- NEAR Intents’ SHIELD system intercepted $50 million in attempted transfers from Bitget hackers, freezing $503K midway through swaps and allowing only $166K through. SHIELD combines Know-Your-Transaction (KYT) intelligence from providers, research firms, and industry players to detect “deviations in flows” and decide how to handle transactions. Most rejected funds subsequently moved to other cross-chain providers. NEAR Intents processes $100M+ daily crosschain volume, validating that Bitget hack traffic represents ~50% spike but concentrated over few days.
- The intervention contradicts NEAR Intents’ marketing as “permissionless, open and uncensorable”—raising philosophical debate over what permissionlessness means in practice. NEAR Cofounder Illia Polosukhin clarified: “permissionless” means users don’t need approval to own/transfer assets or deploy contracts on NEAR, but “does not mean every application or liquidity provider must process every transaction.” NEAR Intents holding frozen $503K pending legal/law-enforcement recovery, waiving recovery bounty if contacted through proper channels—no clarity on how wrongly-flagged users could reclaim funds.
- THORChain took opposite stance: refused Bitget’s request to block attacker addresses, defending “permissionless” ideology as neutrality. CoinDesk identified ~$6.3M in completed ether-to-bitcoin swaps from one Bitget attacker wallet via THORChain. Meanwhile Circle (USDC issuer) and Tether (USDT issuer) froze ~$320K in stablecoins linked to breach—centralized token issuers can block via blacklist, cross-chain swaps cannot without violating “permissionless” design.
- The Bitget hack ($388M, Sept 24 disclosure) tests whether decentralized finance can balance security with ideology. NEAR Intents’ SHIELD approach (blocking via intelligence consensus) may become industry standard—validating that “permissionless” crypto platforms are adopting guardrails similar to Article 165 (Nvidia safety platform, containment). Vini Barbosa (Ramp Labs) warned restrictions nominally targeting “unlawful” actors could also harm users resisting government repression—validating geopolitical risk (Article 156 US-China trade thesis extends to crypto sanctions/capital controls).
What Happened?
NEAR Intents’ SHIELD protocol intercepted $50 million+ in attempted cross-chain swaps from Bitget hackers. The system froze $503,000 midway through transactions and allowed $166,000 to complete. SHIELD uses Know-Your-Transaction (KYT) intelligence from providers, researchers, and industry firms to detect suspicious flows. NEAR Intents General Manager Alex Shevchenko reported that rejected funds subsequently moved through other providers (THORChain, etc.). Frozen funds await legal/law-enforcement recovery process; NEAR Intents waiving recovery bounty if contacted through proper channels. Bitget disclosed $388M breach on Sept. 24 after attackers bypassed wallet security. Circle froze ~$320K USDC, Tether ~$0K USDT. THORChain refused Bitget’s request to block attacker addresses.
Why It Matters?
The intervention exposes tension between “permissionless” crypto ideology and practical security. NEAR Intents markets itself as open, uncensorable, and permissionless—yet successfully blocked $50M+ in attempted theft. NEAR Cofounder Illia Polosukhin clarified: permissionless means users don’t need approval to own assets or deploy contracts, but doesn’t obligate liquidity providers to process every transaction. However, Vini Barbosa (Ramp Labs) warned that restrictions targeting “unlawful” actors could also harm users resisting government repression—validating geopolitical risk (Article 156 thesis: capital controls, sanctions enforcement via crypto). THORChain’s refusal to block hacker addresses (citing neutrality) validates philosophical divide: some protocols enforce “true” permissionlessness; others adopt guardrails (SHIELD, Article 165 Nvidia safety platform). Circle/Tether’s ability to freeze via stablecoin blacklist validates that centralized token issuers have power cross-chain swaps lack—creating arbitrage for hacker funds to flow into non-blacklisted assets (NEAR, ETH, BTC). Bitget hack ($388M, validating Article 151 revised estimate) tests whether decentralized infrastructure can adequately protect users—NEAR Intents’ $503K freeze validates some deterrent, but $166K+ slippage and $6.3M+ completed THORChain swaps validate jurisdictional arbitrage.
What’s Next?
Monitor NEAR Intents’ legal/recovery process: if successfully returns $503K to Bitget, validates SHIELD deterrent. If wrongly-flagged user attempts recovery and is denied, validates guardrail overreach risk. Track whether $50M+ hacker funds successfully convert to non-blacklisted assets (NEAR, ETH, BTC, privacy coins). Watch THORChain for similar hacker flows; if $10M+ confirmed, validates protocol divide (NEAR guardrails vs. THORChain permissionlessness). Monitor stablecoin issuer responses: if Circle/Tether expand blacklists proactively (not just Bitget), validates centralized token control over DeFi. Track geopolitical weaponization of SHIELD/guardrails: if governments pressure NEAR to block non-hacker addresses (sanctions evasion, etc.), validates Barbosa’s caution. Finally, watch for regulatory guidance: if SEC/CFTC mandate SHIELD-like guardrails for cross-chain swaps, validates protocol shift toward permissioned infrastructure disguised as permissionless.
Affected Tickers and Coins: NEAR | BTC | ETH | Circle | Tether | THORChain | Bitget | Ramp Labs
Source: CoinDesk














