0x6da5fc566da5…6da5fc53

ConfirmedDeFi1,005 vB158 sat/vB5 min decode

THORChain Refusal to Block Bitget Hack Funds Ignites Decentralization Debate

THORChain refused to block $387.7M in Bitget hack funds, citing permissionlessness, while NEAR Intents stopped $503,000 via its SHIELD layer — exposing the industry's unresolved divide.

Outputs

  1. THORChain refused Bitget CEO Gracy Chen's request to block addresses linked to the $387.7M Sept. 24 hack, having previously processed ~$1.2B in Bybit hack funds

  2. NEAR Intents' automated SHIELD layer flagged over $50M in hack-linked flows, blocked $503,000 in execution, and let $166,000 pass through

  3. THORChain halted its own chain in May after a vault exploit drained over $10M, and can pause trading via emergency node controls but has no address-screening functionality

THORChain has refused to block addresses linked to the $387.7 million Bitget hack, a decision that has split the crypto industry over whether permissionless protocols carry any obligation to stop the movement of known stolen funds.

The hack, which struck the exchange on Sept. 24, sent $387.5 million in stolen assets moving rapidly across chains, with a portion routed toward THORChain, the decentralized cross-chain swap protocol. Bitget chief executive Gracy Chen publicly appealed to the platform to refuse service to attacker-linked addresses. "The industry is watching," she said.

THORChain declined. The protocol had already processed roughly $1.2 billion in funds funneled by the Bybit hackers earlier this year, making its position consistent. Developer Boone Wheeler defended the stance in unambiguous terms.

"A truly permissionless protocol can do nothing when it encounters known stolen funds — it is blind to their provenance," Wheeler said. "If THORChain were able to block specific stolen funds, it would not be permissionless."

Selective intervention

Critics point out that THORChain's idealism has limits of its own. In May, validators voted to halt the chain after an automated system triggered when an attacker exploited a vulnerability and drained more than $10 million from one of its vaults. The protocol's own post-mortem states that it automatically halts activity when solvency checks detect an insolvency event, and that node operators can then deploy broader emergency controls to pause trading, signing and other network activity.

Wheeler maintains there is "firm consensus" among THORChain nodes around permissionlessness, and that "halts are only used when there is an active issue or problem with the protocol." He adds that there is "no functionality to screen individual addresses or transactions" — a deliberate design choice, as the system was "intentionally designed to be truly permissionless."

The distinction, as Wheeler frames it, is between protocol integrity failures and the provenance of funds. Halting to protect solvency is emergency engineering; blocking specific addresses is censorship infrastructure.

NEAR Intents takes the opposite path

NEAR Intents, a cross-chain transaction competitor, intervened directly. Its automated security layer SHIELD identified more than $50 million in attempted flows linked to the Bitget incident, stopped $503,000 during execution, and reported that $166,000 passed through. NEAR also waived its share of Bitget's recovery bounty.

General manager Alex Shevchenko argued that protocol-level permissionlessness does not obligate every application built on top to process every request. "NEAR Protocol is permissionless: anyone can build on it, transact on it, and become a validator," he said. "No one needs permission to hold or transfer assets or deploy contracts on NEAR Protocol. However, that does not mean every application built on NEAR must process every request."

Shevchenko said SHIELD used public on-chain data, signals from an internal anti-money laundering database and third-party intelligence providers listed in the NEAR Intents risk and compliance documentation. He framed the screening as ecosystem-wide protection: "Every major hack drains capital and activity from the onchain economy, so screening for stolen funds and restricting money laundering helps protect the integrity of the wider blockchain economy."

The system is not limited to high-profile incidents. Shevchenko said the AI-based SHIELD also identified the suspicious behavior behind Thursday's $3.8 million Omni deposit/withdrawal exploit and halted activity.

Legal exposure

NEAR Intents' intervention has drawn its own criticism, with detractors arguing the move proves it is neither permissionless nor decentralized — and that exercising control selectively may invite pressure to exercise it more broadly. Crypto lawyer Yuriy Brisov believes the automated nature of SHIELD could keep NEAR Intents within the legal protections afforded to decentralized protocols.

"There is no compliance team, people who sit there and control the operation manually," Brisov said. "This is a smart solution, and that's what we recommend to all the DeFi companies."

Chen, for her part, acknowledged that protocols have "different architectures, governance models and technical capabilities," but drew a line between open infrastructure and "facilitating the movement of known stolen funds." She said Bitget appreciates NEAR Intents' response and will "follow the appropriate legal and recovery process for those assets."

"Permissionless infrastructure does not necessarily mean there can be no mechanisms for detecting and responding to known illicit flows," Chen said. She added that when stolen funds can be reliably identified, ecosystem participants "should cooperate where technically and legally possible" — through tracing and information sharing, declining transactions, freezing assets where infrastructure allows, or supporting recovery via legal and law enforcement channels.

The cost of the line

Joël Valenzuela, head of business and development for Dash and a self-described libertarian cypherpunk, argued that the capacity to intervene is itself the problem. "Permissionless protocols, quite frankly, should not draw the line anywhere when stolen funds are identified, because being able to do so at all makes them permissioned," he said, warning that such capability "opens up Pandora's Box" and "lets all manner of censorship of innocents eventually happen." He placed responsibility elsewhere: "High-level exchanges custodying billions of dollars need to take their security much more seriously. Ultimately, DEXs are the way forward."

Max Shannon, senior research associate at Bitwise Europe, took a more market-structural view. Protocols still in their formative years, like THORChain and NEAR, have yet to earn user trust, and refusing to launder hack proceeds is a "sound stance." He predicts THORChain's posture will shift more money-laundering flows from NEAR Intents toward THORChain — a flow reallocation with direct operational consequences for both platforms.

"Credible neutrality at all costs," Shannon said, remains a cypherpunk ideal championed by a small faction of users and builders. "They rarely ask why it is valuable, when it is valuable, or what it costs. This is the core difference between NEAR Intents and THORChain."

The Bitget recovery process now proceeds through legal and law enforcement channels, and the diverging approaches of the two protocols will test whether automated screening systems like SHIELD can satisfy both regulators and decentralization advocates before the next major exploit forces the question again.

via x.com (Original)

More from Nathan Brooks

Nathan Brooks

Show full bio

Market editor covering business strategy at Mempool Brief.

451 articles