Business
Cointelegraph.com News

NEAR Intents says its identified the hacker, gives 48-hour ultimatum

Source Entity

Cointelegraph by Felix Ng

October 4, 2026
NEAR Intents says its identified the hacker, gives 48-hour ultimatum

The Bitget exchange suffered a $388 million breach in September 2026, marking the largest incident in a record-breaking month for crypto security losses. Investigations by SlowMist reveal the attack stemmed from a zero-day vulnerability in third-party security software.

The Bitget Breach and the Escalation of Crypto Security Risks

In September 2026, the cryptocurrency industry faced its most severe security crisis of the year, headlined by the staggering $388 million theft from the Bitget exchange. This incident was not an isolated event but rather the centerpiece of a catastrophic month that saw industry-wide losses surpass $768 million. According to data from blockchain security firms PeckShield and CertiK, the scale of these thefts highlights a growing vulnerability in the infrastructure underpinning digital asset platforms.

Anatomy of the Attack: The Zero-Day Vulnerability

Forensic analysis conducted by the security firm SlowMist has provided critical insight into the sophistication of the Bitget breach. Their investigation traced the origin of the malicious activity back to August 31, nearly a month before the final asset drain on September 24. The attackers successfully leveraged a zero-day vulnerability within a third-party security product. By utilizing a hidden script to access a database—referred to as "Product A"—the perpetrators bypassed established defenses, demonstrating a high level of technical planning and long-term infiltration strategy.

The Broader Impact on Q3 Security

The Bitget incident was a primary driver for the surge in Q3 2026 security losses, which totaled an alarming $1.26 billion across 247 distinct incidents. This represents a 53.9% increase in financial losses compared to the second quarter. While the Bitget hack accounted for roughly 31% of the total quarterly losses, it was closely followed by the $320 million Liquid Network exploit, which occurred earlier in September. While some funds from the Liquid Network incident were eventually recovered, the sheer volume of attacks indicates a systemic weakness in the current security apparatus of major crypto entities.

Historical Context and Industrial Trends

The frequency and scale of these attacks suggest a shift in the threat landscape. With 97 incidents recorded by CertiK in September alone, the industry is witnessing a higher velocity of exploits targeting hot wallets and third-party integrations. The reliance on third-party security products, intended to bolster safety, has paradoxically become a vector for intrusion. As seen in the Bitget case, the integration of multiple security products and custom withdrawal tools provided the precise surface area required for hackers to execute their strategy.

Future Implications and Mitigation

The implications of these events are profound for both institutional and retail investors. As security firms continue to document the rise in Q3 losses, the pressure on exchanges to audit their supply chains and third-party dependencies will reach an all-time high. The move from simple phishing or direct protocol hacks to sophisticated, multi-week zero-day exploits signifies a maturation in the capabilities of cybercriminals. Moving forward, the industry must prioritize "defense-in-depth" strategies that do not rely on single points of failure, such as the third-party databases exploited in the Bitget theft.

Conclusion: A Call for Heightened Vigilance

The events of September 2026 serve as a stark reminder of the volatile nature of crypto-asset storage. With total quarterly losses breaching the $1 billion mark, the focus must shift from rapid growth to robust, resilient security frameworks. The recovery of portions of the stolen funds in other incidents provides a glimmer of hope, but the Bitget breach remains a defining moment that underscores the urgent need for enhanced oversight of third-party software integrations and proactive vulnerability management.

Verification Required?

Read the full report from the primary source

Go to Cointelegraph.com News