Near Intents blocks $50 million in Bitget hacker swaps, here's what happened

NEAR Intents said its SHIELD system blocked roughly $503,000 and flagged more than $50 million in attempted swaps linked to the Sept. 24 Bitget exchange breach, while about $166,000 of the stolen funds moved through the service. The protocol is holding intercepted assets pending legal and recovery steps, a move that has prompted debate over whether its swap service can still be described as permissionless.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished less than a minute agoUpdated less than a minute ago0 views
Near Intents blocks $50 million in Bitget hacker swaps, here's what happened

Why It Matters

The incident tests how cross-chain swap services balance open access with anti-money-laundering defenses after a major $388 million exchange hack, and highlights friction between different projects’ approaches to censoring or freezing hacker-linked funds.

Key Facts

  • Breach disclosed: Bitget disclosed the wallet security breach on Sept. 24, 2026
  • Total Bitget loss reported: $388 million
  • Amount NEAR Intents flagged in attempted swaps: more than $50 million (estimated, duplicates removed; +/- ~10% margin)
  • Amount NEAR Intents says it blocked mid-swap: about $503,000
  • Amount that passed through NEAR Intents: about $166,000 passed through the service

NEAR Intents reported that its SHIELD monitoring system intercepted and blocked a portion of funds the attackers tried to move after the Bitget exchange disclosed a $388 million wallet breach on Sept. 24. The protocol’s general manager, Alex Shevchenko, said more than $50 million in attempted transfers were identified; duplicate attempts were removed from the tally and the figure is an estimate that could vary by roughly 10%. Shevchenko said SHIELD stopped about $503,000 in the middle of swaps and that roughly $166,000 nevertheless completed through the service. Rejected funds, he added, subsequently shifted to other providers. NEAR Intents is keeping the held assets on hold pending legal and recovery procedures, and has asked Bitget to pursue recovery through legal and law-enforcement channels; the protocol said it would waive its recovery bounty. The intervention contrasts with the stance taken by THORChain, which has declined requests to block attacker addresses and emphasizes its emergency shutdown controls as a protocol-level protection rather than selective freezing. The differing responses have sparked debate about what “permissionless” means for swap services: critics argue that the ability to block or hold transactions undermines neutrality, while supporters say applications built on a permissionless chain can still apply their own controls. NEAR cofounder Illia Polosukhin framed the distinction by noting that permissionless blockchains allow ownership, transfers and contract deployment without permission, but do not force every application or liquidity provider to process every transaction. Independent commentators, including Ramp Labs documentation engineer Vini Barbosa, warned that mechanisms to restrict flows could have unintended consequences for users, including those evading repressive actors. Stablecoin issuers Circle and Tether have separately reported freezing about $320,000 in coins tied to the Bitget breach, and a CoinDesk analysis identified additional completed swaps tied to attacker wallets through other protocols.

Keep Reading