NEAR Intents Blocks $50M in Bitget Hack Transfers, Testing NEAR (NEAR)'s Open-Access Promise
NEAR Intents blocked over $50M in Bitget hack transfer attempts, freezing $503K, as the NEAR (NEAR) ecosystem debates its permissionless promise.
AI SummaryAI
- NEAR Intents blocked over $50 million in attempted transfers linked to the $388 million Bitget hack.
- The SHIELD system froze $503,000 mid-transaction while about $166,000 in suspect funds passed through.
- Circle and Tether blacklisted an attacker-linked wallet, freezing $318,013 in USDT and USDC.
- NEAR Intents general manager Alex Shevchenko said the service will waive Bitget's 5% freeze and recovery bounties.
SHIELD Halts $50M in Hacker Swaps
Attackers behind the $388 million Bitget breach attempted to push more than $50 million through NEAR Intents, the cross-chain swap service built on the NEAR Protocol, and most of it never cleared the rails. In an official post, NEAR Intents general manager Alex Shevchenko laid out the numbers: the protocol's SHIELD screening system intercepted the bulk of the flows and froze $503,000 mid-execution, while roughly $166,000 in suspected stolen funds slipped through. SHIELD works by spotting deviations in normal flow patterns — it pools signals from KYT vendors, blockchain-intelligence firms, independent researchers and the largest centralized industry players, then decides transaction-by-transaction how to proceed. The $50 million tally counts attempted transfers rather than recovered money; once duplicate attempts were stripped out, the rejected funds simply migrated to other providers. Shevchenko flagged that the estimates could be off by up to roughly 10% in either direction, and noted the slice was negligible against the service's routine throughput of more than $100 million in daily cross-chain trading volume. A significant share of the stolen treasury had already jumped chains toward Ethereum. The confrontation is a live test for a platform that brands itself permissionless, open and uncensorable: its security documentation states that swap requests are screened for links to reported hacks and can be delayed when flagged — controls that bind the swap interface itself, not every wallet on the layer-1 chain. The underlying breach, disclosed by Bitget on Sept. 24 after attackers bypassed security controls protecting its exchange wallets, has since set off a wider containment race, with the exchange publishing attacker addresses and dangling bounties for freezes and recoveries.
Permissionless Label Under Fire
The freeze immediately turned NEAR Intents' self-description into the story's sharpest battleground, and with it the standing of the wider NEAR Protocol ecosystem. Vini Barbosa, a documentation engineer building at Ramp Labs, argued on X that “permissionless does mean neutral” — a label, in his view, that a service able to hold user funds can no longer claim — and warned that blocking supposedly unlawful users could one day ensnare people resisting government repression. He still credited the product with a genuine niche for the vast majority of users. NEAR cofounder Illia Polosukhin countered that the term was being stretched: nobody needs permission to own assets, move them or deploy contracts on NEAR, he wrote, but no application or liquidity provider is obliged to process every transaction that arrives. The position inverts THORChain's — the other cross-chain venue in the spotlight after Bitget CEO Gracy Chen publicly asked it to refuse attacker-linked addresses. THORChain has refused selective freezes, saying its past emergency shutdowns were broad security mechanisms, not targeted holds on specific swaps or individuals. Shevchenko defended his protocol's choice in blunt terms: refusing to help launder stolen assets is a deliberate design decision, and a system guaranteeing thieves an unrestricted right to monetize stolen property “cannot become the economic backbone of the future.” Practically, NEAR Intents will forgo Bitget's 5% freeze bounty and 5% recovery bounty so more value flows back to the exchange, with the frozen $503,000 returned through an appropriate legal process — though the post-mortem did not say who can authorize that release or how a wrongly flagged user reclaims funds. “Permissionless infrastructure, but with boundaries” was how Shevchenko framed the path forward.
On-Chain Trail Sets the Standard
The through-line is a protocol choosing enforcement over neutrality, and the primary evidence backs the claim: on-chain data confirms the blacklisted exploiter wallet and the stablecoins frozen around it — $318,013 in USDT and USDC, per issuer actions on Friday. Root cause sits exchange-side, with Bitget saying it patched the third-party vulnerability behind the breach, while remediation now spans issuer blacklists, SHIELD screening and bounty programs — a layered defense traders should weigh when picking among the best crypto exchanges. The episode lands as Bitwise's NEAR (NEAR) spot ETF gears up for its NYSE Arca debut and as spot NEAR shed 8.1% over the past 24 hours, with earlier on-chain tracking flagging $25.9 million in unrealized losses on whale shorts — a reminder that compliance posture and market confidence now move together.
Related Tags

AI-generated, AI-reviewed, under COINOTAG editorial oversight.


