LIVE
Loading prices…

The Recovery Economy

Bitget blocked customer withdrawals while forged commands kept moving funds. Zano rewound its chain. Limit Break's rescue required revoking old approvals. Each tested a different meaning of recovery.

The Recovery Economy

Week in 60 Seconds

  • Bitget: September's theft became a forensic and recovery story this week. SlowMist identified malicious activity in the available logs dating to 31 August. BlockSec's 29 September snapshot combined issuer freezes and NEAR's reported held funds at approximately $840,000, about 0.2 per cent of the $387.5 million stolen.
  • Zano: An emergency software release excluded roughly a month of transactions from the recovered chain. Reporting on the project's post-mortem puts unauthorised issuance at 36.9 million ZANO and 1.8 quadrillion fUSD. Restitution remains a separate undertaking.
  • Limit Break: Permissions survived Magic Eden's departure from the Payment Processor. Reporting describes 305 NFTs stolen and a separate rescue of 23,155 NFTs. Returning rescued assets requires revoking the vulnerable approval first.
  • Base / Cobalt: The upgrade lets users set conditions on signed transactions and gives authorised token administrators a gated power to move balances without the holder's consent.

Bitget: Detection Was Not Containment

The first unauthorised transfers occurred at 18:31 UTC on 24 September. According to BlockSec's reconstruction, these were two small tests, 0.84 ETH and 93 TRX, below the relevant risk-control threshold. They triggered no alert. Large outflows began at 18:58.

At 19:05, Bitget's reconciliation system detected the discrepancy and blocked user-initiated withdrawals. The attacker's forged withdrawal commands continued. Bitget shut down the signing machines and wallet withdrawal services at 21:44.

The distinction matters: a block on customers' withdrawal requests did not stop commands entering through the compromised wallet infrastructure.

SlowMist's investigation progress report, commissioned by Bitget and current through 29 September, places the earliest malicious activity identified in the available logs on 31 August. That activity involved a zero-day vulnerability in a third-party security product. SlowMist recovered a customised withdrawal tool from deleted files. The tool forged risk-control parameters, constructed withdrawal requests and invoked the withdrawal process. Movement between the affected systems remained under investigation.

Once the funds left, containment depended on other systems. BlockSec traced roughly $340,000 in stablecoin balances frozen by Tether and Circle. NEAR Intents said the attacker attempted more than $50 million through its service. Requests were declined or execution halted; approximately $166,000 passed through and $503,000 was held. NEAR's disclosure allowed for up to 10 per cent uncertainty in its figures.

THORChain responded to requests for intervention by distinguishing a full network halt from selectively freezing funds or individual swaps. It said the protocol does not censor by design.

As of 29 September, BlockSec put the combined issuer freezes and NEAR's self-reported held funds at approximately $840,000 against $387.5 million stolen, about 0.2 per cent. That is a dated containment snapshot, not a final recovery total.

BTC withdrawals resumed on 28 September and ETH on the 29th. CryptoTimes reported that CEO Gracy Chen said on 30 September that USDT withdrawals were also running; its schedule lists Ethereum, BSC, Solana and Tron. Bitget scheduled other tokens, fiat and P2P services to resume on 2 October.

Reopening withdrawals restores access for customers. It does not retrieve the assets stolen from the exchange. Those tasks depend on different evidence, different operators and different powers.


Zano: A Chain Restored, Accounts Still to Settle

Zano's emergency release excluded transactions after block 3,833,000, the 26 August height immediately before Hard Fork 6. The release explicitly states that deploying it means choosing to adopt the rollback and protocol changes. Recovery therefore required participating operators to follow the updated chain.

The decision followed a flaw in HF6's Gateway Addresses. Cointelegraph's reporting of Zano's post-mortem puts unauthorised issuance at 36.9 million ZANO and 1.8 quadrillion units of Freedom Dollar. It reports Zano's explanation that the unauthorised ZANO could not be distinguished from legitimate coins, preventing selective removal of the counterfeit supply.

The rollback also excluded legitimate transactions from the affected period. The recovered chain removed the counterfeit supply, but left exchanges, payment services and users with that activity to reconcile.

Value already settled on other networks remained beyond the rollback's reach. Bitcoin.com reported Freedom Dollar's account that several million dollars of its assets had been exchanged for counterfeit fUSD. Freedom Dollar said it would absorb those losses. That commitment is separate from Zano's wider restitution proposal.

CoinCentral reports that Quinten van Welzen, Zano's head of marketing and growth, said reimbursement would draw on the development fund, team holdings and support from large holders, without new ZANO issuance. The report described a claims process still to be published.

Restoring the chain and compensating affected users are separate tasks, running on separate timelines.


Limit Break: Repair the Permission Before the Return

The Limit Break incident exposed transfer permissions that remained active after Magic Eden stopped using the processor. Cryptopolitan reports that Magic Eden stopped using Payment Processor V2 in October 2024 and closed its EVM marketplace in the first quarter of 2026. Wallets that had granted approvals still carried that authorisation on-chain.

On 24 September, an attacker exploited a vulnerability in the processor to steal 305 NFTs from wallets with standing approvals.

The same report says 0xQuit, Yuga Labs' VP of Blockchain, used the same flaw defensively to move a reported 23,155 NFTs, valued above $5.7 million by his estimate, into protective custody. These were rescued assets, distinct from the NFTs already stolen.

The theft and the rescue used the same vulnerability. Recovery then required a different action: owners had to revoke the vulnerable approval before reclaiming rescued assets through the claim site. Cancelling a marketplace listing did not remove the underlying permission.

A return to the original wallet would not be enough if the processor retained authority to take the asset again. The recovery process had to repair that permission before completing the return.


Base / Cobalt: Conditions and Issuer Powers

Base's Cobalt upgrade, announced on 30 September as live on mainnet, introduces two different controls over how assets move.

Validity Transactions let users attach conditions to a signed transaction. Base checks those conditions against the current chain state before the transaction becomes eligible to be included in a block. Signing alone is therefore insufficient: the conditions must also hold. That check does not guarantee the transaction will execute successfully.

The other change gives token issuers a recovery tool. For tokens using Base's B20 standard, seizeWithMemo lets an authorised administrator move a holder's balance to another account without the holder's approval. The older operation could destroy a blocked balance; this one transfers it without changing the total supply.

Base's documentation sets limits on that power. The administrator must have the required role, seizure must not be paused, and the issuer must configure which accounts can be targeted. By default, every account is protected from seizure. Issuers can also restrict where seized funds may be sent; without those restrictions, any destination is permitted.

These are designed capabilities, not evidence of misuse. One lets users limit when their signed transactions can proceed. The other lets issuers configure when an administrator can move a holder's balance without consent. Both matter when assessing who controls an asset.


Weekly Freeze Ledger

45 freezes • $40.10M frozen

The ledger covers Saturday 26 September through Friday 2 October 2026, counting issuer-enforced freezes of $200K or more across Ethereum, Tron and XRPL.

DateFreezesFrozen
Sat 26 Sept1$611.0K
Sun 27 Sept1$2.70M
Mon 28 Sept6$4.40M
Tue 29 Sept2$632.5K
Wed 30 Sept24$23.37M
Thu 1 Oct9$7.83M
Fri 2 Oct2$552.7K
Weekly total45$40.10M

Issuer and chain concentration dominated the week: 43 of the 45 freezes were USDT on Tron. The two exceptions were USDC freezes on Ethereum, on Saturday and Wednesday, and no XRPL freeze cleared the threshold. Wednesday's 24 freezes and $23.37M accounted for more than 58 per cent of the week's value; 22 of its Tron freezes landed in the same minute, and none has been attributed to a specific case. Excluding Wednesday, daily totals ranged from roughly $550K to $7.8M.

Daily amounts are rounded as published in the digests; the weekly total sums those rounded figures.

Source: The Cipher Index Stablecoin Freeze Tracker


What to Watch

In a 1 October update to its infrastructure-incident notice, MetaMask said it had worked with partners to exit affected validators as a precaution. It reported no indication that MetaMask wallets or customer funds had been affected and said containment and verification remained underway. Its preceding notice said it did not manage clients' staking withdrawal keys. The technical cause and full scope remain to be disclosed.

For Bitget, watch for confirmation that the services scheduled to resume on 2 October have reopened. Further disclosures may also clarify the third-party vulnerability and how the attacker moved between compromised systems.

For Zano, the next material evidence is how exchanges and services reconcile legitimate activity excluded by the rollback, and how restitution moves from funding commitments to claims and payments.

For Limit Break, the reported rescue count does not establish how many assets have been returned. Recovery progress should distinguish protective custody, completed claims and permissions still requiring revocation.


Corrections and Continuing Investigations

Bitget. The forensic report dates malicious activity in the available logs, but does not establish every movement between systems. Frozen balances, assets returned to the exchange and the exchange's own replacement funding must remain separate measures.

Limit Break. The NFT rescue does not establish a reconciled WETH loss total or a complete return count. Those figures remain outside this edition's accounting.


Further Reading


Published by the Zero Trust Network. Research supported by CipherBot and CipherIndex.

Discussion