NEAR Intents says it blocked most of $50M in Bitget hacker swap attempts
In brief
- Bitget attackers tried moving over $50 million through NEAR Intents, per GM Alex Shevchenko's report.
- SHIELD froze $503,000 mid-transaction; about $166,000 passed through, Shevchenko said.
- $50 million figure counts attempted transfers, not recovered funds; rejected funds moved to other providers.
- Vini Barbosa and NEAR cofounder Illia Polosukhin disagreed on X over the 'permissionless' label.
What SHIELD caught
Shevchenko's report says the protocol's SHIELD system blocked most transfers and froze $503,000 partway through a transaction. About $166,000 got through. The frozen funds are waiting on a legal and recovery process, he said. Shevchenko asked Bitget to contact the service through legal and law-enforcement channels and said NEAR Intents would waive its recovery bounty. His report didn't name who can authorize the money's release or explain how someone wrongly flagged could get their funds back, CoinDesk noted.
The $50 million isn't money recovered. It counts attempted transfers (Shevchenko said duplicate attempts were removed from the tally), and the rejected funds subsequently went to other providers. He also called the figures estimates that could be off by roughly 10%.
Shevchenko said NEAR Intents routinely processes more than $100 million in cross-chain trading volume a day, and only a negligible fraction of the hacked funds flowed through it.
"The reason for this behaviour is SHIELD. It automatically detects deviations in flows, collects numerous inputs from KYT and intelligence providers, independent researches, companies and largest centralised players in the industry."
According to NEAR Intents documentation, as cited by CoinDesk, the service checks swap requests for links to reported hacks and can delay suspicious transactions. Those checks only apply when someone uses the swap service, and they don't give operators control over every wallet on the NEAR blockchain.
The 'permissionless' argument
That's where the debate started.
Critics online questioned whether a service that can hold funds should call itself permissionless. Vini Barbosa, a technical writer and documentation engineer building at Ramp Labs, was among them. Barbosa argued on X that permissionless should mean neutral. He warned that restrictions on supposedly unlawful users could also affect people resisting government repression, while saying the product "is valuable for the vast majority of users."
NEAR cofounder Illia Polosukhin took the opposite view on X. He said permissionless means nobody needs permission to own and transfer assets or deploy contracts on NEAR, and it doesn't mean every application or liquidity provider must process every transaction.
THORChain went another way. It resisted Bitget's request to block attacker addresses, saying its emergency shutdown controls protect the protocol rather than selectively freezing funds.
Where the Bitget case stands
Bitget disclosed the breach on Sept. 24 after attackers got past security controls protecting its exchange wallets, CoinDesk reported. The exchange says it's fixed the vulnerability, published attacker addresses and offered bounties for efforts to freeze or recover funds.
Circle and Tether, the issuers of USDC and USDT, have frozen about $320,000 in stablecoins linked to the breach, according to CoinDesk. A separate CoinDesk analysis found about $6.3 million in completed ether-to-bitcoin swaps from a single wallet tied to the Bitget attacker.
Frequently asked questions
Did NEAR Intents recover $50 million from the Bitget hackers?
No. The $50 million figure counts attempted transfers, not money recovered. NEAR Intents GM Alex Shevchenko said SHIELD froze $503,000 midway through a transaction, about $166,000 went through, and rejected funds later moved through other providers. He said the figures are estimates that could be off by roughly 10%.
Why are critics questioning whether NEAR Intents is permissionless?
Critics online asked whether a service that can hold funds should call itself permissionless. Vini Barbosa of Ramp Labs argued on X that permissionless should mean neutral, warning that restrictions could also affect people resisting government repression. NEAR cofounder Illia Polosukhin said on X that letting people hold and transfer assets on a blockchain doesn't oblige every business built on it to handle their money.


