Bitget Hack Update: ETH Withdrawals Reopen and NEAR Intents Holds Hacker-Linked Funds

Abstract:Bitget confirmed ETH withdrawals reopened Sep. 29 across Ethereum, BSC, Arbitrum, Base and Optimism after its ~$388M breach. NEAR Intents says Bitget-linked actors attempted >$50M in swaps; ~$503K was held and ~$166K passed through.

Bitget has completed the second stage of its phased withdrawal recovery.

After BTC withdrawals reopened on September 28, Bitget confirmed:

ETH withdrawals reopened at 08:00 UTC on September 29

across:

  • Ethereum;
  • BNB Smart Chain;
  • Arbitrum One;
  • Base;
  • Optimism.

The next planned stage is USDT at 08:00 UTC on September 30, which is later than this reports publication cutoff.

First-hour ETH flow

Bitget reported that by 09:00 UTC—one hour after ETH withdrawals reopened—it had recorded approximately:

  • 9,674 ETH inflows
  • 9,023 ETH outflows

for a net inflow of approximately:

651 ETH

This is an exchange-reported operational snapshot.

It is not:

  • an independent reserve audit;
  • full-day withdrawal volume;
  • proof that every chain/asset has recovered.

It does show that the reopened ETH withdrawal system was processing meaningful two-way flows rather than merely displaying an enabled button.

Current recovery schedule

Confirmed/planned sequence:

September 28

BTC withdrawals restored on Bitcoin and BSC.

September 29

ETH withdrawals restored on Ethereum, BSC, Arbitrum One, Base and Optimism.

September 30

USDT scheduled on Ethereum, BSC, Solana and Tron.

October 2

Other tokens, fiat and P2P scheduled to return.

The recovery remains partial until the later phases execute.

The incident amount remains approximately $388M

Bitgets current official estimate is approximately:

$388 million

in affected assets transferred from hot/warm wallet infrastructure.

Bitget says:

  • 12 wallet addresses were associated with the incident;
  • 11 blockchains were involved;
  • cold wallets were not compromised;
  • private keys were not compromised.

Leading attack path

Bitgets latest explanation says hackers may have exploited a vulnerability in a:

third-party security product

to obtain high-level internal credentials.

Those credentials were then used to:

  • impersonate legitimate activity;
  • issue fraudulent withdrawal commands;
  • bypass existing risk controls.

This is a security-tool / supply-chain trust failure rather than simple private-key theft.

NEAR Intents intercepted part of the laundering flow

A new cross-chain-control development emerged after the exchange recovery began.

NEAR Intents says attacker-linked actors attempted more than:

$50 million

of transfers through its service.

That figure is attempted volume, not money frozen.

NEAR Intents says its SHIELD screening system:

  • rejected most suspicious attempts;
  • held approximately $503,000;
  • allowed approximately $166,000 through.

The restricted funds remain held pending legal and recovery procedures.

Why the $50M figure must not be called “recovered”

The attempted volume includes transfers that did not complete through NEAR Intents.

Most rejected funds were reportedly sent elsewhere afterward.

Therefore:

  • $50M = attempted use of the service;
  • ~$503K = held/restricted by the service;
  • ~$166K = reportedly passed through.

Conflating these figures would dramatically overstate recovery.

NEAR Intents versus THORChain

The Bitget laundering case has become a real-world test of different cross-chain governance models.

NEAR Intents

Uses a transaction-screening layer that can delay/restrict suspicious swaps.

THORChain

Publicly declined Bitgets request for selective address blacklisting, citing its permissionless architecture.

Neither model is automatically “more decentralized” in every technical sense.

The practical risk difference is clear:

  • one service can stop a flagged transaction inside its application layer;
  • another chose not to selectively censor identified addresses.

What NEAR Intents can and cannot freeze

NEAR Intents‘ intervention does not mean it controls the attacker’s underlying wallet.

It can control:

  • whether its own service processes a swap;
  • funds temporarily held inside that execution path.

It cannot generally freeze:

  • native BTC in the attackers wallet;
  • all NEAR blockchain transfers;
  • funds routed through unrelated protocols.

This is why rejected funds can move to another service.

Recovery legal process

NEAR Intents says the held funds will remain restricted while Bitget/law enforcement use legal recovery procedures.

The service reportedly offered to waive its recovery bounty for the intercepted funds.

Important unresolved questions include:

  • who legally authorizes release;
  • how false positives are appealed;
  • what court/order standard applies.

Stolen-fund laundering continues elsewhere

Attacker-linked funds have already used:

  • THORChain;
  • privacy/mixing routes;
  • multiple cross-chain swaps.

The gradual conversion of stolen stablecoins/XRP/ETH exposure toward BTC reduces the usefulness of issuer-level freezes.

Bitgets customer withdrawal recovery and attacker-fund laundering are therefore moving in opposite directions:

  • customer access improves;
  • asset-recovery complexity can worsen.

Protection Fund

Bitget says its User Protection Fund covers the platform-wide financial impact.

The final economic cost depends on:

  • frozen funds;
  • recovered funds;
  • bounty recoveries;
  • law-enforcement seizures;
  • how much of the stolen value the exchange ultimately absorbs.

Evidence Status

Confirmed / Official Bitget

  • BTC withdrawals restored Sep. 28.
  • ETH withdrawals restored Sep. 29 at 08:00 UTC on five networks.
  • USDT scheduled Sep. 30 08:00 UTC.
  • Incident estimate ~ $388M.
  • Third-party security-product vulnerability is the leading attack path.
  • Private keys and cold wallets not compromised.
  • Incident contained.

Project-Reported Operational Data

  • First-hour ETH inflow ~9,674 ETH.
  • First-hour ETH outflow ~9,023 ETH.
  • Net inflow ~651 ETH.

NEAR Intents / Media

  • $50M attempted attacker-linked transfers through service.
  • ~$503K held.
  • ~$166K passed through.
  • Most rejected funds reportedly routed elsewhere.

Developing

  • USDT/full withdrawal restoration.
  • Final forensic report.
  • Final recovered/frozen percentage.
  • Final attacker attribution.
  • Legal disposition of held cross-chain funds.

Risk Assessment

Critical, but customer-access risk continues to improve.

The exchange has now restored two major withdrawal classes. Security/recovery risk remains Critical because the stolen-fund investigation and full service restoration are incomplete.

What to Watch Next

USDT withdrawals at Sep. 30 08:00 UTC, Oct. 2 full restoration, final forensic report, NEAR Intents recovery disposition, THORChain/other routes, exchange freezes and Protection Fund accounting.

FAQ

Are ETH withdrawals open?

Yes. Bitget confirmed ETH withdrawals reopened on September 29 across five networks.

How much ETH flowed in the first hour?

Bitget reported ~9,674 ETH in and ~9,023 ETH out, a net inflow of about 651 ETH.

Did NEAR Intents freeze $50 million?

No. More than $50M was attempted volume. NEAR Intents says it held about $503K.

How much passed through NEAR Intents?

Approximately $166K, according to the reported service data.

Are USDT withdrawals open?

They are scheduled for September 30 at 08:00 UTC; at this reports cutoff that time has not yet arrived.

Is the Bitget investigation finished?

No.

Disclaimer

The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
Previous Post

Relay API Vulnerability: 5,600 Users Hit by Sandwich Attacks, $312K Reimbursement Planned

Next

UK FCA Crypto Authorisation Gateway Opens September 30: What Firms Must Do