Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
NEAR Intents Loses $3.8 Million to Hackers Two Days After Helping Trace Bitget's $387.5 Million Theft

Since Bitget disclosed a $387.5 million theft from its hot and warm wallets on September 24, 2026, the cleanup has been slow, messy, and complicated by a second hack.
According to The Hacker News, Bitget confirmed the breach traced back to a zero-day vulnerability in unnamed third-party security software, first spotted by blockchain security firm SlowMist. The earliest malicious activity dates to August 31, 2026, when attackers ran hidden scripts on a vendor's node to grab a database password. By September 25, the attacker had accessed a second product's management platform using a stolen internal employee identity, injected malicious code, and built a custom tool tailored to Bitget's withdrawal logic. That tool began executing the theft at 1:49 a.m. on September 25, hitting 11 blockchains including Ethereum, Tron, XRP Ledger, and BNB Smart Chain.
Bitget halted withdrawals immediately and began restoring them on September 28, telling customers its User Protection Fund, valued at over $464 million before the breach, would cover all losses.
Bitget Calls Out DeFi for Looking the Other Way
In a post on X reported by Crypto Briefing, Bitget argued that some permissionless DeFi protocols declined to help trace or freeze the stolen funds. The exchange singled out NEAR Intents as the exception, crediting its SHIELD risk-intelligence system with flagging over $50 million in attempted laundering tied to the hack. Actual real-time freezes were far smaller: SHIELD caught $503,000 before it moved, while roughly $166,000 slipped through. Stablecoin issuers Tether and Circle separately froze between $320,000 and $340,000. The Hacker News put the combined frozen total at close to $1.1 million, meaning overall recovery sits around 0.2% of the $387.5 million stolen.
Permissionless protocols are built on the premise that transactions are final and that no central party can arbitrarily reverse or block them. Developers who resist ad hoc freeze requests argue that letting any party, including a well-meaning one, selectively block transactions on request undermines the censorship-resistance that is the entire point of decentralized finance. NEAR Intents chose to act. Not every protocol shares that philosophy, and the sources here do not establish that any specific protocol acted in bad faith by declining.
NEAR Intents Gets Hacked Itself
NEAR Intents' own credibility took a hit two days later. TradingView reported that on Thursday, October 1, 2026, the protocol paused services after discovering a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract. The flaw let an attacker drain $3.8 million in user funds.
NEAR said the contract-side vulnerability has since been patched and pledged to fully compensate affected users, according to both TradingView and The Defiant. Blockchain investigator ZachXBT traced the stolen funds to the KuCoin exchange, where they were bridged into Bitcoin, per TradingView. As of that reporting, no one had been publicly confirmed as responsible.
That changed, at least partially, by October 2. According to a Cointelegraph report carried on Bitget's own news platform, NEAR Intents said it had identified the individual behind the $3.8 million exploit and gave them a 48-hour window to return the funds under what the protocol called "responsible disclosure," warning: "After 48 hours, that window closes." NEAR has not named the suspect publicly, and no law enforcement action or charge has been announced in connection with that specific case.
North Korea Speculation Remains Unconfirmed
Bitget CEO Gracy Chen has speculated that North Korean-linked actors may be behind the original $387.5 million exchange hack, a theory also noted by TradingView. No source in this reporting confirms that attribution. Bitget itself has not named a specific group, and the investigation led by SlowMist remains ongoing. Given North Korea's documented history of state-linked crypto theft to fund weapons programs, the suspicion is not unreasonable, but it is still speculation, not an established fact.
None of this has dented market enthusiasm for NEAR's token. 24/7 Wall St. reported the NEAR token gained 182% over the past month through October 1, even after both the Bitget assist and the protocol's own $3.8 million loss became public. Whether that rally holds now depends partly on what happens when NEAR's 48-hour ultimatum lapses, expected around October 4, and whether the identified hacker actually returns the funds or forces NEAR into a drawn-out recovery fight of its own.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.