NEAR Intents freezes $503,000 and blocks $50 million in Bitget hack flows
Cross-chain protocol NEAR Intents intercepted more than $50 million in attempted transfers following the $387.5 million Bitget hack, freezing $503,000 mid-execution while waiving its share of the exchange's recovery bounty.

Cross-chain trading protocol NEAR Intents blocked attackers from laundering more than $50 million stolen during the Sept. 24 Bitget hack, according to protocol general manager Alex Shevchenko. While approximately $166,000 passed through, the protocol's SHIELD risk intelligence layer froze roughly $503,000 mid-execution. Shevchenko stated that the frozen assets remain restricted pending legal and recovery proceedings.[3][4][2]
The intervention prompted discussion over the nature of decentralized networks. NEAR co-founder Illia Polosukhin defended the action, arguing that while anyone can deploy contracts or transfer assets on NEAR, applications and liquidity providers are not obligated to process every trade. Shevchenko added that permissionless does not mean neutral, stating that refusing to assist in laundering stolen assets was a deliberate choice. NEAR Intents also confirmed it would waive its share of Bitget's recovery bounty to allow the exchange to recoup more funds.[3][1][7]
Bitget chief executive Gracy Chen praised the response, stating that public blockchains can integrate risk detection without sacrificing openness. Bitget reported that roughly $387.5 million was stolen after attackers breached backend wallet infrastructure, though its User Protection Fund covers the entire loss. In contrast, cross-chain protocol THORChain declined Bitget's request to restrict hacker addresses, maintaining that it does not censor by design. Most of the flows rejected by NEAR Intents subsequently moved through alternative swap providers.[3][5][6]
Key facts
- Attackers from the Sept. 24 Bitget exchange hack attempted to move more than $50 million through NEAR Intents.
- NEAR Intents' SHIELD risk system froze $503,000 mid-execution, while about $166,000 passed through.
- NEAR Intents waived its share of Bitget's recovery bounty so the exchange could recover more stolen assets.
- NEAR co-founder Illia Polosukhin defended the intervention, arguing permissionless does not require apps or liquidity providers to process every transaction.
- Bitget reported $387.5 million in total losses from the wallet infrastructure compromise, with the loss fully covered by its User Protection Fund.
- THORChain rejected Bitget's request to block attacker addresses, stating that it does not censor by design.
- Most of the funds blocked by NEAR Intents subsequently flowed through other swap providers.
Sources · 7 sources
- SO
SolanaFloor@SolanaFloorPost on X ·
🚨JUST IN: @NEARProtocol says it froze $503K from the $387.5M Bitget hack and stopped more than $50M in attempted laundering flows via NEAR Intents “Permissionless doesn’t mean neutral. NEAR Intents is not a place for laundering stolen assets.” https://t.co/CPDndDGFVs
Open source - BS
BSCN@BSCNewsPost on X ·
Near Intents Stops Stolen Bitget Funds in Cross Chain Flows NEAR Intents (@near_intents) detected attempts to move more than $50 million from the Bitget (@bitget) hack. The platform's SHIELD system detected the suspicious activity during execution. Around $503,000 was frozen, while approximately $166,000 passed through. Bitget estimates the September 24 hack caused about $387.5 million in losses. NEAR Intents will waive its share of the recovery bounty.
Open source - UN
UnchainedArticle ·
NEAR Defends Blocking Bitget Hack Funds, Says Permissionless ‘Doesn’t Mean Neutral’ NEAR co-founder Illia Polosukhin defended NEAR Intents’ decision to stop funds tied to the Bitget hack, arguing on Monday that an open blockchain does not require every app built on it to handle every trade. “Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR,” Polosukhin wrote on X. “It does not mean every application or liquidity provider must process every transaction.” His post came hours after Alex Shevchenko , general manager of NEAR Intents , the network’s cross-chain trading protocol, disclosed that attackers tried to push more than $50 million of stolen funds through NEAR Intents. About $166,000 got through, and $503,000 was frozen partway through execution, Shevchenko said. Those funds “remain restricted pending the appropriate legal and recovery process,” he added. Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter . How SHIELD Works The blocking came from SHIELD , a risk-intelligence layer that Shevchenko said combines transaction-monitoring data, outside researchers and input from large centralized players to spot suspicious flows. When it ties a trade to a hack, the protocol either declines to quote it or halts it if execution has already begun. “Permissionless doesn’t mean neutral,” Shevchenko wrote in his post. “The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours.” NEAR Intents also said it would give up its share of the bounty Bitget has offered for frozen funds, so the exchange can recover more. A Different Answer From THORChain Bitget CEO Gracy Chen thanked the NEAR Intents team on Monday. “A public chain doesn’t have to choose between being open and excluding hackers, you can build the risk detection in and still let anyone use the chain,” she wrote. THORChain, another cross-chain protocol, has taken the opposite position. On Monday it again turned down Bitget’s request to block the attacker’s addresses, saying it “doesn’t censor by design.” Not everyone welcomed NEAR’s approach. A pseudonymous X user, loracle, argued that NEAR runs on a trusted execution environment its team controls, and that it can “seize funds just like a CEX” and request KYC at its discretion. Bitget has said attackers took about $387.5 million on Sept. 24 after compromising a backend system in its wallet infrastructure. The exchange says its User Protection Fund covers the full loss. Related Listen: Uneasy Money: How the Resolv Hack Shows an Audit Doesn’t Mean ‘Secure’ The post NEAR Defends Blocking Bitget Hack Funds, Says Permissionless ‘Doesn’t Mean Neutral’ appeared first on Unchained .
Open source - WB
Wu Blockchain@WuBlockchainPost on X ·
NEAR Intents Blocks Over $50M in Bitget Hack Flows and Waives Recovery Bounty Share Aurora co-founder Alex Shevchenko said attackers behind the September 24 Bitget hack attempted to move more than $50 million in stolen funds through NEAR Intents. Its SHIELD risk system detected the flows, with about $166,000 passing through and roughly $503,000 frozen mid-execution pending legal and recovery procedures. Shevchenko said about $387.5 million was stolen in total, with most cross-chain funds ultimately consolidated into ETH on Ethereum. Bitget CEO Gracy Chen said NEAR Intents has waived its share of the recovery bounty to allow Bitget to recover more of the stolen funds. She added that public blockchains do not have to choose between openness and restricting known stolen funds, arguing that risk-detection mechanisms can be built in while keeping access permissionless. Bitget will proceed through the appropriate legal and asset-recovery process.
Open source - CO
CoindeskArticle ·
Near Intents blocks $50 million in Bitget hacker swaps, here's what happened The swap service identified more than $50 million in attempted transfers, although most rejected funds subsequently moved through other providers.
Open source - CT
Coin TelegraphArticle ·
NEAR Intents says it blocked $50M tied to Bitget hackers The cross-chain protocol said it actively prevents stolen funds from being laundered, drawing a contrast with THORChain’s position that it does not selectively censor transactions.
Open source - CO
CoinMarketCap@CoinMarketCapPost on X ·
ICYMI: 🚨 NEAR Intents blocked over $50M in attempted transfers tied to the $387.5M Bitget hack, froze $503K, and waived its recovery bounty so Bitget can recover more. https://t.co/lPHk0Ar75z
Open source

