Furious debate about THORChain vs NEAR shows idealism has limits
After a Sept. 24 hack of Bitget that sent about $387.5–$387.7 million of stolen funds across chains, some flows were routed toward THORChain while others hit NEAR Intents. THORChain declined requests to block attacker-linked addresses, citing a design commitment to permissionless operations, while NEAR’s automated SHIELD system intervened and prevented a portion of suspicious transfers.

Why It Matters
The dispute highlights a core tension in blockchain design: whether protocols should remain strictly permissionless even when they can identify illicit flows, or build automated controls that block thefts and protect broader ecosystem integrity. The outcome could shape governance and technical choices across cross-chain infrastructure.
Key Facts
- Date of Bitget hack: Sept. 24 (year not specified in excerpt)
- Amount of stolen funds moving across chains: $387.5–$387.7 million
- THORChain response: Refused to block attacker-linked addresses; cited permissionless design
- NEAR Intents response: Used SHIELD to block flows, stopping $503,000 during execution and identifying over $50 million in attempted linked flows; $166,000 passed through
- Bybit-related prior routing through THORChain: $1.2 billion previously funneled through the protocol (as reported)
When Bitget was hacked on Sept. 24, hundreds of millions in stolen assets began moving between blockchains, prompting an unusual public clash over how cross‑chain infrastructure should respond. Bitget’s CEO publicly urged THORChain to refuse service to addresses linked to the attack, but THORChain declined, saying it has no mechanism to screen or block specific transactions and that doing so would violate its commitment to being truly permissionless.
THORChain developers and node operators argue their architecture intentionally lacks address‑screening functionality; they say emergency halts are only used for protocol solvency or safety issues, not to police the provenance of funds. Critics point to a prior May incident where THORChain halted the network after an exploit drained over $10 million from a vault, suggesting the protocol has shown it can intervene when operators agree it is necessary.
NEAR Intents took the opposite path in this incident. Its SHIELD automated security layer used on‑chain data and third‑party risk signals to identify more than $50 million in flows tied to the Bitget breach, blocking $503,000 in‑flight and allowing about $166,000 to pass. NEAR’s general manager framed this approach as consistent with permissionless participation at the protocol level while allowing individual applications to apply targeted controls; NEAR also waived its share of Bitget’s recovery bounty.
The episode has sharpened questions about boundaries for permissionlessness. Advocates for intervention emphasize ecosystem protection and automated controls that can limit laundering and reduce damage from hacks. Defenders of strict permissionlessness warn that adding provenance filters or manual controls could undermine censorship resistance and alter governance expectations. With major cross‑chain platforms taking opposite approaches, the industry is wrestling with tradeoffs between idealized decentralization and practical measures to stem illicit flows.
Keep Reading
‘Euro stablecoin isn’t enough’: EU issuers make case for USD tokens

Bitcoin briefly hits $87K as weak US jobs data sends bond yields lower

Crypto’s billions are back, but the premiums aren’t

71% of UK finance leaders expect tokenization to reshape financial services: Lloyds
Original source: Cointelegraph