NEAR Intents Intercepts $50 Million in Stolen Bitget Funds
The cross-chain protocol NEAR Intents disclosed that it successfully blocked more than $50 million in attempted transfers connected to the massive Bitget hack that unfolded on Thursday. According to Alex Shevchenko, the protocol's general manager, a substantial share of the stolen assets was routed across multiple chains toward Ethereum, where NEAR Intents' SHIELD detection system flagged and halted the transfers before they could be completed.
The Bitget exploit saw attackers drain $387.5 million from the exchange. Of the funds that reached NEAR Intents' infrastructure, the SHIELD system stopped the bulk — over $50 million — which were then redirected to other service providers. In the course of execution, the protocol managed to freeze $503,000 in assets. However, Shevchenko acknowledged that approximately $166,000 in what he described as suspected stolen funds still managed to pass through the system.
For traders and institutional users relying on cross-chain bridges, this incident underscores a persistent risk: the speed at which stolen digital assets can be moved across blockchains makes real-time detection and interdiction a critical layer of defense.
The Permissionless Protocol Debate Intensifies
The NEAR Intents disclosure landed at a sensitive moment. THORChain, a decentralized protocol facilitating asset swaps between blockchains, came under direct pressure to block wallet addresses associated with the Bitget exploit. Bitget CEO Gracy Chen publicly called on THORChain to deny services to the linked addresses on Friday.
THORChain pushed back, stating that its architecture does not incorporate selective censorship by design. The protocol clarified that while it has halted its network in past incidents, such a halt functions as a broad emergency security mechanism affecting the entire protocol rather than a targeted freeze of specific funds or individual swaps.
Shevchenko used the opportunity to challenge the assumption that permissionless systems must remain neutral. He argued that the engineers building these protocols inherently make choices about what the infrastructure permits, and that refusing to facilitate the laundering of stolen assets is a deliberate design decision on their part.
He went further, asserting that property rights are foundational to any functioning market. In his view, a financial ecosystem in which theft grants the perpetrator an unrestricted ability to convert the stolen asset into value is not a freer system — it is one that shields the thief. Such a framework, he warned, cannot serve as the economic foundation for future financial infrastructure.
Bounty Waiver and Recovery Efforts
In a move that signals a commitment to returning assets to the victim rather than maximizing its own revenue, NEAR Intents announced it will waive the 5% bounty that Bitget had offered for the freezing of attacker funds, along with an additional 5% bounty tied to the eventual recovery of those assets. This means a larger share of the frozen capital will flow back to Bitget and, ultimately, to affected users.
Shevchenko confirmed that the frozen funds would be returned through an appropriate legal process, a detail that matters for traders who may be holding assets in wallets connected to the exploit chain.
Separately, onchain data showed that stablecoin issuers Circle and Tether blacklisted a wallet linked to the Bitget exploit on Friday, freezing $318,013 in combined USDT and USDC balances. This coordinated response across multiple protocol operators highlights the growing, if still fragmented, effort to track and immobilize stolen crypto assets.
Key Takeaways for Traders and Security Teams
The Bitget incident and the ensuing cross-protocol response raise several practical concerns for anyone active in the crypto markets:
Cross-chain bridges are a primary laundering vector. The fact that a significant portion of $387.5 million moved toward Ethereum within hours demonstrates how quickly stolen assets can be re-routed. Traders should be aware that bridge protocols, while convenient, are among the first points of contact for illicit fund movements.
Protocol responses are not uniform. NEAR Intents chose active interdiction; THORChain adhered to its no-censorship design philosophy. Users should understand which protocols in their stack have built-in security filters and which operate on a purely permissionless basis.
Bounty structures influence recovery outcomes. The decision by NEAR Intents to forgo its share of the bounty is notable, but it also illustrates that recovery of stolen funds depends heavily on the willingness of intermediate protocols to cooperate.
Stablecoin issuers remain a critical choke point. The Circle and Tether blacklist action, freezing over $318,000 in stablecoins, shows that even in a fragmented ecosystem, centralized issuers can still play a decisive role in halting illicit flows.
Shevchenko closed with a pointed warning directed at the broader industry: crypto cannot simultaneously demand recognition of digital property rights while building infrastructure optimized for monetizing stolen property. For traders, that statement frames the Bitget hack not merely as an isolated security failure, but as a stress test of the values and safeguards underpinning the entire cross-chain ecosystem.