0x215f2650215f…215f2653

ConfirmedSecurity574 vB160 sat/vB3 min decode

Bitget Resumes BTC Withdrawals After $387.5M Hack; NEAR Blocks $50M

Bitget resumed Bitcoin withdrawals after the Sept. 24 exploit drained $387.5M from hot and warm wallets, while NEAR Intents blocked more than $50M in transfers linked to the attackers.

Here’s what happened in crypto today
WitnessHere’s what happened in crypto todayAI-generated

Outputs

  1. Bitget revised its damage estimate to $387.5M after the Sept. 24 breach of hot and warm wallet infrastructure; cold wallets remained secure

  2. NEAR Intents' SHIELD system blocked more than $50M in attempted transfers tied to the attackers, froze $503,000 during execution, and saw roughly $166,000 slip through

  3. CEO Gracy Chen said BTC withdrawals resumed Monday on the Bitcoin network and BNB Smart Chain, with ETH and USDt to follow pending security reviews

  4. The SEC released non-binding FAQs expanding its March Howey test guidance across token buybacks, network maintenance work and staking receipt tokens

  5. The Senate failed to advance the CLARITY Act days before the SEC's updated guidance, leaving the SEC and CFTC to act under existing authority

Bitget resumed Bitcoin withdrawals on Monday after a Sept. 24 security breach drained an estimated $387.5 million from the exchange's hot and warm wallet infrastructure. The exchange suspended withdrawals immediately after detecting the intrusion. Cold wallets remained secure throughout the incident, the company disclosed.

The exchange lifted its BTC pause on the Bitcoin network and BNB Smart Chain first, with Ether (ETH) and Tether (USDT) withdrawals to follow pending security reviews, CEO Gracy Chen said during a Monday ask-me-anything session. Bitget said additional assets and networks will resume over the coming days.

"We restored BTC first because the withdrawal pipeline is the first to be completed," Chen told users.

Bitget raised its damage estimate from an initial $351.6 million after tracking additional transfers on Zcash and Tron tied to the attack.

How much of the stolen funds were intercepted?

Cross-chain swap protocol NEAR Intents said its SHIELD system detected and blocked more than $50 million in attempted transfers linked to the hackers, which subsequently moved to other providers. The system froze $503,000 in funds during execution while roughly $166,000 in suspected stolen proceeds slipped through to other venues, according to Alex Shevchenko, general manager of NEAR Intents.

Shevchenko said a significant portion of the assets bridged across chains to Ethereum before reaching the protocol.

Can cross-chain protocols block illicit transactions?

The interception came as THORChain, the cross-chain liquidity network, faced public calls to blacklist addresses tied to the Bitget exploit. The episode crystallizes a fault line in decentralized infrastructure: maintaining permissionless access while denying service to known exploiters, even when doing so requires active intervention.

Shevchenko said protocol developers retain discretion over which activities their infrastructure enables.

"The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours," he said.

"Property rights are fundamental to functioning markets. A financial system where stealing an asset gives you an unrestricted right to monetize it isn't a freer system. It is simply a system that protects the thief. Such systems cannot become the economic backbone of the future," Shevchenko added.

What did the SEC clarify?

The U.S. Securities and Exchange Commission released updated FAQs expanding its March interpretation of how the Howey test applies to digital assets, covering token buybacks, network maintenance work and staking receipt tokens.

Under the guidance, buybacks may not constitute the "managerial efforts" associated with an investment contract when a crypto network is already functional and lacks a central party. Routine work to maintain or improve a functioning network may also fall outside that standard. Staking receipt tokens would not automatically be classified as securities.

The guidance is non-binding and does not change existing law, but gives projects explicit touchpoints for how agency staff intends to evaluate transactions, and brings SEC posture closer to recent Commodity Futures Trading Commission interpretations.

What's next for U.S. crypto oversight?

The SEC's FAQ lands days after the Senate failed to advance the CLARITY Act, a bill that would have codified a jurisdictional split between the SEC and CFTC.

With the legislation stalled, both regulators continue rulemaking under existing authority. The next concrete signal will arrive when SEC staff begins applying the new FAQs to live filings and enforcement referrals through the end of the year, shaping how issuers structure token launches, staking programs and protocol-funded buybacks into 2026.

via anthropic.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles