This article was compiled and organized by BlockWeeks
Late last week, Bitget disclosed that attackers stole $387.5 million from the exchange's hot and warm wallets through a series of unauthorized transfers, and temporarily suspended all withdrawals.
When you read a post-mortem of a crypto hack, you get a peculiar feeling—you realize you've read this content before. Not a "similar" one, but the "same" one, just with the nouns swapped out.
What Exactly Happened to Bitget
The losses spanned 11 blockchains, including Ethereum, XRP, TRON, Arbitrum, Base, and BSC, with the largest single-chain loss on XRP, at approximately $83 million. According to Bitget CEO Gracy Chen, the private keys and cold wallets were not compromised—a claim corroborated by the fact that hundreds of millions of dollars in tokens remain untransferred in the attacked addresses. The actual attack path was: attackers exploited a zero-day vulnerability in a third-party security product to obtain high-level internal credentials, injected forged withdrawal instructions into the wallet backend, and deleted these instructions after the funds were transferred out.
The security firm SlowMist, hired by Bitget, traced the earliest malicious activity back to August 31 and reconstructed a custom withdrawal tool built around Bitget's withdrawal logic. All signs point to a deeply researched, highly targeted attack on Bitget's wallet management. Based on IP behavior and on-chain analysis, Bitget attributed the attack to North Korean hackers; on-chain detective firms Elliptic and TRM also found overlaps between the relevant wallets and previous hacking incidents.
Fund Flows: Two Choices for THORChain and NEAR Intents
The majority of the stolen funds were transferred through THORChain. Chen had requested that THORChain refuse to provide services for it, but the other party declined on the grounds of being "decentralized and permissionless" (never mind the security freezes it has executed in the past). NEAR Intents took the opposite approach: it intercepted over $50 million in money-laundering attempts and froze approximately $503,000 during execution.
Bitget's protection fund and the applicable Proof of Reserves (PoR) over-collateralization covered the amount of this attack. Bitget fully absorbed the loss through its protection fund, which has since been replenished to $300 million.
However, on Thursday, NEAR Intents itself was also attacked. A vulnerability in its Omni deposit and withdrawal infrastructure resulted in a loss of approximately $3.8 million, and NEAR Intents stated it would fully compensate. ZachXBT flagged multiple abnormal outflows from a BSC hot wallet, with funds sent to KuCoin and further bridged to Bitcoin.
If You Feel Like You've Seen This Before, You're Right
In February 2025, the North Korean hacker group Lazarus stole $1.5 billion from Bybit in the same way. They did not steal Bybit's private keys; instead, they compromised the infrastructure of Safe{Wallet}, showing signers a tampered interface, and the signers approved a transfer that looked perfectly normal. The cryptography itself worked perfectly—it signed exactly what it was told to sign.
No one attacked the mathematics of the private key. They attacked the person or system that tells the mathematics what to do. This is the true picture of major attacks today.
Private key security Is Basically Solved, but the "Middle Layer" Is Not
A private key is a perfect mathematical way to protect funds (depending on the quantum resistance of the cryptographic protocol). It will sign anything put in front of it, so protecting it is crucial. Exchange private key security is world-class, and we haven't seen a major crypto platform's private key compromised in years. Phemex had a private key vulnerability in January 2025, but the loss was only about $50 million; Coincheck suffered a major attack of over $500 million in 2018, but by crypto industry standards, that was already the Paleozoic era. Private key security is basically solved, so for attackers, the valuable target is not the key itself, but the person or system that decides "what to put in front of the key."
We don't yet have all the details, but the shape of this theft already tells most of the story. If you had the key, you would transfer all the money out. But Bitget's initial announcement described unauthorized transfers from a "limited number" of hot wallets; and SlowMist believes the losses would have been greater if not for two forged BTC withdrawal instructions that went wrong. This is exactly what impersonating an approval pipeline looks like: you can only take the amount the pipeline is willing to process, one convincing request at a time. Partial theft is the fingerprint of a "compromised middle service," not a "compromised key."
The Vendor Not Yet Named, and a Repeatedly Validated Lesson
Bitget has not yet disclosed the name of the compromised vendor. The forensic report refers to them as "Product A" and "Product B." Hopefully this time it's not Gnosis Safe again. SlowMist described that multiple "nodes" of Product A were infected with malicious code injected through a zero-day vulnerability.
Nick Szabo wrote "Trusted Third Parties Are Security Holes" back in 2001. Every year, this industry relearns this lesson, and each time the cost is close to nine figures. The mathematics of cryptography is secure; what needs hardening is the structure around it. The AI industry learned a similar lesson this summer: misbehaving agents in frontier labs exploited third-party integrations to escape their testing sandboxes.
Aftermath, Also a Familiar Recipe
Most of the stolen funds were moved and exchanged, with some routed through THORChain. THORChain's official X account replied that it is decentralized and permissionless, so it can do nothing. Bybit's stolen funds (and the proceeds of countless other attacks such as ColdCard) also took a similar "cross-chain hop" path, laundered through THORChain. At this point, it's no longer a "bridge"—it's more like a "getaway vehicle" for North Korea (DPRK).
One more point. No one has attributed Thursday's NEAR Intents vulnerability to any party, and we want to be clear: we also do not attribute it. We merely note—on Monday, NEAR Intents confiscated about $500,000, which looked like Kim Jong-un's "lunch money"; and on Thursday, someone stole $3.8 million from this multi-chain transaction protocol's BSC hot wallet. The path was exactly the deposit and withdrawal infrastructure—if you've read this far, you should know that is the "middle layer."






