skip to content

Research • October 02, 2026 • 16 mins

Weekly Research Brief: Bitget Hack Postmortem, White House AI Summit, SEC Buybacks FAQ

This week, Thad Pinakiewicz writes a postmortem of the $387.5 million Bitget hack; Zack Pokorny digs into the SEC’s FAQ on token buybacks; and Lucas Tcheyan shares takeaways from the White House AI summit.

Welcome to Galaxy Research's Weekly Research Brief. Subscribe to get this newsletter delivered to your inbox every Friday morning.

In this week's edition, Thad Pinakiewicz writes a postmortem of the $387.5 million Bitget hack; Zack Pokorny digs into the SEC’s FAQ on token buybacks; and Lucas Tcheyan shares takeaways from the White House AI summit.

Déjà Vu, Lazarus Crew: $387.5m Bitget Exploit Repeats a Pattern

Late last week, Bitget disclosed that attackers had stolen $387.5 million from its hot and warm wallets through a series of unauthorized transfers, and it temporarily halted all withdrawals.

There's a specific feeling you get reading a crypto hack post-mortem and realizing you've already read it. Not just a similar one, the same one, with the nouns swapped.

First, let’s recap what happened with Bitget. The losses span 11 blockchains, including Ethereum, XRP, TRON, Arbitrum, Base and BSC, and the largest single-chain loss was about $83 million in XRP. According to Bitget CEO Gracy Chen, private keys and cold wallets were not compromised, and her statement is confirmed by hundreds of millions of dollars in tokens remaining in the exploited addresses (more on this distinction in OUR TAKE below). Instead, attackers exploited two third-party security products (utilizing a zero-day exploit to obtain high-level internal credentials), inserted fraudulent withdrawal commands into the wallet backend, and deleted those commands after the funds were sent out. SlowMist, a security firm hired by Bitget, traced the earliest malicious activity to Aug. 31 and recovered a custom withdrawal tool built around Bitget's withdrawal logic. It all points to a highly researched, targeted exploit of Bitget’s wallet management. Bitget attributes the attack to North Korean actors, citing IP behavior and onchain analysis, and onchain sleuthing firms Elliptic and TRM found wallet overlaps with prior hacks.

Much of the stolen funds moved through THORChain, which declined Chen's request to refuse service on the grounds that it is decentralized and permissionless (just ignore the security freezes it has done in the past). NEAR Intents took the opposite approach, blocking more than $50 million in attempted laundering flows and freezing about $503,000 mid-execution. Bitget's protection fund, and applicable Proof of Reserve (PoR) overcollateralization, covered the exploit amount, with Bitget covering the entirety of the exploit from the protection fund, which has since been topped up to $300m.

Then on Thursday, NEAR Intents got hit with an exploit. A bug in its Omni deposit and withdrawal infrastructure led to roughly $3.8 million in losses, which it says it will fully compensate. ZachXBT flagged multiple abnormal outflows from the BSC hot wallet, with the funds sent to KuCoin and bridged onward to Bitcoin.

Our take

If this episode sounds familiar, it should. In February 2025, the North Korean hacker group Lazarus took $1.5 billion from Bybit the same way. Instead of stealing Bybit's keys, they compromised Safe{Wallet}'s infrastructure, served the signers a doctored interface, and the signers approved what looked like a routine transfer. The cryptography worked perfectly. It signed exactly what it was told to sign.

That's the landscape for major exploits these days. Nobody attacks the private-key math, because that math is (for now) unbreakable. They attack whoever, or whatever, tells the math what to do.

A private key is a perfect (depending on the cryptographic protocol’s quantum resistance) mathematical way to protect your funds. It will sign anything anyone puts in front of it, so protecting it is utmost. Exchanges’ private key security is some of the best in the world, and we haven’t seen a private key exploit from a major crypto venue in years. Phemex had a private key exploit in January 2025 for only ~$50m, and Coincheck had a major $500m+ exploit in 2018, but that might as well be the Paleozoic era in crypto years. Private key security is mostly solved, so for exploiters the valuable target isn't the key; it's whoever or whatever decides what gets put in front of the key.

We don't know the full details yet, but the shape of the theft tells you most of what you need. If you had the keys, you'd take everything. Instead, Bitget's first notice described unauthorized transfers from a limited number of hot wallets, and SlowMist believes the haul would have been larger if two forged BTC withdrawal orders hadn't errored out. That's what impersonating an approval pipeline looks like: you only get what the pipeline will process, one convincing request at a time. A partial drain is the fingerprint of an exploit in an intermediary service, not a key exploit.

Bitget still hasn't named the vendors that were exploited. The forensic reports call them "Product A" and "Product B." Hopefully it isn't Gnosis Safe again. SlowMist described multiple “nodes” of Product A being infected with malicious code from the zero-day exploit.

Nick Szabo wrote "Trusted Third Parties Are Security Holes" in 2001. Every year, the industry rediscovers this lesson, each time at a cost of roughly nine figures. The cryptographic math is secure; it’s the structure around it that needs hardening. The AI industry learned a similar lesson this summer when frontier labs’ misaligned agents exploited third-party integrations to escape testing sandboxes.

The aftermath has its own déjà vu. The bulk of the stolen funds was moved and converted, some through THORChain, and THORChain’s X handle replied that it is decentralized and permissionless, so its hands were tied. The Bybit loot (as well as portions of ColdCard and countless other exploits) followed a similar chain-hopping path through THORChain, so at this point it's less a bridge than a getaway car for the DPRK.

One more thing. Nobody has attributed Thursday's exploit of NEAR Intents, and we want to be clear that we are not attributing it either. We simply observe that on Monday NEAR Intents confiscated $500,000 of what looks like Kim Jong Un’s lunch money, and on Thursday someone pilfered $3.8 million from the multichain transaction protocol’s BSC hot wallet. Through the deposit and withdrawal infrastructure. Which is, if you've been following along, the intermediary layer.

Déjà vu. Again. – Thad Pinakiewicz

AI Gets a New Name, The Rules Stay the Same

President Trump convened executives from leading AI companies and tech firms for a lunch Tuesday where they signed the White House Accord on Super Intelligence and he signed an executive order renaming artificial intelligence as “super intelligence.”

Executives from leading frontier labs OpenAI and Anthropic as well as Tesla, Nvidia, Meta, Amazon, Alphabet, Microsoft, AMD, and Palantir attended the lunch. Google, Anthropic, Meta, OpenAI, Nvidia, and XAI signed the Accord. It commits them to four layers of controls and audits. These include internal controls on training and deployment around cyber, biological, and chemical risk, plus unintended system access; internal teams to check those controls; independent external auditors; and board committees to receive the reports. The Accord carries no penalties for noncompliance, doesn't require companies to publish audit results, and gives the government no enforcement role. It says that over time "it may make sense to codify these steps into laws or regulations." Trump called it "morally binding."

The executive order applies to correspondence, websites, reports, and other non-statutory documents, and states that the executive branch "will not acknowledge" the older terms for this technology. It defines SI as the same technologies covered by the statutory definition of AI. It also gives the President's science adviser 60 days to propose legislative language for a new federal definition.

Our take

The AI summit and rebranding are an attempt to quell growing anxiety among the American public over the negative externalities caused by the rapid development and deployment of AI. A CNN poll last week found 75% of Americans feel closer to fear than hope about AI. A UMass poll found fewer than one in four approves of Trump's handling of it. There is an existential fear that AI adoption will severely disrupt society, lead to mass layoffs, and could even end humanity.

These fears are at direct odds with the views of the White House and some senior AI executives, who view the race to develop AI as existential to the continued supremacy of the United States. But the lack of clear and coherent messaging increasingly places their views at the odds with the public. When it comes to change, fear of the worst often outweighs hope for the best, and that exact dynamic is playing out today.

Tuesday was a step forward toward changing the narrative, but far from a solution. There is just too much distrust in the government, labs, and technology companies for a renaming of AI and an agreement to self-regulate to reset the narrative. The more likely path toward shifting the narrative is going to come from AI introducing real benefits into everyday lives. And we are likely just at the beginning of that process.

Public perception is likely to shift as we enter a new period of adoption driven by increasingly sophisticated harnesses like Meta’s Muse, Instinct, and GrokBot. These products significantly enhance the average individual’s ability to use AI as more than just a chatbot, and as a personal assistant or chief of staff.

The regulatory path is murkier. Leopold Aschenbrenner’s Situational Awareness essay predicted company-level rules initially followed by state intervention in 2027 or 2028. The AI 2027 authors’ view is that Washington stays light-touch until recursive self-improvement, then intervenes directly. Tuesday’s meeting aligns with both scenarios, advancing light self-regulation and a questionable rebranding, but nothing that appears to materially stymie the current trajectory of AI development. -Lucas Tcheyan

Who Is a 'Central Party'? Open Questions in the SEC's Crypto FAQs

Late last week, the SEC’s Division of Corporate Finance issued FAQs applying the Commission’s March 17 Interpretive Release on how federal securities laws apply to crypto assets.

The FAQs are explicitly the staff’s views, and do not represent a Commission rule or statement and do not carry legal force. But they give the market an understanding of how this current SEC staff intends to operate the Commission. The FAQs address three primary areas:

  1. On classification, a “Staking Receipt Token” that is a receipt for a digital commodity not subject to an investment contract is itself a “digital tool” under the SEC’s five-prong token taxonomy (Q1.2), because it serves the practical function of evidencing a holder’s ownership of an underlying asset. A Staking Receipt Token may instead be classified as a digital commodity if issued by a protocol-based Liquid Staking Provider because its value is then linked to the programmatic operation of a “functional crypto system” and supply and demand dynamics. Q1.3 defined “receipt” (which also applies to Redeemable Wrapped Tokens) as “an instrument certifying that a stated amount of an asset has been deposited with a depository or custodian issuing the receipt and evidencing the depositor’s ownership of” it. A receipt 1) doesn’t change any rights, obligations, or benefits of the deposited asset; 2) gives the holder no additional financial incentives or benefits; and 3) doesn’t transfer ownership or control of the underlying asset to the issuer, so the issuer cannot transfer, lend, pledge, rehypothecate, or otherwise use the deposited asset for any reason.

  2. On investment contracts, promoting a crypto system’s current utility or indefinite aspirational features without noting profit likely isn’t a promise of “essential managerial efforts,” and once a system is functional, services to secure, maintain, improve, or enhance it, or to facilitate network effects, would not involve essential managerial efforts would not satisfy the Howey test.

  3. On buybacks, the most scrutinized part of the FAQ, Q2.5 asks whether an issuer's announcement of a buyback program for a non-security crypto asset (whether for treasury management, supply reduction, protocol-funded burns, or rebalancing) is itself a representation or promise to undertake essential managerial efforts, which is one way a token sale can become an investment contract under Howey. Staff answer that where a crypto system is functional and has no central party, such an announcement would not be that kind of promise. Staff added the phrase “and has no central party” on Sept. 28, 2026, three days after issuance of the FAQ and after industry criticism that the original wording, which required only functionality, was too broad. Where a system is not functional, an announcement could still be such a promise if the issuer presents the buyback as creating yield or return for token holders. The FAQ doesn't say how a buyback announcement is treated on a functional system that does have a central party. Since the answer no longer covers that case, it presumably falls back to a general facts-and-circumstances Howey analysis, though that is our inference as laypeople and not something the staff say.

The FAQs use terms defined in the March Interpretive Release:

  • Functional: a system is functional if its native crypto asset can be used on it in accordance with its programmatic utility.

  • Decentralized: a system is decentralized if it operates autonomously with no person, entity, or group holding operational, economic, or voting control.

  • Central party: defined by the same control test as decentralization, so the Q2.5 revision effectively conditions the buyback answer on decentralization, though the FAQ doesn't say this explicitly.

The publication builds on the seminal 2017 DAO report, the 2019 staff Framework, and 2025 statements on memecoins, mining, stablecoins, and staking, which the March 2026 Release superseded. FAQ2.3 cites the proposed Regulation Crypto Assets, which would create two offering exemptions ($5 million over four years; $75 million per 12 months for project fundraising) and a conditional safe harbor for when an investment contract no longer exists. The Sept. 17 Innovation Exemption, which covers exchange and dealer status for tokenized stock trading, falls under the same "Project Crypto" initiative but is a separate action that the FAQ doesn't mention.

Our take

The FAQ received pushback, most notably on the buyback portion (Q2.5) which was revised three days after initial publication to include language around the lack of a central party in control of the system conducting buybacks. Before the amendment, the answer centered on protocol functionality alone. Supporters read this as a clear path for functional projects to conduct buybacks without the announcement being an essential managerial effort, which was viewed as a big win since buybacks triggering securities laws have been a looming concern. Critics, however, read the definition as overly broad, a concern which ushered in an onslaught of questions. For example: a widget business can sell tokens to the public and use a portion of the revenue generated from selling its goods to buy back and burn said token. Because the smart contracts through which it receives payments works and no explicit promises were made, the FAQ’s logic would put the token outside of securities laws even though it functions similar to a profits interest. Technically, the argument could be made that the FAQ is limited to non-security digital assets, so a company’s token wouldn't qualify, but the critical interpretation of the language questioned where that limit appears in the text.

The disagreement between skeptics and proponents points to a deeper problem. Distinguishing a “business” from a “protocol” seems to require looking at control, which is close to decentralization, yet the SEC did not include decentralization as a factor in its prior investment contract analysis, which instead turns on issuer representations or promises to undertake essential managerial efforts. Staff revisions made a few days after publication addressed this concern by explicitly adding "and has no central party" to its answer around buyback programs, which now reads as: “Where a crypto system is functional and has no central party, an issuer’s announcement of a non-security crypto asset buyback program would not constitute a representation or promise to undertake essential managerial efforts.”

Even with the amended language, open questions remain. The buyback answer was narrowed to functional systems with no central party, but the FAQ doesn't say how buybacks by projects with a central party are treated, and it doesn't say how much influence counts as "control." The first is specific to the newly released FAQ, while the second is a longstanding question. The SEC has defined control in other releases, such as the Innovation Exemption, which defines it as the power to direct the management or policies of a trading venue, but it has not said whether that definition informs the "central party" standard in the FAQ. - Zack Pokorny

Other News

  • 💰 Anthropic prospectus details leak; IPO could value lab at >$2t

  • 🔐 SEC proposes crypto custody rules for investment advisors and funds

  • 🏹 Robinhood rolls out AI trading agents to millions, plans perps

  • 🧪 Morgan Stanley sets up “lab” to test stables, DeFi, tokenization

  • ⛓️ Blockchain.com said to target IPO this year at $4b-$6b valuation

  • ⚔️ Tether rebuts Senate Dems’ report claiming USDT is ‘lifeline’ for Iran

  • 🤝 Citi, Coinbase partner to let bank’s clients accept stablecoin payments

  • 🤔 Ostium lets hack victims choose: $1k now, or pro rata share of any recoveries

  • 🦊 MetaMask staking exits Lido validators after infrastructure compromise

  • 🔷 Ethereum Foundation launches ZK-based private payments for LLM API credits

Charts of the Week: Polymarket’s Polymaths

Are traders on Polymarket specialists or generalists, and how does their performance vary? We define users as specialists if more than 60% of the markets they traded fall under a single topic, measured across at least five categorized markets. By this definition, 44.1% of traders are “specialists” and 55.9% are “generalists.”

Polymarket specalists vs generalists amount

These questions are answerable because Polymarket tags every market. In order to avoid classifying every trader as a “specialist,” we collapse the tags into 10 topics: crypto, sports, politics, finance, economy, weather, culture, world, tech and science, and business. Sub-topics reliably carry their parents (for example, soccer markets are tagged sports).

Polymarket specialist traders

Specialists do slightly worse: 28.1% of them finished profitable against 30.4% of generalists. This is because 61% of them concentrate on three topics that underperform (sports, politics, culture).

10 Poly percent profitable

For more insights, read Galaxy Research's new report, an analysis of 2.9 million Polymarket accounts from onchain data curated by oracle network Stork – Will Owens

Got feedback on this newsletter? Email [email protected]. We’d love to hear from you.

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.