THORChain and NEAR Intents split over blocking Bitget hack funds

Editorial illustration: Blue and gold faceted tokens occupy a branching dark channel. One branch has a raised metal gate, while tokens cluster before a closed gate on the other branch.

In brief

  • Bitget was hacked Sept. 24; Cointelegraph cites both $387.5 million and $387.7 million in losses.
  • THORChain refused Bitget CEO Gracy Chen's request to deny service to attacker-linked addresses.
  • NEAR Intents' SHIELD layer stopped $503,000 and let $166,000 through, NEAR said.
  • Critics say NEAR's intervention and THORChain's May halt each undercut their own permissionless claims.

Two protocols, two answers

Bitget was hacked on Sept. 24, and $387.5 million of stolen funds quickly began moving across chains, Cointelegraph reported (the same piece puts the figure at $387.7 million in its lead, so the exact number isn't settled). Some of it headed to THORChain, a cross-chain swap platform. Chen publicly appealed to the protocol to refuse service to attacker-linked addresses.

“The industry is watching,” she said.

THORChain refused.

NEAR Intents went the other way. Its automated security layer, SHIELD, identified more than $50 million in attempted flows linked to the incident and stopped $503,000 during execution, according to NEAR as reported by Cointelegraph. It said $166,000 passed through. NEAR also waived its share of Bitget's recovery bounty.

Chen told the magazine there's an important distinction between permissionless infrastructure and facilitating the movement of known stolen funds. She said Bitget wants to understand what's technically and governance-wise possible when stolen assets are identified.

THORChain's case

THORChain developer Boone Wheeler told Cointelegraph Magazine there's firm consensus among the protocol's nodes around being permissionless, and that halts are used only when the protocol has an active issue. He said there's no functionality to screen individual addresses or transactions. That's deliberate, in his telling.

Critics aren't convinced. They point out that THORChain validators voted to halt the chain in May, after an automated system triggered when an attacker exploited a vulnerability and drained over $10 million from a vault. THORChain's post-mortem of that exploit said the protocol automatically halts when solvency checks detect an insolvency event, and node operators can then use emergency controls to pause trading, signing and other network activity. The magazine also noted that the Bybit hackers had previously moved $1.2 billion through THORChain.

NEAR takes heat too

Intervening didn't win NEAR Intents universal praise. Critics argued it shows the platform isn't permissionless or decentralized. Crypto lawyer Yuriy Brisov said that because SHIELD is automated, it could still fall within the protections given to decentralized protocols.

Cointelegraph framed the whole episode as a test of whether ideals around permissionless, decentralized tech mean never intervening, even when a protocol could.

Frequently asked questions

Why did THORChain refuse to block the Bitget hacker's addresses?

THORChain developer Boone Wheeler told Cointelegraph Magazine there's firm consensus among its nodes around being permissionless, and halts are used only when the protocol has an active issue. He said THORChain has no functionality to screen individual addresses or transactions, which he described as a deliberate design choice.

How did NEAR Intents stop funds from the Bitget hack?

NEAR Intents' automated security layer, SHIELD, identified more than $50 million in attempted flows linked to the Bitget incident and stopped $503,000 during execution, NEAR said, as reported by Cointelegraph. It said $166,000 passed through. NEAR also waived its share of Bitget's recovery bounty.

Why are critics questioning both THORChain and NEAR?

Critics say NEAR Intents' intervention shows it isn't permissionless or decentralized. Others point to THORChain validators voting to halt the chain in May after an attacker drained over $10 million from a vault. Lawyer Yuriy Brisov said SHIELD's automation could keep it within protections for decentralized protocols.