Decentralized exchange protocol NEAR Intents markets itself as an open, neutral, and censorship-resistant environment. Yet, it slammed the brakes when stolen capital tied to the Bitget breach attempted to pass through the system.
The threat actors who drained $388 million from the Bitget trading platform last week sought to funnel over $50 million via NEAR Intents, a crosschain asset exchange tool, according to an update published by Alex Shevchenko, general manager of NEAR Intents.
The protocol’s built-in “SHIELD” mechanism intercepted the bulk of the transfers, freezing approximately $503,000 mid-transfer. This approach directly contrasts with THORChain, which previously declined the exchange platform’s appeals to block malicious addresses.
Roughly $166,000 successfully processed, while the suspended assets are now held awaiting formal legal and asset recovery procedures, he explained. The larger figure mirrors attempted transactions instead of fully reclaimed funds.
Shevchenko noted that duplicate attempts were filtered out of the statistics, and rejected funds ultimately shifted toward alternative platforms. Nevertheless, these numbers are preliminary estimates and might vary by up to 10% from exact balances.
“NEAR Intents routinely processes $100M+ of a crosschain trading volume in a day. Yet in this case, only a negligible fraction of the hacked funds were flowing through us,” he said.
“The reason for this behaviour is SHIELD. It automatically detects deviations in flows, collects numerous inputs from KYT and intelligence providers, independent researches, companies and largest centralised players in the industry. Based on these signals the protocol can decide how to handle a transaction,” Shevchenko added.
In other words, being open and permissionless does not automatically grant bad actors and their illicit capital a free pass.
Bitget revealed the exploit on September 24 after perpetrators bypassed security defenses securing its exchange wallets. The firm subsequently announced it patched the flaw, disclosed malicious addresses, and issued bounties for successful efforts to freeze or retrieve assets.
As previously covered by CoinDesk, stablecoin issuers Circle and Tether have already locked roughly $320,000 in digital tokens associated with the exploit.
Official documentation for Intents specifies that the platform screens swap inquiries for connections to known security incidents and possesses the capability to pause suspicious operations. These evaluations trigger when individuals utilize the swap utility, though they do not grant administrators authority over every individual wallet across the broader NEAR network.
This capacity to withhold assets has sparked intense debate over whether NEAR Intents can rightfully label itself as permissionless—a term denoting that individuals can utilize a system without needing authorization from an operator.
Who gets to stop a swap
This intervention triggered online skepticism concerning whether a protocol capable of freezing funds should define itself as permissionless. Vini Barbosa, a technical writer and documentation engineer contributing to Ramp Labs, was among those challenging the designation.
“Permissionless does mean neutral. It’s the whole point of building something ‘permissionless’,” he shared on X, noting that the utility remained functional while cautioning that curbs targeting illicit users could inadvertently impact individuals evading oppressive government regimes.
“I’m not saying it’s a bad product. It has its use/niche and is valuable for the vast majority of users,” he added.
Meanwhile, NEAR co-founder Illia Polosukhin argued that empowering users to hold and transfer funds natively on a blockchain does not force every enterprise built on top of it to service those transactions.
“Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR,” he posted on X. “It does not mean every application or liquidity provider must process every transaction.”
This strategy stands in stark contrast to alternative networks where some capital is routed.
Swap protocol THORChain has defended its policy of permitting unrestricted network access, arguing that emergency circuit breakers safeguard the protocol framework as a whole instead of selectively locking specific funds.
A CoinDesk analysis published on Monday tracked approximately $6.3 million in finalized ether-to-bitcoin exchanges originating from a single address linked to the Bitget attacker.
Read More: THORChain rejects Bitget request to block hacker as $6 million moves to bitcoin
NEAR Intents is retaining the intercepted capital pending judicial and recovery workflows. Shevchenko encouraged Bitget to reach out through formal legal and law enforcement pathways and confirmed the platform would waive its standard recovery bounty.
His update omitted details regarding who holds the authority to approve the release of these assets or how falsely flagged participants might reclaim their money.
“NEAR Intents will remain permissionless infrastructure, but with boundaries,” he wrote. “We will actively fight the laundering of hacked funds.”
Originally published at https://www.coindesk.com/tech/2026/09/29/usd50-million-in-bitget-hacker-swaps-puts-near-intents-permissionless-claim-to-the-test.