NEAR Intents flagged more than $50 million in attempted transfers linked to the Bitget hack, although most of the funds rejected by the platform later moved through other swap services.
The cross-chain exchange platform describes its infrastructure as permissionless, open and uncensorable. However, it intervened after attackers attempted to route stolen Bitget funds through the service.
Alex Shevchenko, general manager of NEAR Intents, said the attackers responsible for the $388 million Bitget breach attempted to move more than $50 million through the platform. NEAR Intents enables users to swap assets across different blockchain networks.
The platform’s SHIELD system blocked most of the attempted transactions and froze $503,000 during the transfer process. Its response contrasts with THORChain, which has resisted Bitget’s request to block wallets linked to the attackers.
Roughly $166,000 passed through NEAR Intents, while the restricted funds remain frozen as part of a legal and recovery process, Shevchenko said. He noted that the more than $50 million figure refers to attempted transfers rather than funds that were recovered.
Shevchenko said duplicate transactions were removed from the calculation, while funds rejected by NEAR Intents were subsequently routed through other providers. He cautioned that the figures are estimates and could vary from the actual amounts by approximately 10%.
NEAR Intents typically processes more than $100 million in cross-chain trading volume per day, according to Shevchenko. He said only a small portion of the stolen Bitget funds passed through the service.
The SHIELD system was responsible for the intervention. Shevchenko said it detects unusual transaction flows and combines data from KYT and intelligence providers, independent researchers, companies and major centralized crypto platforms. The resulting signals help determine how individual transactions should be handled.
The incident highlights the distinction between permissionless blockchain infrastructure and individual applications built on top of it. A service can remain open to users while still imposing restrictions on transactions associated with suspected stolen funds.
How NEAR Intents Detected the Bitget Funds
Bitget disclosed the breach on Sept. 24 after attackers bypassed security controls protecting its exchange wallets. The company later said it had patched the vulnerability, published wallet addresses linked to the attackers and offered bounties for eligible efforts to freeze or recover the stolen assets.
Circle and Tether, the issuers of USDC and USDT, have already frozen approximately $320,000 in stablecoins connected to the breach, according to CoinDesk.
NEAR Intents’ documentation states that swap requests are checked for links to reported hacks and that suspicious transactions can be delayed. These measures apply to activity conducted through the swap service and do not give NEAR Intents authority over every wallet on the NEAR blockchain.
The ability to restrict transactions has nevertheless prompted questions about the platform’s description of itself as permissionless.
Debate Over Who Can Stop a Swap
The intervention sparked an online debate about whether a service capable of holding funds should be considered permissionless.
Vini Barbosa, a technical writer and documentation engineer at Ramp Labs, questioned the distinction on X. He argued that permissionless systems should remain neutral, while acknowledging that NEAR Intents still has a useful role. He also warned that restrictions aimed at blocking unlawful users could potentially affect people attempting to resist government repression.
NEAR co-founder Illia Polosukhin presented a different view. He said permissionless blockchain infrastructure means users can own and transfer assets or deploy contracts on NEAR without obtaining permission. However, he argued that individual applications and liquidity providers are not required to process every transaction.
The position differs from THORChain’s approach. The swap network has defended allowing users to access its infrastructure and said its emergency shutdown mechanisms are intended to protect the protocol rather than selectively freeze funds.
A CoinDesk analysis on Monday found about $6.3 million in completed ether-to-bitcoin swaps from a wallet associated with the Bitget attacker.
NEAR Intents continues to hold the intercepted funds while legal and recovery procedures are carried out. Shevchenko asked Bitget to contact the service through legal and law-enforcement channels and said the platform would waive its recovery bounty.
However, his report did not identify who has authority to approve the release of the funds or explain how legitimate users could recover assets if their transactions were incorrectly flagged.
Shevchenko said NEAR Intents would continue operating as permissionless infrastructure while maintaining safeguards against the laundering of hacked funds.





