Bitget has completed the second stage of its phased withdrawal recovery.
After BTC withdrawals reopened on September 28, Bitget confirmed:
ETH withdrawals reopened at 08:00 UTC on September 29
across:
- Ethereum;
- BNB Smart Chain;
- Arbitrum One;
- Base;
- Optimism.
The next planned stage is USDT at 08:00 UTC on September 30, which is later than this reports publication cutoff.
First-hour ETH flow
Bitget reported that by 09:00 UTC—one hour after ETH withdrawals reopened—it had recorded approximately:
- 9,674 ETH inflows
- 9,023 ETH outflows
for a net inflow of approximately:
651 ETH
This is an exchange-reported operational snapshot.
It is not:
- an independent reserve audit;
- full-day withdrawal volume;
- proof that every chain/asset has recovered.
It does show that the reopened ETH withdrawal system was processing meaningful two-way flows rather than merely displaying an enabled button.
Current recovery schedule
Confirmed/planned sequence:
September 28
BTC withdrawals restored on Bitcoin and BSC.
September 29
ETH withdrawals restored on Ethereum, BSC, Arbitrum One, Base and Optimism.
September 30
USDT scheduled on Ethereum, BSC, Solana and Tron.
October 2
Other tokens, fiat and P2P scheduled to return.
The recovery remains partial until the later phases execute.
The incident amount remains approximately $388M
Bitgets current official estimate is approximately:
$388 million
in affected assets transferred from hot/warm wallet infrastructure.
Bitget says:
- 12 wallet addresses were associated with the incident;
- 11 blockchains were involved;
- cold wallets were not compromised;
- private keys were not compromised.
Leading attack path
Bitgets latest explanation says hackers may have exploited a vulnerability in a:
third-party security product
to obtain high-level internal credentials.
Those credentials were then used to:
- impersonate legitimate activity;
- issue fraudulent withdrawal commands;
- bypass existing risk controls.
This is a security-tool / supply-chain trust failure rather than simple private-key theft.
NEAR Intents intercepted part of the laundering flow
A new cross-chain-control development emerged after the exchange recovery began.
NEAR Intents says attacker-linked actors attempted more than:
$50 million
of transfers through its service.
That figure is attempted volume, not money frozen.
NEAR Intents says its SHIELD screening system:
- rejected most suspicious attempts;
- held approximately $503,000;
- allowed approximately $166,000 through.
The restricted funds remain held pending legal and recovery procedures.
Why the $50M figure must not be called “recovered”
The attempted volume includes transfers that did not complete through NEAR Intents.
Most rejected funds were reportedly sent elsewhere afterward.
Therefore:
- $50M = attempted use of the service;
- ~$503K = held/restricted by the service;
- ~$166K = reportedly passed through.
Conflating these figures would dramatically overstate recovery.
NEAR Intents versus THORChain
The Bitget laundering case has become a real-world test of different cross-chain governance models.
NEAR Intents
Uses a transaction-screening layer that can delay/restrict suspicious swaps.
THORChain
Publicly declined Bitgets request for selective address blacklisting, citing its permissionless architecture.
Neither model is automatically “more decentralized” in every technical sense.
The practical risk difference is clear:
- one service can stop a flagged transaction inside its application layer;
- another chose not to selectively censor identified addresses.
What NEAR Intents can and cannot freeze
NEAR Intents‘ intervention does not mean it controls the attacker’s underlying wallet.
It can control:
- whether its own service processes a swap;
- funds temporarily held inside that execution path.
It cannot generally freeze:
- native BTC in the attackers wallet;
- all NEAR blockchain transfers;
- funds routed through unrelated protocols.
This is why rejected funds can move to another service.
Recovery legal process
NEAR Intents says the held funds will remain restricted while Bitget/law enforcement use legal recovery procedures.
The service reportedly offered to waive its recovery bounty for the intercepted funds.
Important unresolved questions include:
- who legally authorizes release;
- how false positives are appealed;
- what court/order standard applies.
Stolen-fund laundering continues elsewhere
Attacker-linked funds have already used:
- THORChain;
- privacy/mixing routes;
- multiple cross-chain swaps.
The gradual conversion of stolen stablecoins/XRP/ETH exposure toward BTC reduces the usefulness of issuer-level freezes.
Bitgets customer withdrawal recovery and attacker-fund laundering are therefore moving in opposite directions:
- customer access improves;
- asset-recovery complexity can worsen.
Protection Fund
Bitget says its User Protection Fund covers the platform-wide financial impact.
The final economic cost depends on:
- frozen funds;
- recovered funds;
- bounty recoveries;
- law-enforcement seizures;
- how much of the stolen value the exchange ultimately absorbs.
Evidence Status
Confirmed / Official Bitget
- BTC withdrawals restored Sep. 28.
- ETH withdrawals restored Sep. 29 at 08:00 UTC on five networks.
- USDT scheduled Sep. 30 08:00 UTC.
- Incident estimate ~ $388M.
- Third-party security-product vulnerability is the leading attack path.
- Private keys and cold wallets not compromised.
- Incident contained.
Project-Reported Operational Data
- First-hour ETH inflow ~9,674 ETH.
- First-hour ETH outflow ~9,023 ETH.
- Net inflow ~651 ETH.
NEAR Intents / Media
- $50M attempted attacker-linked transfers through service.
- ~$503K held.
- ~$166K passed through.
- Most rejected funds reportedly routed elsewhere.
Developing
- USDT/full withdrawal restoration.
- Final forensic report.
- Final recovered/frozen percentage.
- Final attacker attribution.
- Legal disposition of held cross-chain funds.
Risk Assessment
Critical, but customer-access risk continues to improve.
The exchange has now restored two major withdrawal classes. Security/recovery risk remains Critical because the stolen-fund investigation and full service restoration are incomplete.
What to Watch Next
USDT withdrawals at Sep. 30 08:00 UTC, Oct. 2 full restoration, final forensic report, NEAR Intents recovery disposition, THORChain/other routes, exchange freezes and Protection Fund accounting.
FAQ
Are ETH withdrawals open?
Yes. Bitget confirmed ETH withdrawals reopened on September 29 across five networks.
How much ETH flowed in the first hour?
Bitget reported ~9,674 ETH in and ~9,023 ETH out, a net inflow of about 651 ETH.
Did NEAR Intents freeze $50 million?
No. More than $50M was attempted volume. NEAR Intents says it held about $503K.
How much passed through NEAR Intents?
Approximately $166K, according to the reported service data.
Are USDT withdrawals open?
They are scheduled for September 30 at 08:00 UTC; at this reports cutoff that time has not yet arrived.
Is the Bitget investigation finished?
No.

