigations
Investigations into the breach remain ongoing. While theories have pointed toward possible involvement by North Korean-linked actors, Bitget has not confirmed any specific affiliations.
The incident has intensified industry debates surrounding cross-chain protocols, third-party software vulnerabilities, and the challenges of asset recovery in decentralized environments, which may draw increased regulatory scrutiny regarding how platforms manage illicit capital flows.


