A $50 Million Laundering Attempt Stops at the Gate

The group that drained $388 million from Bitget exchange in late September made a coordinated push to move more than $50 million in stolen assets through NEAR Intents, a cross-chain swap service that advertises itself as open, permissionless, and uncensorable. According to Alex Shevchenko, the protocol's general manager, the bulk of those transfer attempts were intercepted, and $503,000 was frozen mid-transaction by the platform's automated security layer.

Approximately $166,000 slipped through before the system flagged the flow, Shevchenko noted. He stressed that the larger $50 million figure reflects attempted transfers rather than recovered money, and that duplicate entries had been stripped from the count. He also cautioned that all figures are estimates with a possible margin of error of around 10 percent. Rejected funds were subsequently routed to other liquidity providers.

Shevchenko put the scale in context: NEAR Intents routinely clears over $100 million in cross-chain trading volume on a typical day, yet the hacker traffic represented only a tiny slice of that flow. The intervention, he said, was the direct result of the protocol's SHIELD system, which monitors for anomalous flow patterns and ingests signals from KYT (Know Your Transaction) vendors, threat-intelligence firms, independent researchers, and major centralized market participants before deciding how to treat a given transaction.

Bitget's Breach and the Wider Response

Bitget publicly disclosed the hack on September 24 after the attackers exploited a vulnerability in the security controls guarding its exchange hot wallets. The company has since patched the flaw, released the addresses associated with the stolen funds, and put bounties on the table for anyone who can help freeze or recover the money.

Stablecoin issuers have also moved: Circle and Tether, the companies behind USDC and USDT respectively, have already frozen roughly $320,000 in stablecoins tied to the breach. Meanwhile, THORChain, another cross-chain swap network, took the opposite stance. It publicly rejected Bitget's request to black-list the attacker addresses, arguing that its emergency shutdown mechanism is designed to protect the protocol as a whole rather than to selectively freeze individual wallets.

A CoinDesk analysis published earlier this week identified approximately $6.3 million in completed ether-to-bitcoin swaps originating from a single wallet linked to the Bitget attacker, underscoring how quickly the stolen funds were being converted across chains.

The 'Permissionless' Label Under the Microscope

NEAR Intents' decision to hold funds has reignited a thorny question in the crypto community: can a service that reserves the right to freeze transactions genuinely call itself permissionless? The protocol's own documentation states that it screens swap requests against known hack reports and can delay suspicious transfers, but it clarifies that these checks apply only when a user actively routes a trade through the service and do not extend to every wallet on the NEAR chain.

Vini Barbosa, a technical writer and documentation engineer at Ramp Labs, pushed back on the terminology on X. He argued that the whole point of building a 'permissionless' system is neutrality, and warned that restrictions aimed at allegedly unlawful users could also catch people evading government repression. He conceded the product remained useful and valuable for most users but insisted the label should not be applied without scrutiny.

Illia Polosukhin, co-founder of NEAR, offered a different framing. He wrote on X that permissionless means no one needs approval to own, transfer, or deploy assets on the NEAR chain, but it does not compel every application or liquidity provider built on top of that chain to process every single transaction. In his view, the protocol layer and the application layer are distinct, and a swap service is free to set its own operational boundaries.

What Traders and Investors Should Take Away

From a risk-management perspective, the incident highlights several points that crypto traders and self-custody holders should keep in mind. First, even services that brand themselves as open and trustless may deploy automated screening and can freeze or delay transactions that trigger their risk models. Users routing significant sums through cross-chain aggregators should be aware that a hold is possible, particularly when the destination or source address has been flagged by third-party intelligence feeds.

Second, the Bitget episode shows how rapidly stolen exchange funds are laundered across multiple chains within hours. If you hold assets on a centralized exchange, the window between a breach and the funds being moved off-platform is narrow. Diversifying storage across self-custody wallets, hardware devices, or staking positions reduces exposure to a single institutional failure.

Third, the lack of clarity around NEAR Intents' freeze process is a red flag for anyone whose transaction might be wrongly flagged. Shevchenko's report did not specify who holds authority to release the held funds, nor did it outline a formal appeal mechanism for a user who believes their assets were mistakenly caught. Traders using the service should review its terms of use carefully and keep transaction records that could support a recovery claim.

Shevchenko closed his statement by asking Bitget to reach out through legal and law-enforcement channels and said NEAR Intents would waive any recovery bounty it might otherwise claim. "NEAR Intents will remain permissionless infrastructure, but with boundaries," he wrote. "We will actively fight the laundering of hacked funds." That single sentence may become a defining reference point in the ongoing debate over where the line between open infrastructure and selective censorship sits in crypto.