0x0aae7eb20aae…0aae7eaf

ConfirmedStablecoins727 vB140 sat/vB4 min decode

Bitget Hack Splits Cross-Chain Swaps Into Two Compliance Models

NEAR Intents blocked over $50 million in Bitget-hack transfers and froze $503,000 mid-swap, while THORChain processed $6.3 million and refused Bitget's blocking request — splitting cross-chain finance into two products.

The Bitget hack split the cross-chain market into two products
WitnessThe Bitget hack split the cross-chain market into two productsAI-generated

Outputs

  1. NEAR Intents blocked more than $50 million in transfer attempts linked to the $388 million Bitget hack; its SHIELD system froze $503,000 mid-transaction, per GM Alex Shevchenko's report

  2. THORChain processed about $6.3 million in ether-to-bitcoin swaps from a wallet tied to the attack and declined Bitget's request to block the addresses

  3. Circle and Tether froze roughly $320,000 in USDC and USDT linked to the breach; NEAR holds the intercepted funds pending a legal process via the Kodex portal with no published release authority

NEAR Intents, the cross-chain swap service that routes exchanges between blockchains through a network of solvers, blocked more than $50 million in transfer attempts linked to the $388 million Bitget hack, according to a report by general manager Alex Shevchenko. THORChain, the largest decentralized swap network, took the opposite path in the same week: it processed roughly $6.3 million in ether-to-bitcoin swaps from a wallet tied to the attack and declined Bitget's request to block the addresses involved.

The divergence marks the first time the cross-chain market has publicly split into two distinct products — one that screens flows, one that structurally refuses to.

How the freeze worked

NEAR's screening system, SHIELD, froze about $503,000 mid-transaction, while roughly $166,000 passed through before detection caught up, Shevchenko wrote. The $50 million figure counts refused transfer attempts with duplicates removed, carries an error margin Shevchenko put at about 10%, and measures volume the service turned away rather than funds it holds.

SHIELD screens quote flows against TRM Labs, AMLBot, PureFi and Binance AML data, alongside an internal AML database, according to the service's risk and compliance documentation. Shevchenko framed the blocked volume against ordinary business: NEAR routinely processes more than $100 million in daily volume, and the refusals were a negligible fraction of it. The screening did not cost the service its flow.

The operational lesson is structural. Cross-chain infrastructure has long been treated as incapable of stopping stolen funds, with no operator to call and no account to freeze. The Bitget flows show the constraint is a business decision, not a technical limit. A service that takes custody mid-swap, even briefly, can screen at that moment.

The censorship debate

NEAR markets itself as permissionless and uncensorable, and freezing funds mid-swap sits uneasily beside that claim. Vini Barbosa, a technical writer building at Ramp Labs, argued on X that permissionless must mean neutral, and that a rail willing to restrict suspected unlawful users will also restrict people moving money under repressive governments.

NEAR cofounder Illia Polosukhin answered in narrower terms: permissionless means nobody needs permission to own assets, transfer them or deploy contracts. Shevchenko's own phrasing concedes the gap. The service will remain "permissionless infrastructure, but with boundaries."

THORChain stated its position on X: "A halt is not a selective freeze of specific funds or an individual swap. THORChain is permissionless and doesn't censor by design." The protocol asked what responsibility Bitcoin, Ethereum and BNB Chain bear when stolen funds move across them, and noted that the addresses that took $10.7 million from its own vaults in May were never blacklisted either. It gave the same answer after the $1.5 billion Bybit theft last year.

Industry pushback followed. Bitget CEO Gracy Chen, whose request THORChain declined, wrote that decentralization "is a design principle, not a shield for facilitating known stolen funds." OKX founder Star Xu disputed the Bitcoin comparison from the other direction: THORChain's validators jointly control the assets in its vaults, making the network an intermediary rather than a base layer — and the same node operators halted the chain for 39 days in May when its own vaults were at stake.

At a third layer, Circle and Tether froze about $320,000 in USDC and USDT linked to the breach. The amount is a rounding error against the total loss, but issuer-level freezing remains crypto's most reliable circuit breaker because it operates on the asset, not the application.

The $503,000 question

NEAR is holding the intercepted $503,000 pending a legal and recovery process and has waived any recovery bounty Bitget offered. Formal requests route through the Kodex law-enforcement portal. Shevchenko's report does not name who can authorize a release and describes no process for a wrongly flagged user to reclaim funds — while the screening that produced the freeze operates on estimates with a stated 10% error margin.

A screen that halts a legitimate transfer, with no published release authority and no remedy, is a service holding someone's money on suspicion. The securities and payments industries resolved that problem with defined processes, because holding funds without one creates liability in almost every jurisdiction. The first dispute over the $503,000 will test whether the release of those funds follows a rule anyone can see.

via google.com (Original)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles