On Sept. 24 Bitget suffered a security breach that sent $387.5 million to attacker-controlled addresses. NEAR Intents, a cross-chain swapping protocol, says its SHIELD monitoring system detected and blocked more than $50 million in attempted transfers tied to those attacker wallets as funds moved across chains to Ethereum.
Concrete numbers reported by NEAR Intents' general manager Alex Shevchenko: SHIELD blocked over $50 million in attempted transfers, froze $503,000 during execution, and around $166,000 in suspected stolen funds passed through its infrastructure.
Stablecoin issuers Circle and Tether blacklisted a wallet linked to the Bitget exploiter and froze $318,013 in USDT and USDC, according to onchain data cited in reporting. Bitget's CEO publicly called on THORChain to refuse services to addresses tied to the attack.
THORChain's response differed: it said it does not implement selective freezes and that its emergency halts are broad security mechanisms rather than targeted censorship of specific funds or swaps.
The Bitget incident highlights a tension within permissionless finance: maintaining open access versus taking targeted action to block illicit flows. NEAR Intents' stance is that protocol designers make choices about permitted behavior and that refusing to process stolen assets is a valid policy. THORChain's stance emphasizes non-selective protocol behavior even when external parties request freezes.
Related reporting indicates that days later NEAR Intents itself was exploited, with a separate incident resulting in a $3.8 million loss via a deposit/withdrawal bug. NEAR Intents said it would compensate affected users. These follow-up reports show the operational and security risks that can follow high-profile intervention in laundering cases.
- Whether NEAR Intents and other cross-chain protocols adopt more formalized rules or industry standards for blocking suspected illicit flows.
- Any legal steps or court orders tied to returning frozen funds NEAR Intents identified.
NEAR Intents used its SHIELD system to stop large attempted transfers it linked to the Bitget hack, waived recovery bounties to maximize returned funds, and framed this as a deliberate design choice. Other major actors took different approaches: Circle and Tether blacklisted a wallet, while THORChain maintained a non-selective policy. Follow-up developments included a separate exploit that affected NEAR Intents days later.