NEAR Intents' SHIELD Stopped $503,000 in Bitget Hack Flows
NEAR Intents' SHIELD stopped $503,000 of $50M-plus attempted Bitget hack flows, while THORChain refused to block stolen funds from the Sept. 24 breach.
AI SummaryAI
- SHIELD identified over $50 million in attempted flows tied to the Bitget incident.
- THORChain refused Bitget CEO Gracy Chen's public appeal to block attacker-linked addresses.
- $166,000 in Bitget-linked funds passed through NEAR Intents before detection.
- SHIELD halted activity during the $3.8 million Omni exploit on Oct. 1.
SHIELD Stops $503,000 in Hack Flows
The screening applied to the Bitget hack runs through a single venue:
NEAR Protocol (NEAR) Intents, the NEAR Protocol's cross-chain transaction service, and its automated security layer SHIELD. Bitget lost $387.5 million on Sept. 24, and the stolen funds began moving across chains, with part of the flow routed toward THORChain, a decentralized cross-chain bridge protocol for asset swaps. Bitget CEO Gracy Chen appealed publicly to THORChain to refuse service to attacker-linked addresses, writing that “the industry is watching.” THORChain declined. NEAR Intents took the opposite approach: SHIELD identified more than $50 million in attempted flows tied to the incident, stopped $503,000 during execution, and let $166,000 pass through before detection, per figures the NEAR Intents team released. NEAR also waived its share of Bitget's recovery bounty, and Chen said the exchange “appreciates that response and will follow the appropriate legal and recovery process for those assets.” The blocked Bitget hack transfers put two models to the test at once. The episode raises a question that goes beyond the NEAR price: whether a Layer 1 blockchain protocol and the applications built on it owe any duty to intercept stolen funds. General manager Alex Shevchenko said SHIELD draws on public on-chain data, an internal anti-money laundering database and third-party intelligence providers, and the controls stop at the flows the service supports, a boundary the team states rather than implies. Critics have since attacked the intervention itself, arguing it proves
NEAR Protocol (NEAR) Intents is neither permissionless nor decentralized and may invite demands that it exercise that control more broadly. Shevchenko framed the position NEAR defends: “NEAR Protocol is permissionless: anyone can build on it, transact on it, and become a validator... No one needs permission to hold or transfer assets or deploy contracts on NEAR Protocol. However, that does not mean every application built on NEAR must process every request.”
THORChain's refusal is a stated design position, not an oversight. Developer Boone Wheeler argues that a truly permissionless protocol can do nothing when it encounters known stolen funds because it is blind to their provenance, and that if THORChain could block specific funds it would not be permissionless. He described “firm consensus” among the protocol's nodes around that ideal and said there is “no functionality to screen individual addresses or transactions.” The chain has intervened before, though. In May, validators voted to halt the network after an attacker exploited a vulnerability and drained more than $10 million from one of its vaults, and THORChain's own post-mortem of that incident describes automatic halts when solvency checks detect an insolvency event, with node operators able to extend emergency controls to pause trading and signing. Wheeler said halts are reserved for active problems with the protocol itself. The precedent runs long: the Bybit hackers had already funneled $1.2 billion through the protocol. Crypto lawyer Yuriy Brisov argued that SHIELD's automation may keep
NEAR Protocol (NEAR) Intents within the protections afforded to decentralized protocols, since there is no compliance team controlling operations manually. Dash's Joël Valenzuela countered that permissionless protocols “should not draw the line anywhere” when stolen funds are identified, because the ability to block at all makes them permissioned and eventually invites censorship of innocents; in his view, exchanges custodying billions should harden their own security instead. Chen, for her part, distinguished permissionless infrastructure from “facilitating the movement of known stolen funds,” and said participants should cooperate where technically and legally possible, through tracing, declining transactions or supporting recovery through legal processes. Max Shannon, senior research associate at Bitwise Europe, the firm behind the first US spot NEAR ETF, called refusing to launder hack proceeds a “sound stance” for protocols still earning trust, adding that “credible neutrality at all costs” remains a cypherpunk ideal for a small faction of builders, one that rarely asks why it is valuable or what it costs.
Where NEAR's Screening Stops
SHIELD's screening is not confined to the Bitget case. The layer flagged the behavior behind the $3.8 million Omni deposit/withdrawal interaction exploit on Oct. 1 and halted activity, pausing NEAR cross-chain swaps while checks ran, as covered in our NEAR Intents exploit report. The same bounds apply: the system stops at the flows it supports. What the sources leave open is destination, not capability. Shannon's reading is that laundering flows will likely shift from NEAR Intents to THORChain, where no screening exists, and nothing in the record yet bounds where the remaining Bitget proceeds settle. NEAR enters that contest with visibility, fresh off a 100%-plus September rally and a listed US ETF, so its screening model will be studied across the altcoin sector.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

