What to Know
- NEAR Intents said it stopped about $503,000 linked to Bitget’s $388 million hack during attempted cryptocurrency swaps.
- The platform identified more than $50 million in attempted transfers connected to the attacker, though most rejected funds later moved through other providers.
- About $166,000 passed through NEAR Intents before restrictions took effect, according to figures shared by the platform.
- The estimated figures could differ from actual amounts by up to roughly 10%.
- Bitget disclosed the breach on Sept. 24 after attackers bypassed security controls protecting exchange wallets.
- Circle and Tether have already frozen about $320,000 in stablecoins linked to the breach.
- The incident has intensified debate over whether a swap service that can restrict suspicious transactions should call itself permissionless.
- NEAR Intents said the restricted funds will remain on hold pending legal and recovery proceedings.
NEAR Intents Intervenes in Bitget Hacker-Linked Swaps
NEAR Intents has become a central focus in the crypto industry’s latest debate over censorship resistance, compliance, and the practical meaning of permissionless infrastructure after blocking attempted swaps tied to the Bitget exchange hack. The swap platform said it identified more than $50 million in attempted transfers connected to the attacker, while freezing about $503,000 in funds that were already moving through the service.
The incident followed Bitget’s disclosure of a $388 million breach after attackers bypassed protections around the exchange’s wallets. In the aftermath, attacker-linked addresses were published, recovery efforts began, and infrastructure providers across the market faced renewed pressure to decide whether they should block, flag, freeze, or process transactions associated with stolen funds.
NEAR Intents, which facilitates cross-chain asset exchanges, says its SHIELD system detected suspicious flows and restricted most of the attempted activity. The platform said about $166,000 still passed through the service, while the frozen amount remains subject to legal and recovery proceedings. The larger attempted-transfer figure does not represent recovered funds, but rather the value of attempted swap activity linked to the attacker.
Why the Figures Matter
The distinction between attempted flows, frozen funds, and completed swaps is important. The more than $50 million figure reflects attempted transfers that were identified by the service, not an amount seized or recovered. NEAR Intents said duplicate attempts were removed from the tally, and that rejected funds subsequently moved through other providers. The figures were also described as estimates that could differ from actual amounts by up to roughly 10%.
That means the intervention was meaningful but limited in scope. The platform did not absorb or recover the full attempted amount, and the attacker-linked funds appeared to continue seeking alternate routes after being rejected. This pattern highlights one of the persistent challenges in crypto incident response: blocking one venue can disrupt laundering activity, but it does not necessarily stop funds from moving across the wider ecosystem.
Cross-chain swap services are especially sensitive in these moments because they often sit at the intersection of liquidity, speed, and blockchain fragmentation. Attackers may attempt to convert stolen assets into other tokens or move value across networks in order to make tracing and recovery more difficult. Services that can detect and delay suspicious activity may provide a friction point, but their actions also raise difficult questions about neutrality and user control.
The SHIELD System and Transaction Screening
NEAR Intents said its SHIELD system automatically detects deviations in flows and gathers inputs from know-your-transaction providers, intelligence providers, independent researchers, companies, and major centralized industry participants. Based on those signals, the protocol can decide how to handle a transaction when a swap request appears connected to illicit activity.
The platform’s documentation indicates that swap requests can be checked for links to reported hacks and that suspicious transactions can be delayed. These checks apply to use of the swap service itself and do not give the operators control over every wallet on the NEAR blockchain. That distinction is central to the platform’s defense: users may still hold assets and deploy contracts on the underlying network, but applications and liquidity providers may impose risk controls on their own services.
For many market participants, the intervention demonstrates how crypto infrastructure is evolving. A service can advertise open access while still implementing controls designed to prevent laundering of hacked funds. For others, the ability to stop or hold funds cuts against the core promise of permissionless finance, especially if the process for reviewing false positives or releasing restricted assets is not fully transparent.
Permissionless Infrastructure Faces a Real-World Test
The strongest criticism centers on the word permissionless. In crypto, permissionless commonly means that users do not need approval from a central operator to access a network, move assets, or deploy software. Yet in application-layer services, the meaning can become less clear. If an interface, liquidity provider, or swap mechanism can reject transactions, some users argue that the service is not fully neutral in practice.
That criticism gained traction after NEAR Intents restricted the Bitget hacker-linked swaps. Some critics argued that permissionless systems are supposed to remain neutral, and that restrictions on supposedly unlawful users could create risks for people operating under political pressure or government repression. The concern is not necessarily that stolen funds should move freely, but that discretionary blocking mechanisms can expand beyond clearly illicit activity if governance and accountability are weak.
NEAR’s position is different. The argument from its side is that permissionless ownership and transfer on a blockchain do not require every business, application, or liquidity provider to process every transaction. In that framing, the base network can remain open while individual services set boundaries against laundering, fraud, and hacked funds. The debate is likely to persist because both positions appeal to foundational crypto principles: censorship resistance on one side and ecosystem integrity on the other.
Contrast With THORChain
The NEAR Intents response stands in contrast to THORChain, which has resisted requests to block attacker addresses. THORChain has defended its model as one where anyone can use the network, while emergency controls are designed to protect the protocol rather than selectively freeze funds. That difference has made the Bitget hack a live comparison between two philosophies of decentralized infrastructure.
In one model, infrastructure tries to remain as neutral as possible, even when illicit actors use it. In another, services incorporate detection systems and transaction restrictions to limit the movement of stolen assets. Neither approach eliminates risk. Strict neutrality may allow hackers to move value more freely, while active screening can introduce questions about who makes decisions, how accurate those decisions are, and what recourse exists for legitimate users.
Market participants are watching these choices closely because liquidity networks, bridges, and swap protocols are often judged not only by speed and cost, but also by trust assumptions. Users increasingly want to know whether a protocol can halt flows, under what circumstances that might happen, and whether there is a clear path to appeal if a transaction is wrongly flagged.
Recovery Process Leaves Open Questions
NEAR Intents said the restricted funds will remain on hold pending legal and recovery proceedings, and Bitget was asked to contact the service through legal and law-enforcement channels. The platform also said it would waive its recovery bounty. However, important procedural details remain unclear, including who can authorize release of the funds and how a wrongly flagged user could recover money if caught by the screening process.
Those unanswered questions matter because transaction screening systems are not only judged by their success against attackers. They are also judged by their safeguards for ordinary users. False positives can happen in any compliance process, and crypto users tend to be particularly sensitive to opaque controls. A transparent process for review, evidence, authorization, and appeal could become an important part of how swap services defend their legitimacy.
The Bitget breach has already drawn responses from stablecoin issuers, with Circle and Tether freezing about $320,000 in stablecoins linked to the incident. Their role is more familiar to many market observers because centralized issuers can freeze tokens under certain conditions. The more novel and contentious issue is how far decentralized or semi-decentralized swap services should go when attacker-linked assets attempt to move through liquidity routes.
A Defining Moment for Cross-Chain Compliance
The Bitget-linked activity has turned NEAR Intents into a case study for the next phase of crypto infrastructure. As cross-chain trading grows, swap services may increasingly face pressure from exchanges, investigators, and users to detect stolen funds before they disappear into deeper liquidity. At the same time, these services must preserve the open-access qualities that made decentralized finance attractive in the first place.
The outcome is unlikely to produce a simple industry consensus. Some chart watchers and protocol observers may view NEAR Intents’ decision as a necessary defense against laundering. Others may see it as evidence that claims of being permissionless require sharper definitions. What is clear is that language matters: open, uncensorable, permissionless, and compliant do not always mean the same thing, especially when a major hack forces theory into practice.
For now, NEAR Intents has drawn a boundary. It says the infrastructure remains permissionless, but not without limits when hacked funds are detected. Whether that framing satisfies users, developers, exchanges, and regulators may depend on what happens next in the recovery process and whether the service provides more clarity around control, release authority, and user recourse.
Frequently Asked Questions (FAQs)
What did NEAR Intents do after the Bitget hack?
NEAR Intents said it identified more than $50 million in attempted transfers linked to the Bitget attacker and froze about $503,000 that was moving through the swap service.
How much money passed through NEAR Intents?
About $166,000 passed through the service, while a larger amount of attempted activity was rejected or blocked by its transaction-screening system.
Was the full attempted amount recovered?
No. The more than $50 million figure refers to attempted transfers, not recovered funds. NEAR Intents said rejected funds later moved through other providers.
What was the size of the Bitget hack?
Bitget disclosed a $388 million breach after attackers bypassed security controls protecting its exchange wallets.
What is the controversy around permissionless infrastructure?
The controversy is whether a service that can restrict, delay, or hold transactions should describe itself as permissionless, especially if users do not have a clearly explained appeal process.
Does NEAR Intents control all wallets on NEAR?
No. The transaction checks apply to use of the NEAR Intents swap service and do not give its operators control over every wallet on the NEAR blockchain.
How does this differ from THORChain’s approach?
THORChain has resisted selectively blocking attacker addresses, while NEAR Intents used its screening system to restrict Bitget hacker-linked swap activity.
What happens to the frozen funds now?
NEAR Intents said the restricted funds will remain on hold pending legal and recovery proceedings, though questions remain about who can authorize release and how wrongly flagged users can recover funds.
