
NEAR Intents detected more than $50 million in attempted transfers tied to the Bitget hack, although most of the rejected funds were later routed through other swap providers.
The cross-chain swap platform describes itself as permissionless, open and uncensorable. However, it blocked transactions after attackers attempted to move stolen Bitget funds through its infrastructure.
Alex Shevchenko, general manager of NEAR Intents, said the group responsible for the $388 million Bitget breach attempted to transfer more than $50 million through the service. NEAR Intents allows users to exchange assets across multiple blockchain networks.
Its SHIELD system stopped most of the attempted transfers and froze $503,000 during the transaction process. The move contrasts with THORChain, which has resisted Bitget’s request to block addresses associated with the attackers.
Around $166,000 successfully moved through NEAR Intents, while the restricted funds remain subject to legal and recovery procedures, Shevchenko said. He stressed that the $50 million-plus figure represents attempted transfers rather than the amount ultimately recovered.
According to Shevchenko, duplicate transactions were removed from the tally, while funds rejected by NEAR Intents were later sent through other providers. He added that the figures are estimates and may differ from the actual amounts by roughly 10%.
NEAR Intents normally processes more than $100 million in cross-chain trading volume each day, Shevchenko said. In comparison, only a small portion of the funds stolen from Bitget passed through the service.
He said the SHIELD system enabled the intervention by identifying unusual transaction patterns and gathering information from KYT and intelligence providers, independent researchers, companies and major centralized crypto platforms. The combined signals are used to determine how a transaction should be processed.
The episode highlights the distinction between permissionless infrastructure and individual applications operating on a blockchain. Being open to users does not necessarily require a service to process transactions associated with suspected stolen funds.
NEAR Intents’ Response to the Bitget Hack
Bitget disclosed the breach on Sept. 24 after attackers bypassed security controls protecting the exchange’s wallets. The company later said it had fixed the vulnerability, published addresses associated with the attackers and offered bounties for qualifying efforts to freeze or recover the stolen assets.
Circle and Tether, the issuers of USDC and USDT, have already frozen about $320,000 in stablecoins linked to the breach, according to CoinDesk.
NEAR Intents documentation says its swap service screens transactions for connections to reported hacks and can delay suspicious transfers. These checks apply to transactions conducted through the service and do not give NEAR Intents control over every wallet operating on the NEAR blockchain.
The ability to intercept or hold funds has nevertheless raised questions about the platform’s use of the term “permissionless.”
Debate Over Permissionless Infrastructure
The intervention led to an online debate over whether a service that can restrict transactions should describe itself as permissionless.
Vini Barbosa, a technical writer and documentation engineer at Ramp Labs, questioned the distinction on X. He argued that permissionless systems should remain neutral while acknowledging that NEAR Intents has a useful role. He also warned that restrictions intended to block unlawful activity could potentially affect users in situations involving government repression.
NEAR co-founder Illia Polosukhin offered a different interpretation. He said permissionless infrastructure allows anyone to own and transfer assets or deploy contracts on NEAR without authorization. However, he added that individual applications and liquidity providers are not required to process every transaction.
This approach differs from THORChain, which has defended its decision to allow transactions through its network and said its emergency shutdown mechanisms are intended to protect the protocol rather than selectively freeze individual funds.
A CoinDesk analysis on Monday identified about $6.3 million in completed ether-to-bitcoin swaps originating from a wallet linked to the Bitget attacker.
NEAR Intents is holding the intercepted funds while legal and recovery procedures continue. Shevchenko asked Bitget to contact the service through legal and law-enforcement channels and said NEAR Intents would waive its recovery bounty.
His report did not specify who can authorize the release of the frozen funds or explain what procedure would apply if legitimate funds were incorrectly flagged.
Shevchenko said NEAR Intents would continue operating as permissionless infrastructure while maintaining safeguards designed to prevent hacked funds from being laundered.






