The headline incidents of the week — the Bitget aftermath, the NEAR Intents return, the Tren de Aragua capture — carried several smaller storylines worth tracking on their own.

AI-assisted tracing gets its first marquee case

Chainalysis' use of AI tooling in the Bitget trace compressed an investigation that would have taken roughly 20 hours of manual cross-bridge work into under 10 minutes, according to reporting by CoinGape and The Cryptonomist. The stolen funds crossed multiple bridges and chains on their way from XRP to Bitcoin; mapping each hop manually is the slowest part of post-hack forensics, and the point at which stolen assets usually become untraceable in practice.

Speed matters more than elegance here: freeze requests to issuers and exchanges are only effective inside the window before funds fragment. Whether the compression holds on messier traces — and whether it survives adversarial laundering designed to waste automated analysis — is the open question. But the Bitget case is the first large-scale demonstration that AI-assisted tracing is operational, not theoretical.

THORChain's refusal hardens into a stance

Bitget's stolen funds moved through THORChain in volume, and the protocol refused the exchange's requests to block the linked addresses — a decision The Currency Analytics framed as decentralized infrastructure being "put on trial." No freeze came, and none is structurally possible without the kind of operator gate NEAR Intents used when its SHIELD system rejected more than $50 million in Bitget-linked swaps.

The contrast is becoming the industry's cleanest natural experiment: one cross-chain venue screens and blocks; another processes and refuses. Regulators have so far punished the first kind of venue less than skeptics predicted, and the second kind not at all. Watch whether stablecoin issuers — the only parties with unilateral freeze power over a large share of crypto liquidity — start treating sustained non-cooperation by a protocol as a listing risk. That is where leverage actually exists.

Critical findings published against DEX223 contracts

An independent researcher published line-by-line review findings against the Dex223 contracts suite on October 1–2 via the project's bug bounty tracker, including a critical-severity flaw in which a multicall function reuses attached ETH value across sub-calls — described in the disclosure as enabling pooled-ETH drainage — alongside margin-module value reuse, oracle manipulation and slippage risks in a second report.

The disclosure states no state-changing exploit was broadcast on-chain. The findings cover 14 custom contracts across dex-core, periphery, converter, payments and token libraries at a pinned commit. Until the project responds or remediates, the report is a published researcher analysis rather than a confirmed incident — but the multicall pattern it describes is the same value-reuse class that has drained other protocols, and integrators should treat the pinned commit as unvetted.

Briefly noted

  • Bitget's rebuilt $309 million Protection Fund is now the exchange's main customer backstop, with only ~$1.1 million of the $388 million theft frozen so far.
  • The NEAR Intents attacker's full $3.8 million return took roughly a day from ultimatum to settlement — no ransom disclosed, investigation dropped.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.