Bitget has publicly criticized specific decentralized finance protocols for their refusal to help trace stolen funds following a major security breach. On September 24, 2026, attackers drained approximately $387.5 million from the exchange's hot and warm wallets across Ethereum, Tron, and the XRP Ledger. The exploit utilized a zero-day vulnerability in third-party security software to obtain high-level credentials and issue fraudulent withdrawal commands before erasing digital footprints.
In contrast to the uncooperative protocols, NEAR Intents reported that its SHIELD risk-intelligence system identified and halted over $50 million in illicit laundering attempts. While actual freezes were smaller, with $503,000 stopped during execution, the protocol waived Bitget’s offered 5% bounty on recovered funds. Stablecoin issuers Tether and Circle also froze between $320,000 and $340,000 linked to the theft. Overall recovery is estimated at just 0.2% of total losses, though Bitget confirmed its User Protection Fund, valued at over $464 million pre-breach, would fully cover customer losses.
The incident highlights a significant operational fault line within the crypto ecosystem regarding asset recovery and compliance responsibilities. Bitget’s criticism underscores the tension between permissionless infrastructure ideals and the practical need for coordinated responses to criminal activity. By contrasting the non-cooperation of some DeFi protocols with NEAR Intents’ active intervention, the exchange frames the refusal to act as an ethical choice that effectively determines who controls financial rails. This dynamic suggests that institutional exchanges may increasingly view selective cooperation from decentralized entities as a prerequisite for broader market integration.
From a regulatory and risk perspective, the reliance on third-party software vendors introduces substantial systemic vulnerability. The breach originated from a zero-day flaw in external security tools, demonstrating how supply chain risks can translate directly into massive financial liabilities. With only 0.2% of funds recovered, the limited efficacy of current cross-chain tracking mechanisms may invite heightened scrutiny from regulators concerned about illicit flows. Future developments will likely focus on whether such incidents accelerate the adoption of mandatory compliance standards or enhanced liability frameworks for infrastructure providers.


