NEAR Intents2026-10-01 18:18:28NEAR Intents pauses after $3.8 million hack tied to Omni deposit and withdrawal systemNEAR Intents, a multichain transaction protocol, halted services on October 1 after suffering a $3.8 million exploit involving its Omni deposit and withdrawal infrastructure. The team disclosed the incident at 2 p.m. GMT+1 and said services would resume within an hour after fixing what it described as a "contract-side vulnerability." Even so, deposits and withdrawals across BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll, and Plasma remained offline pending further work on the Omni infrastructure. Crypto investigator ZachXBT said the protocol’s BSC hot wallet showed irregular outflows before transaction processing stopped, adding that the stolen funds were quickly sent to KuCoin and then bridged to Bitcoin. Following the disclosure, NEAR fell from $5.1 to $4.79 within minutes. The incident came days after NEAR Intents said it had helped block part of the funds stolen from Bitget, with General Manager Alex Shevchenko saying $50 million attempted to move through the protocol, $503,000 was frozen, and only $166,000 got through while the remainder moved to other providers.40
ZachXBT2026-10-02 13:07:59ZachXBT questions whether UPay enabled Xinbi-branded Visa crypto cardsOn Oct. 2, on-chain investigator ZachXBT said he suspects UPay may have allowed Xinbi, a sanctioned illicit marketplace, to use its Visa crypto card through a white-label arrangement. He called on UPay to respond to the allegation. ZachXBT also said Xinbi is mainly associated with pig-butchering schemes, fraud, money laundering, and human trafficking. The statement did not include a response from UPay. The claim, as presented in the source material, reflects ZachXBT’s public allegation and request for clarification rather than a confirmed finding by UPay or Visa.20
NEAR Intents2026-10-02 07:36:31NEAR Intents loses about 3.865 million USDT as team says attacker identified and given 48 hours to return fundsNEAR Intents, a cross-chain trading system built in the NEAR ecosystem, suffered another security incident after roughly 3.865 million USDT was drained from a BNB Chain vault address used by the protocol. The team said the issue came from a vulnerability in the interaction between its Omni deposit-and-withdrawal infrastructure and NEAR Intents smart contracts. Services were paused after the anomaly was detected, and the contract-side flaw was patched in about an hour, according to the team, which also said affected users will be fully reimbursed. Blockchain analytics firm Bitquery said the attacker moved the funds in five transactions between the evening of Sept. 30 and Oct. 1 over roughly six hours. The stolen assets were then swapped into BNB and split across dozens of new addresses. By the afternoon of Oct. 1, Bitquery said it had traced about 99% of the funds: around 76% had been converted into 34.69 BTC across four Bitcoin addresses, about $802,000 had flowed into KuCoin-linked addresses, and roughly $90,000 had been turned into Monero-related assets. On Oct. 2, NEAR Intents general manager Alex Shevchenko said the team had identified the attacker and opened a 48-hour "responsible disclosure" window for repayment.20
Bitget2026-10-02 04:29:06Alleged Bitget fund launderers sought help in public chats after swaps stalled, ZachXBT saysBlockchain investigator ZachXBT said people allegedly laundering funds from the Sept. 24 Bitget exploit for suspected North Korean attackers openly asked for help in public Discord servers and Telegram channels after swap orders ran into problems. The post described several users, including aliases such as jack, Cc, Melon, and lolo, who said they used THORChain-related services to swap XRP into BTC but could not verify the expected BTC on-chain. In one exchange highlighted in the report, a staff member carrying a SwapKit tag replied with a photo of Kim Jong Un and comments mocking the user’s concern. The article also cited a TRM flow chart showing how funds moved from the XRP Ledger through intermediary wallets into THORChain, then through cross-chain bridges, and eventually to Wasabi. Bitget had asked THORChain to block hacker-linked addresses, while THORChain said a network pause on Sept. 28 was an emergency safety measure for the protocol rather than a selective freeze aimed at a specific set of funds or swaps.40
NEAR Intents2026-10-01 13:08:42NEAR Intents confirms exploit, with losses topping $3.8 millionNEAR Intents said it was hit by an attack and traced the issue to a flaw in how its Omni deposit and withdrawal infrastructure interacted with smart contracts. The project said the contract vulnerability has already been fixed and that core services are expected to resume within one hour. It also said affected users will be fully reimbursed for damaged assets. At the same time, deposit and withdrawal services on several chains, including BSC, Polygon and TON, will remain suspended for about 12 more hours. NEAR Intents said the case has been reported and on-chain tracking is under way. Separately, on-chain investigator ZachXBT said NEAR Intents’ BSC hot wallet showed multiple abnormal outflows. According to his statement, the stolen funds were moved to KuCoin and then bridged onward to the Bitcoin network. The amount involved now exceeds $3.8 million.00
Bitget2026-10-01 00:37:16Bitget-linked addresses move about 2,700 ZEC into Ironwood shielded poolAddresses tied to the Sept. 24 Bitget security incident have started moving roughly 2,700 Zcash tokens into Ironwood, Zcash’s newest shielded pool, according to on-chain investigator ZachXBT. At a ZEC price of about $1,407, the amount is worth roughly $3.8 million to $3.9 million. Based on currently disclosed figures, the transfer accounts for around 14% to 15% of the approximately 18,900 ZEC moved in the incident, which was valued at about $28.3 million at the time. Bitget said on Sept. 25 that total affected assets in the attack were about $387.5 million, revised up from an initial $351.6 million after adding assets such as Zcash and Tron that had not been fully counted earlier. The exchange also disclosed a main attacker ZEC address, t1WgMdtND8NF7NDUuYmq8MpMj1NTCXkMDVG, which matches the source of funds tracked by ZachXBT. The move matters because transfers into Ironwood break the public transaction trail that analysts can follow on transparent addresses. While deposits from transparent addresses into the pool remain visible, activity inside the pool does not directly reveal sender, recipient, or amount. ZachXBT said the attacker had only “begun” shielding, leaving open the question of whether the remaining roughly 16,000 ZEC will also move into the privacy pool.00
Bitget2026-09-30 16:28:30Bitget says operations are returning to normal as protection fund reaches $309MBitget says it is gradually restoring normal operations after a security breach that led to $388 million in user losses. CEO Gracy Chen said on Wednesday that withdrawals for all tokens will resume on Friday, while access to Bitcoin, Ether, and USDt has already been restored. The exchange also said its Protection Fund has reached $309 million as part of its recovery effort. According to Bitget, the fund was established in January 2022 with 5,500 BTC and was designed to cover user losses in cases not caused by misconduct by the user or the platform itself. Chen said the fund was built for incidents like this and has absorbed the financial impact of the breach. Chen also told Cointelegraph that the company has not ruled out possible perpetrators behind the attack, including the possibility of an inside job or North Korean hackers. Bitget has launched a bounty program offering 5% of frozen funds and 5% of any recovered funds. Separately, blockchain investigator ZachXBT said wallets linked to the hack moved about $3.8 million in Zcash into Ironwood, accounting for roughly 14% of the 18,917 ZEC stolen.00
Bitget2026-09-30 10:43:26ZachXBT says suspected North Korea-linked attackers are using Zcash to shield Bitget stolen fundsCoinBureau, citing on-chain investigator ZachXBT, reported that suspected North Korea-linked attackers are using Zcash to obscure funds stolen from Bitget. Around 2,700 ZEC, worth about $3.8 million, has already started moving into Zcash’s Ironwood. Those stolen coins are being sent into the shielded pool, where transaction details can be hidden. The report ties the movement to Bitget’s broader security incident, which involved multiple asset types and totaled about $388 million. Within that event, about 18,900 ZEC, valued at roughly $28.3 million, was stolen. Earlier, Bitget CEO Gracy Chen said she was "not very optimistic" about recovering the stolen funds. The update points to continued efforts to move part of the stolen assets into privacy-preserving infrastructure, based on ZachXBT’s account as cited by CoinBureau.350