0x4d0eccb64d0e…4d0eccb9

ConfirmedSecurity602 vB28 sat/vB3 min decode

NEAR Intents SHIELD Freezes $503,000 in Bitget Hack Funds

NEAR Intents' SHIELD froze $503,000 linked to Bitget's Sept. 24 hack and blocked $50M+ in attempted swaps, but $166,000 slipped through. THORChain refused Bitget's blacklist request.

Outputs

  1. $503,000 in Bitget hack-linked funds frozen mid-execution by NEAR Intents SHIELD on Sept. 28

  2. $50M+ in additional attempted swap transfers detected and blocked by SHIELD

  3. Roughly $166,000 in hack-linked swaps passed through SHIELD to other providers

  4. Bitget estimates $387.5M reached attacker-controlled addresses in Sept. 24 breach

  5. THORChain declined Bitget's blacklist request, citing 'decentralized and permissionless' design

NEAR Intents' SHIELD risk system froze $503,000 mid-execution that its engine linked to Bitget's Sept. 24 exchange hack, according to a Sept. 28 incident report by general manager Alex Shevchenko. The screening layer detected more than $50 million in additional attempted swaps and blocked most from proceeding; roughly $166,000 still passed through to other providers.

Bitget CEO Gracy Chen acknowledged the freeze on X, writing that NEAR Intents had "waived their own bounty share so we can recover more." Under the exchange's published bounty terms, Bitget pays 5% of eligible frozen funds and 5% of recovered funds. Eligibility sits with Bitget; assets addressed through court orders or law-enforcement requests fall outside.

How does SHIELD flag and freeze swaps?

Shevchenko wrote that the system aggregates risk signals from transaction-monitoring vendors, researchers and industry participants. When the engine identifies hack-related activity, SHIELD can withhold swap quotes or halt execution already underway. He characterized the design philosophy directly: "permissionless doesn't mean neutral."

NEAR Intents' technical documentation describes authorized parties submitting incident reports and integrated services querying the registry before processing swaps. Quote-time checks operate live. Broader execution-stage enforcement is still rolling out, with restrictions targeted at affected services rather than triggering platform-wide shutdowns. The architecture preserves permissionless access for clean flows while concentrating enforcement on flagged counterparties.

Why did THORChain take a different path?

THORChain declined Chen's Sept. 26 request to refuse service to Bitget-flagged addresses. Its official account described the protocol as "decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain." A flagged address subsequently completed an XRP-to-Bitcoin swap after both the exchange's request and the protocol's response, per The Defiant.

The episode crystallizes a governance split inside cross-chain infrastructure. NEAR Intents runs an active screening layer that can hold execution-stage assets pending legal recovery. THORChain maintains a no-blacklist posture even when a named victim makes a direct request and identifies specific wallets.

What does Chainflip's earlier proposal show about screening and seizure?

Chainflip's February 2025 response to the Bybit hack exposed a broker-bypass vulnerability: anyone could create the intermediary that interfaces use to submit swaps. Its proposed fix gave selected brokers authority to block submissions from competing brokers while preserving user-side restitution. "Rejected deposits are sent back directly to the refund address specified by the user," Chainflip wrote.

The separation carries operational weight. Authority to reject a swap and authority to seize or redirect funds are distinct powers. Expanding one does not automatically transfer the other, a distinction that affects both protocol design and victim recovery prospects.

Where do the frozen funds sit now?

The $503,000 remains restricted pending legal and recovery procedures, Shevchenko said. He directed Bitget to use appropriate legal and law-enforcement channels to release the assets. Chen said the exchange would follow the legal and recovery process on its end.

Bitget estimates roughly $387.5 million reached attacker-controlled addresses during the breach. Shevchenko called his own flow figures rounded estimates and warned that transaction-labeling errors could move the totals, projecting deviation from true values at no more than 10%. Flows that SHIELD rejected from execution rerouted to other providers, extending the tracing work for Bitget's investigators.

The next procedural test is which channel—court order, mutual agreement, or law-enforcement request—Bitget will use to unlock the funds, and whether NEAR Intents will publish a post-resolution accounting of the blocked and held balances. The answer will shape how other cross-chain protocols calibrate their own screening-versus-neutrality tradeoffs.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles