0x3fdd89553fdd…3fdd8952

ConfirmedSecurity605 vB145 sat/vB3 min decode

NEAR Intents Blocked $50M in Bitget Hacker Swap Attempts

NEAR Intents blocked over $50 million in attempted transfers tied to the $388 million Bitget hack, freezing $503,000 while $166,000 slipped through to other providers.

Near Intents blocks $50 million in Bitget hacker swaps, here's what happened
WitnessNear Intents blocks $50 million in Bitget hacker swaps, here's what happenedAI-generated

Outputs

  1. NEAR Intents blocked more than $50 million in attempted transfers linked to the $388 million Bitget hack, freezing about $503,000 mid-transaction.

  2. Approximately $166,000 in stolen funds passed through NEAR Intents; most rejected funds moved via other providers, per GM Alex Shevchenko.

  3. The intervention contrasts with THORChain, which refused Bitget's request to block attacker addresses; a CoinDesk analysis found $6.3 million in ether-to-bitcoin swaps from one attacker wallet.

Cross-chain swap service NEAR Intents blocked more than $50 million in attempted transfers linked to the hackers who stole $388 million from Bitget, according to a report by the protocol's general manager, Alex Shevchenko. The intervention froze roughly $503,000 mid-transaction, while about $166,000 in stolen funds passed through the service before detection.

The $50 million figure represents attempted transfers rather than recovered funds, and most of the rejected money subsequently moved through other providers, Shevchenko said. He noted duplicate attempts were removed from the tally and cautioned the estimates could deviate from actual amounts by up to roughly 10%.

"NEAR Intents routinely processes $100M+ of a crosschain trading volume in a day. Yet in this case, only a negligible fraction of the hacked funds were flowing through us," Shevchenko wrote.

The blocking mechanism, which NEAR Intents calls SHIELD, flagged the transfers using inputs from know-your-transaction (KYT) vendors, intelligence providers, independent researchers and large centralized industry players. Based on those signals, the protocol decides whether to process, delay or reject a transaction.

A split with THORChain

The stance places NEAR Intents in direct contrast with THORChain, which has rejected Bitget's request to block attacker addresses. A CoinDesk analysis on Monday identified approximately $6.3 million in completed ether-to-bitcoin swaps from a single wallet tied to the Bitget attacker. THORChain has defended its position by arguing that its emergency shutdown controls exist to protect the protocol itself, not to selectively freeze funds.

Bitget disclosed the breach on Sept. 24 after attackers bypassed security controls protecting its exchange wallets. The company has since said it patched the vulnerability, published attacker addresses, and offered bounties for efforts to freeze or recover funds. Circle and Tether, the issuers of USDC and USDT, have frozen about $320,000 in stablecoins connected to the breach, as CoinDesk reported last week.

The permissionless question

The intervention has drawn scrutiny of NEAR Intents' self-description as permissionless, open and uncensorable. Documentation for the service says it screens swap requests for links to reported hacks and can delay suspicious transactions — controls that apply at the swap layer, not to wallets on the NEAR blockchain itself.

Vini Barbosa, a technical writer and documentation engineer building at Ramp Labs, was among those questioning the framing. "Permissionless does mean neutral. It's the whole point of building something 'permissionless'," he wrote on X, warning that restrictions on supposedly unlawful users could also affect people resisting government repression.

"I'm not saying it's a bad product. It has its use/niche and is valuable for the vast majority of users," he added.

NEAR co-founder Illia Polosukhin defended the distinction. "Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR," he wrote on X. "It does not mean every application or liquidity provider must process every transaction."

Frozen funds await legal process

NEAR Intents is holding the intercepted $503,000 pending legal and recovery proceedings. Shevchenko asked Bitget to contact the service through legal and law-enforcement channels and said the protocol would waive its recovery bounty.

"NEAR Intents will remain permissionless infrastructure, but with boundaries," he wrote. "We will actively fight the laundering of hacked funds."

His report did not specify who can authorize the release of the frozen funds or how a wrongly flagged user could reclaim them — an operational gap that will likely shape how the industry evaluates similar interventions. With THORChain still routing attacker funds and issuers freezing only a small slice of the $388 million haul, the recovery process for Bitget remains fragmented across providers with conflicting policies.

via CoinDesk (Source)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles