Crypto exchange Bitget suffered a $387.5 million loss after an attacker exploited a zero-day flaw in external security software to gain admin credentials and inject fake withdrawal commands. The intrusion began with small test transfers that bypassed risk controls, followed by large-scale movements across eight networks including Ethereum and XRP. Bitget’s reconciliation system detected the mismatch within seven minutes, prompting a platform-wide withdrawal freeze.
In response to the theft, NEAR Intents utilized its SHIELD system to flag and block more than $50 million in attempted fund laundering, freezing $503,000 directly. Conversely, decentralized protocol THORChain refused Bitget’s request to selectively freeze attacker-linked wallets, citing its operational stance against selective censorship. Circle and Tether also froze a wallet containing $318,013 in stablecoins. Bitget CEO Gracy Chen confirmed that private keys remained secure and stated the company’s protection fund will absorb the losses.
The divergent responses from cross-chain protocols highlight a growing tension between asset recovery efforts and decentralized neutrality principles. While NEAR Intents actively intervened to block stolen funds, THORChain’s refusal underscores the difficulty of coordinating enforcement actions across permissionless infrastructure. This split suggests that institutional victims may increasingly rely on centralized or semi-centralized intermediaries for immediate containment, as fully decentralized protocols often lack mechanisms for selective intervention without compromising their core ethos.
From an operational risk perspective, the incident exposes vulnerabilities in third-party security integrations rather than direct key management failures. The attacker’s ability to exploit a zero-day flaw in external software to manipulate backend systems indicates that supply chain risks remain a critical threat vector for exchanges. Market participants should monitor how such breaches influence insurance frameworks and whether regulatory bodies begin mandating stricter audits of external dependencies used in custody and transaction processing infrastructure.


