September 29, 2026

Real-Time Crypto Insights, News And Articles

Near Intents Blocks $50M in Bitget Hacker Swaps: What Happened

NEAR Intents detected more than $50 million in attempted transfers linked to the Bitget hack, although most of the rejected funds were later routed through other swap providers.

NEAR Intents describes its crypto swap infrastructure as permissionless, open and uncensorable. However, the platform blocked transactions when funds stolen from Bitget were brought through its system.

Attackers behind the $388 million Bitget breach attempted to move more than $50 million through NEAR Intents, a service that enables asset swaps across multiple blockchains, according to a report from NEAR Intents general manager Alex Shevchenko.

The platform’s SHIELD system stopped most of the attempted transfers and froze $503,000 during the transaction process. This differs from THORChain’s approach, which has rejected Bitget’s request to block addresses associated with the attackers.

Around $166,000 ultimately passed through NEAR Intents, while the frozen funds remain subject to legal and recovery procedures, Shevchenko said. He stressed that the $50 million figure refers to attempted transfers rather than funds that were successfully recovered.

According to Shevchenko, duplicate transactions were excluded from the calculation, while funds rejected by NEAR Intents were subsequently sent through other service providers. He also noted that the figures are estimates and may vary from the actual amounts by roughly 10%.

“NEAR Intents routinely processes $100M+ of a crosschain trading volume in a day. Yet in this case, only a negligible fraction of the hacked funds were flowing through us,” Shevchenko said.

He attributed the intervention to SHIELD, which monitors unusual transaction flows and incorporates information from know-your-transaction (KYT) providers, intelligence firms, independent researchers and major centralized crypto companies. The system uses these signals to determine how a transaction should be handled.

The incident highlights that being permissionless and open does not necessarily mean malicious actors can freely move funds through every application built on a blockchain.

How NEAR Intents Blocked the Funds

Bitget revealed the security breach on Sept. 24 after attackers circumvented controls protecting wallets used by the exchange. The company later said it had fixed the vulnerability, released the attackers’ wallet addresses and offered bounties for qualifying efforts to freeze or recover the stolen assets.

Circle and Tether, the issuers of USDC and USDT, have already frozen roughly $320,000 in stablecoins associated with the exploit, according to a CoinDesk report from last week.

NEAR Intents documentation states that its swap service checks transactions for connections to known hacks and can delay transfers considered suspicious. These safeguards apply to users conducting swaps through the service and do not give NEAR Intents control over all wallets operating on the NEAR blockchain.

The ability to temporarily hold funds has nevertheless raised questions about the platform’s use of the term “permissionless,” since users can interact with permissionless infrastructure without obtaining approval from a central operator.

Debate Over Who Can Block a Swap

The decision to intervene prompted discussion online about whether a service capable of holding user funds should describe itself as permissionless.

Vini Barbosa, a technical writer and documentation engineer working at Ramp Labs, questioned the terminology. He argued on X that permissionless systems should remain neutral, while also acknowledging that NEAR Intents serves a useful purpose. He warned that restrictions designed to prevent unlawful activity could potentially affect users attempting to resist government repression.

NEAR co-founder Illia Polosukhin offered a different interpretation. He said that permissionless blockchain infrastructure allows users to own and transfer assets and deploy contracts without authorization, but does not require every application or liquidity provider built on the network to process every transaction.

“Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR,” Polosukhin wrote on X. “It does not mean every application or liquidity provider must process every transaction.”

The position contrasts with THORChain, which has defended its decision to allow users to access its network while arguing that its emergency shutdown mechanisms are intended to protect the protocol rather than selectively freeze individual funds.

A CoinDesk analysis on Monday found that roughly $6.3 million in completed ether-to-bitcoin swaps had originated from a wallet linked to the Bitget attacker.

NEAR Intents is keeping the intercepted funds while legal and recovery procedures take place. Shevchenko urged Bitget to contact the service through legal and law-enforcement channels and said NEAR Intents would waive its recovery bounty.

However, his report did not specify who has authority to approve the release of the frozen funds or describe the process available to users whose transactions are mistakenly flagged.

“NEAR Intents will remain permissionless infrastructure, but with boundaries,” Shevchenko wrote, adding that the service would continue working to prevent hacked funds from being laundered.

About The Author