Table of Contents
Key Takeaway π° The NEAR Intents hack ended the way almost none of them do: with the money back. On October 1, 2026, a vault drain moved 3.87 million USDT out of NEAR Intents on BNB Chain in five separate transfers, according to Bitquery’s on-chain reconstruction. Alex Shevchenko, the protocol’s CEO, went on X the next day and said the attacker had been identified β and gave the man behind the NEAR Intents hack 48 hours. Before the deadline expired, $3.8 million flowed back.
For one Filipino family that woke up to NEAR Intents hack headlines about a fifth exchange failure in a year, the more important number sits in the same week’s news: $387.5 million walked out of Bitget on September 24 through a vendor zero-day, the largest theft of 2026, and only $1.1 million of it has been frozen across Tether, Circle, and NEAR Intents combined.
Two incidents, two endings, one question every OFW remitter should be asking: which exchange model keeps your money safe when the attacker is already inside? This piece answers it with the facts on the table.
The NEAR Intents hack started, according to Bitquery’s analysis, on the night of September 30 to October 1: five withdrawals from a vault on BNB Chain, totaling 3.87 million USDT. NEAR Intents itself put the figure at $3.8 million. By early October 1, on-chain tracking showed 76% of the loot converted to bitcoin β 34.69 BTC β and 21% already parked on KuCoin. That laundering speed inside the NEAR Intents hack matters for the story’s ending, because the money was being cut into spending chunks at the same time its owner was deciding whether to give it back.
Shevchenko’s October 2 ultimatum in the NEAR Intents hack contained two threats that made return the cheapest option. First, he said the hacker had been identified β a claim that, if backed by the exchange’s internal forensics, converts an anonymous on-chain address into a person with a passport. Second, he disclosed that NEAR Intents had blocked part of the transfers during the theft itself, an admission that the protocol’s own guardrails had done real work that night.
The attacker in the NEAR Intents hack chose 100% return before the 48 hours ran out. There was no negotiation, no partial payment, no “bug bounty plea.” The NEAR Intents hack therefore joins a tiny club of full reversals, and it did so precisely because the exchange could name a human being. Anonymity is the criminal’s entire margin in crypto β the same identification logic now governs AI-agent incidents; remove it and a court appearance beats a ransom every time.
The week’s bigger number: how $387.5 million left Bitget without a single key being stolen
Zoom from the NEAR Intents vault to the week’s main event. On September 24 at 6:31 PM UTC, a test transfer of 0.184 ETH left a Bitget hot wallet on Ethereum, followed by 193 TRX from another wallet on Tron. The amounts were small enough to look like noise β and that was the design. Half an hour later the real theft began, and by the time Bitget suspended withdrawals, an estimated $387.5 million had crossed 11 blockchains, from Ethereum and XRP Ledger to Zcash, TRON, Arbitrum, Optimism, Base, BNB Smart Chain, Avalanche, Algorand, and Celestia. Assets included XRP, ETH, USDT, USDC, ATOM, and even tokenized gold (XAUt).
It became the largest crypto theft of 2026 and one of the ten largest ever recorded β and, most unsettling, the attackers never touched Bitget’s private keys, and the cold wallets were not breached.
Bitget’s confirmation on Wednesday, citing an ongoing investigation by SlowMist, identified the mechanism: a zero-day vulnerability in third-party security products used inside the exchange’s backend. SlowMist’s progress report describes the earliest malicious activity as dating back to August 31 β more than three weeks before the drain. The attacker ran a hidden script under a service process on one of “Product A’s” nodes, read the environment variable containing a database password, and connected to the database. Similar hidden-script activity was observed on two other nodes on September 23 and 25. By the time the withdrawals began, the affected service environments had been compromised for weeks.
The payoff of that patience was credential-level access. The attacker obtained high-level internal credentials and used them to issue fraudulent withdrawal commands to the wallet system β what Bitget’s own post called “abnormal transfers that bypassed existing risk controls.” The cryptography held. The signing keys signed what they were told, because the stolen layer above them was the thing deciding whether a withdrawal was legitimate. A zero-day in a security product, ironically, functioned as the skeleton key to the entire authorization stack.
Gracy Chen, Bitget’s chief executive, told The Block that the attacker deliberately probed the exchange’s risk controls with small transfers before the main theft. That sequence profiles a patient, well-resourced crew that had mapped how Bitget’s monitoring behaved and needed proof the path was clear before committing. Once they could issue commands that looked authorized, they did not need signers or broken encryption. The exchange’s own automated systems did the work for them, siphoning hot wallets with transfers indistinguishable from ordinary client withdrawals. That is the trap every platform builds when it automates withdrawals for clients’ convenience β the convenience itself becomes the attack surface.
Bitget has since notified the affected third-party vendor and disabled the functionality pending a fix; roughly $1.1 million of the stolen funds has been frozen through cooperation with Tether, Circle, and NEAR Intents. Read that 0.28% recovery ratio against the NEAR Intents hack return ratio β 100% β and the comparison writes itself. Size is not the difference in the NEAR Intents hack. Identification is.
Why the two endings define crypto safety for OFW remitters
Almost every major crypto theft of the last four years ended the same way: the funds vanished through mixers and bridges, a slice resurfaced on an exchange, and the exchange published a freeze of single-digit millions while the bulk moved to a place nobody could subpoena. our ledger on the $387.5M Bitget vendor zero-day tracks the theft itself; this week’s Chainalysis attribution to North Korean infrastructure, the same attribution family as the Bybit heist ZachXBT’s team traced earlier in the year. That is the industry’s standard ending.
The NEAR Intents hack ending is the outlier. What makes it repeatable is a specific combination: a protocol small enough that the identifiable CEO can make credible threats, on-chain analytics fast enough to trace conversion at the moment it happens, and cooperation rails (Tether and Circle freezes) that work when the amounts are small. Every element scales badly. A $387.5 million thief already knows he is hunted and is willing to launder at a discount; a $3.8 million thief has not yet surrendered his anonymity and can still calculate that returning everything is cheaper than losing it all plus a passport.
For Filipino families moving money across borders, the practical takeaway is not “crypto is unsafe” β the Keio-style segregation lesson of this week applies more than any slogan. Remittance corridors increasingly pass through stablecoin rails, whether the sender knows it or not; Wise-style fintechs and even some banks now hold USDT or USDC inventory.
The relevant question, when choosing a platform, is exactly the one this week answered twice: if their authorization layer is tricked, what stands between the attacker and your balance? A platform whose controls can identify you is safer than one whose controls merely freeze you β and a 100% recovery beat a 0.28% one. The remittance corridor angle: where NEAR Intents actually touches Filipino money Readers who have never held a NEAR token may wonder why a protocol-level heist matters to a remittance reader.
The answer is structural. NEAR Intents is a cross-chain swap and settlement layer β the kind of plumbing that stablecoin remitter apps invoke when a user in Dubai sends USDT home and the family in Bulacan receives pesos. When a vault on that layer drains, the pipes pause for every app sitting on top of them. The NEAR Intents hack was therefore not just an exchange incident; it was a two-day outage risk for settlement paths that Filipino workers already use, and the freeze that NEAR Intents imposed on Bitget-era funds shows the layer has real police powers.
The NEAR Intents hack also demonstrates why settlement-layer incidents play out differently from retail-exchange breaches. The vault belongs to the protocol, not to users; balances are settled between counterparties at swap time. That architecture kept individual remitters from losing principal β the protocol could eat the loss in dispute, and ultimately did not have to. Retail exchanges carry the opposite profile: your USDT sits in their pooled hot wallet, and when authorization fails, your balance is the direct target. The same $100 sent through each rail faces two completely different failure modes, and this week showed both endings on the same news cycle.
The OFW playbook, applied to this week’s two endings
Scenario one: your remitter app uses a settlement layer like NEAR Intents. Your exposure during the NEAR Intents hack was a delay, not a haircut β funds paused in transit while the vault was quarantined. Your action item: know which rail your app runs on (usually disclosed in the app’s help pages) and keep your remittance schedule flexible enough to absorb a 48-hour pause without a family emergency becoming a cash crisis.
Scenario two: you self-custody on a retail exchange that behaves like the Bitget pattern β fast automated withdrawals, vendor security tooling, warm wallets holding more than a day’s flow. Your exposure is direct. The Bitget attacker needed three weeks of patience, one environment variable, and a zero-day that turned the exchange’s own withdrawal automation into the getaway car. Your action item: the working/settlement split from the checklist above, plus a withdrawal whitelisting rule. Bitget’s own monitoring caught the 0.184 ETH probe; your whitelisting rule catches the version of that probe that points at your account.
Neither scenario rewards panic selling or platform-hopping. Both reward the unglamorous architecture decisions that this week’s two endings validated: segregation that Keio would recognize, identification that Shevchenko enforced, and the boring discipline of keeping the working balance small. The NEAR Intents hack returned everything because the right controls existed before the thief arrived β that is the only part of the story a family can replicate tonight.
The five-point checklist this week hands every remitter
First, prefer platforms that publish their custody architecture. NEAR Intents could run its ultimatum because its leadership was identifiable and its on-chain flows were transparent; opacity helps the attacker in every scenario in this piece. Second, separate your working-money app from your settlement app. The 0.184 ETH test transfer shows that attackers start small; a working account holding only the current month’s remittance cap losses automatically. Third, treat “automated withdrawals” as a feature that carries a price tag. Speed of payout is the exact system category the Bitget attacker turned into a weapon β an exchange that processes withdrawals through a human checkpoint at midnight is the one that catches the 3:00 AM drain.
Fourth, watch for the freeze-rail signals. Circle and Tether freezes recovered $1.1 million within days β stablecoin issuers are the remittance economy’s real police, and they move only when issuers and exchanges cooperate fast. Fifth, ignore the “hack-proof” kind of marketing entirely (the POGO playbook shows what identity theft costs). Bitget held its private keys perfectly; the NEAR Intents hack was reversed through social identification and transparency, not cryptography. The lesson is that the security stack that matters most now sits between the code and the criminal’s name.
What Shevchenko’s ultimatum means for the industry’s next quarter
The NEAR Intents hack proved the exchange CEO who can credibly say “we know who you are” is a new category of counterparty, and the protocol he runs is small enough to make the threat personal. Whether the tactic survives contact with a serious adversary β a state-linked team laundering $100 million β is doubtful, but the NEAR Intents hack return already reset expectations for incidents inside that size band. On-chain analysts now know a 48-hour return window can be enforced; attackers now know the cheapest exit is the one that goes through the protocol’s own X account.
The Bitget investigation continues, and its vendor has a patch to ship. SlowMist traced activity inside the perimeter back three weeks before the drain; expect the Bitget post-mortem to read like a case study in how a single environment variable β a database password sitting in a text file on a node β became the first domino. For the families wired into the remittance corridors that stablecoins now carry, the week’s two endings are the entire syllabus: transparency identified one thief, and an environment variable armed another. The platforms you choose this quarter should be the ones that have already learned both lessons.






