NEAR Intents Blocks $50 Million in Stolen Bitget Funds, Testing 'Permissionless' Claims
Stolen funds halted during cross-chain swaps
Crypto swap platform NEAR Intents intercepted more than $50 million in attempted transfers linked to a recent hack on the Bitget exchange. While the service describes itself as "permissionless" and "uncensorable," it blocked most of these transactions using an automated detection system.
The incident follows a breach where attackers stole $388 million from Bitget, an online cryptocurrency exchange. Although NEAR Intents stopped the majority of the flow, some funds still managed to pass through the protocol before being flagged.
Numbers behind the intervention
- Total attempted transfers linked to the hack exceeded $50 million.
- Approximately $503,000 was frozen mid-transaction by the protocol's "SHIELD" system.
- About $166,000 successfully passed through the service before being detected.
- These figures are estimates and may vary by up to 10%.
- Duplicate attempts were removed from the final count.
How the SHIELD system works
According to Alex Shevchenko, general manager of NEAR Intents, the "SHIELD" system automatically identifies unusual patterns in transaction flows. It gathers data from various sources, including Know Your Transaction (KYT) providers, independent researchers, and major centralized industry players. Based on these signals, the protocol decides whether to allow or block a specific transaction.
This approach differs from other platforms like THORChain, which has previously refused to block addresses associated with attackers. Shevchenko noted that while NEAR Intents handles over $100 million in daily cross-chain volume, the hacked funds represented only a tiny fraction of its total traffic.
Status of the frozen assets
The restricted funds remain on hold while legal and recovery proceedings take place. However, NEAR Intents has not yet clarified who has the authority to release these funds or how users who were incorrectly flagged can recover their money.
Shevchenko mentioned that rejected funds were subsequently routed to other service providers. The larger figure of $50 million represents attempted transfers rather than money permanently recovered or seized.
Debate over decentralization
The event has sparked discussion regarding whether NEAR Intents can truly be called "permissionless." Critics argue that blocking transactions based on external intelligence contradicts the principle of an open, uncensorable network. Supporters suggest that preventing malicious actors from moving stolen assets is a necessary function for the health of the ecosystem.
What comes next
Bitget disclosed the breach on September 24 after attackers bypassed security controls. The exchange has since fixed the vulnerability, published the attacker addresses, and offered bounties for efforts to freeze the stolen assets. The outcome of the legal process regarding the funds held by NEAR Intents remains pending.