Bitget counts $388 million in losses as Bitcoin withdrawals resume
The crypto market is absorbing the fallout from one of the largest exchange breaches in recent memory. Attackers stole $387.5 million from Bitget on Thursday, according to Cointelegraph, and the exchange has since confirmed that roughly $388 million in assets were affected, some $35 million more than initially reported.
Bitcoin withdrawals resumed on Monday, with other assets and networks expected to follow in the coming days. The staggered reopening suggests the exchange is rebuilding its withdrawal infrastructure network by network rather than flicking a single switch, a pattern familiar from previous major exchange incidents.
The prognosis for recovery is bleak. Bitget has said it is “not very optimistic” about retrieving the stolen funds, with chief executive Gracy Chen drawing a direct comparison to the 2025 Bybit hack. In that case, Chen noted, only a small portion of the stolen funds was frozen or recovered, and the industry should expect a similar trajectory here.
Cointelegraph reports the breach involved a third-party security vulnerability, a detail that shifts part of the narrative away from Bitget’s own custody controls and towards the sprawling supply-chain and vendor ecosystem on which even major exchanges depend. For a sector that has spent years assuring users that cold storage and multi-signature arrangements mitigate exchange risk, a compromise routed through a third party is a reminder that the perimeter is only as strong as its weakest external dependency.
The incident lands amid a broader run of high-value exploits, and it will inevitably sharpen scrutiny of how exchanges vet infrastructure partners, audit integrations, and structure incident response. Chen’s Bybit comparison is telling: when the precedent-setting hack of the era recovered only a sliver of stolen assets, expectations for restitution must be recalibrated downward.
For fuller context on exchange security incidents and their market consequences, see our exchange and security coverage.
Interception on-chain: NEAR Intents blocks over $50 million in attacker transfers
Not all of the stolen funds are moving freely. NEAR Intents, the cross-chain intent-based protocol, said it blocked more than $50 million in attempted transfers linked to the attackers, according to the Cointelegraph roundup.
That figure is significant for two reasons.
First, it demonstrates that interception is possible. The orthodox view of exchange hacks holds that once funds are drained and dispersed across chains and mixers, recovery is effectively finished. A protocol-level block of more than $50 million in a single incident shows that on-chain infrastructure providers can, in real time, act as choke points when attacker addresses are identified quickly enough. The crypto equivalent of a bank robber finding that several motorways have been closed mid-getaway.
Second, it raises awkward questions about where responsibility lies. If intent-based protocols and cross-chain infrastructure can freeze significant sums, pressure will grow on the broader DeFi stack, including bridges, aggregators and liquidity venues, to maintain sanctions and attacker-address screening as a matter of course. That carries its own controversies, since many of these systems were built with neutrality as a design principle. Every successful interception strengthens the argument for embedded compliance; every over-broad freeze fuels the counter-argument that infrastructure should not adjudicate.
The remaining gap is stark. More than $50 million blocked still leaves the overwhelming majority of the roughly $388 million unaccounted for or in motion. Expect continued address-blacklist coordination between exchanges, chain-analytics firms and protocols in the coming weeks, alongside the slow process of law-enforcement engagement across jurisdictions.
MiCA’s reach extends as four Greek providers join the EU register
While the Bitget saga dominates headlines, the quieter regulatory story may matter more over the long run. Four Greek crypto providers have entered the European Union’s crypto regulatory register, bringing them fully within the scope of the bloc’s Markets in Crypto-Assets framework, MiCA.
Greece is a useful bellwether for MiCA’s maturation. The framework has been live long enough that initial licence waves concentrated in the larger financial centres. Expanding authorisation into additional member states, with four firms entering the register simultaneously, indicates the regime is moving from a launch-phase scramble to steady-state uptake across the Union’s single market.
For the firms involved, registration is both a burden and a badge. MiCA imposes capital, custody, disclosure and governance requirements that smaller operators have found onerous. In exchange, it grants passporting rights across all EU member states, access to banking relationships that have historically been difficult for unregulated crypto firms to secure, and a degree of regulatory legitimacy that institutional counterparties increasingly demand.
The competitive implication cuts both ways. Exchanges and service providers operating inside MiCA can court European retail and institutional flows with a compliance story regulators recognise. Those outside it face a shrinking map: Europe is effectively closed to non-compliant operators, and the contrast with a week in which a major offshore-facing exchange suffered a $388 million breach will not be lost on European policymakers. Expect MiCA’s defenders, and there are many in Brussels and national finance ministries, to cite the Bitget incident as evidence of why the framework’s custody and operational-resilience standards matter.
There is a harder commercial edge too. A two-tier market is forming: regulated, passportable entities on one side, and everyone else on the other, with liquidity, listings and institutional flow gradually migrating towards the former. Each new cohort of registered firms, in Greece or elsewhere, thickens the regulated tier.
For ongoing analysis of the EU regime and its enforcement trajectory, see our regulation coverage.
SEC issues updated guidance on when crypto falls outside securities laws
Across the Atlantic, the US Securities and Exchange Commission has issued updated guidance clarifying when certain crypto assets and transactions may fall outside federal securities laws.
The classification question is the load-bearing wall of American crypto regulation. Whether a token is a security determines whether the SEC has jurisdiction, whether issuers face registration and disclosure obligations, and whether platforms listing the asset must operate as broker-dealers, exchanges or clearing agencies under federal law. Assets and activities that fall outside that perimeter sit in a different regulatory universe, one with materially lighter compliance costs and, in the current environment, an increasingly warm institutional reception.
The timing is notable. Coming in the same week as a major exchange hack and further MiCA expansion, the guidance contributes to a week in which the world’s two largest crypto regulatory blocs moved in opposite directions by different means: Europe by consolidating a comprehensive licensing regime, the United States by drawing finer lines around what its securities regulator can reach.
For exchanges and token issuers, the practical effects will be felt in listing decisions, token-launch structures and the compliance programmes attached to both. If the guidance carves out meaningful categories of activity from the securities perimeter, US-facing platforms gain flexibility in what they list and how they structure products. If the boundaries remain contested, litigation risk persists regardless of how the guidance is framed, and legal teams will be parsing every clause for months.
Three forces, one direction: institutional-grade crypto is arriving on regulators’ terms
Taken together, the week’s developments sketch the industry’s current trajectory with unusual clarity. A $388 million theft routed through a third-party vulnerability demonstrates that security risk remains existential and increasingly supply-chain-shaped. A protocol blocking more than $50 million in attacker transfers shows the industry’s defensive capability is improving, even if asymmetric to the threat. Four Greek firms joining the MiCA register confirms Europe’s licensing regime is broadening rather than stalling. And new SEC guidance narrows, or at least clarifies, the securities perimeter in the world’s deepest capital market.
The common thread is institutionalisation. Custody standards, licensing regimes, jurisdictional clarity and protocol-level interception are all features of a maturing market, and all of them reduce the degrees of freedom that made crypto’s earlier eras both freewheeling and dangerous. Bitget’s users, facing a recovery outlook its own chief executive describes pessimistically, are bearing the cost of that lesson this week. The markets and regulators watching the aftermath will decide how expensive it becomes for everyone else.