Advertisement

Bitget Hacker’s $50M Swap Attempt Blocked by Near Intents

NEAR Intents identified more than $50 million in attempted transfers connected to the Bitget hack, although most of the funds rejected by the service were later moved through other providers.

The cross-chain swap platform describes itself as permissionless, open and uncensorable. Despite that positioning, NEAR Intents intervened when attackers attempted to move stolen Bitget funds through its infrastructure.

According to NEAR Intents general manager Alex Shevchenko, the attackers behind the $388 million Bitget breach attempted to route more than $50 million through the platform. NEAR Intents allows users to exchange assets across different blockchain networks.

Its SHIELD security system blocked most of those transactions and froze $503,000 while the transfers were in progress. The response differs from THORChain, which has declined Bitget’s request to block addresses associated with the attackers.

About $166,000 of the attempted transfers were completed, while the frozen funds remain subject to legal and recovery procedures, Shevchenko said. He emphasized that the more than $50 million figure represents attempted transfers, not the amount ultimately recovered.

Shevchenko said duplicate transactions were removed from the calculations and that funds rejected by NEAR Intents later moved through other swap services. He added that the figures are estimates and could differ from the actual amounts by around 10%.

NEAR Intents normally handles more than $100 million in daily cross-chain trading volume, according to Shevchenko. He said only a small portion of the Bitget attackers’ stolen assets passed through the platform.

He attributed the intervention to SHIELD, which monitors unusual transaction patterns and combines information from KYT providers, intelligence companies, independent researchers and major centralized crypto firms. Those signals help determine whether a transaction should proceed or face restrictions.

The incident demonstrates that permissionless access does not necessarily mean every application or service will process transactions involving potentially stolen assets.

Why NEAR Intents Blocked the Transfers

Bitget disclosed the breach on Sept. 24 after attackers bypassed security measures protecting the exchange’s wallets. The exchange later said it had fixed the vulnerability, published addresses associated with the attackers and offered bounties for eligible efforts to freeze or recover the stolen funds.

Circle and Tether, the issuers of USDC and USDT, have separately frozen around $320,000 in stablecoins connected to the breach, according to CoinDesk.

NEAR Intents documentation states that swap requests are screened for connections to reported hacks and that suspicious transactions can be delayed. These controls apply to activity conducted through the swap service and do not give NEAR Intents control over every wallet operating on the NEAR blockchain.

Still, the ability to intercept funds has raised questions about how the platform defines itself as permissionless.

Debate Over Permissionless Swaps

The intervention prompted discussion over whether a service that can restrict or hold funds should describe itself as permissionless.

Vini Barbosa, a technical writer and documentation engineer at Ramp Labs, questioned the distinction on X. He argued that permissionless infrastructure should remain neutral, while also saying the product remains useful. He cautioned that restrictions intended to prevent illicit activity could potentially affect users in situations involving government repression.

NEAR co-founder Illia Polosukhin offered a different interpretation. He said permissionless blockchain infrastructure means users do not need approval to own or transfer assets or deploy contracts on NEAR. However, he argued that this does not require every application or liquidity provider operating on the network to process every transaction.

The distinction sets NEAR Intents apart from THORChain, which has defended its decision to allow transactions on its network and said its emergency shutdown mechanisms are designed to protect the protocol rather than selectively freeze individual funds.

A CoinDesk analysis on Monday identified approximately $6.3 million in completed ether-to-bitcoin swaps from a wallet linked to the Bitget attacker.

NEAR Intents is keeping the intercepted funds while legal and recovery procedures are underway. Shevchenko asked Bitget to contact the platform through legal and law-enforcement channels and said NEAR Intents would waive its recovery bounty.

His report did not specify who can authorize the release of the frozen funds or explain what process would be available if a legitimate user were incorrectly flagged.

Shevchenko said NEAR Intents would continue operating as permissionless infrastructure while maintaining limits designed to prevent the movement and laundering of hacked funds.