
NEAR Intents says SHIELD blocked $50M+ in Bitget-hack-linked transfer attempts
The disclosure lands as THORChain reiterates it will not selectively censor attacker-linked flows by design.
NEAR Intents said its SHIELD system detected and blocked more than $50 million in attempted cross-chain transfers linked to the Bitget hack, freezing $503,000 during execution while about $166,000 still passed through. The numbers sharpen a trader-facing split between routes that filter suspected illicit flows and routes that refuse selective censorship, with different freeze and execution risks.
NEAR Intents Puts Numbers on SHIELD’s Bitget-Hack Interdictions
NEAR Intents said its SHIELD system detected and blocked more than $50 million in attempted transfers linked to the Bitget hack. The protocol framed the figure as interdicted routing demand rather than recovered proceeds, noting the blocked attempts “subsequently went to other providers.” That is the immediate market tell. Attack flows do not stop, they reroute.
The same disclosure put hard bounds on both effectiveness and leakage. NEAR Intents said it froze $503,000 in funds “during execution,” while around $166,000 in suspected stolen funds still passed through. The relationship between those figures is not fully reconciled in the disclosure, and the protocol did not publish transaction hashes or wallet identifiers. Traders should treat the numbers as directional until the onchain trail is mapped.
The hack itself was large enough to stress cross-chain liquidity. Attackers stole $387.5 million from Bitget on Thursday relative to the Sep. 29 publication date, and NEAR Intents general manager Alex Shevchenko said a “significant portion” moved across chains to Ethereum. “Significant” is not a number. The absence of a chain-by-chain breakdown is part of the risk here.
Cross-Chain Censorship Fault Line: NEAR’s Selective Blocking vs THORChain’s Non-Censorship Design
NEAR Intents is positioning SHIELD as a compliance-style gate inside a permissionless wrapper. Shevchenko rejected the idea that open access requires neutrality, saying, “The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours,” and adding, “Property rights are fundamental to functioning markets. A financial system where stealing an asset gives you an unrestricted right to monetize it isn’t a freer system. It is simply a system that protects the thief. Such systems cannot become the economic backbone of the future,”.
That posture matters because it changes the routing calculus during exploit flows. A selective filter can reduce downstream contamination risk for integrators and market makers, but it introduces a new failure mode for users: false positives and frozen execution mid-route. NEAR Intents said it will forego Bitget’s offered bounty of 5% for freezing attacker funds and an additional 5% for recovery, explicitly to return more funds to Bitget. That is a signaling move. It reads like infrastructure trying to look neutral on incentives while still being opinionated on enforcement.
The other side of the split is being litigated in public. Bitget CEO Gracy Chen called on THORChain to refuse services to addresses linked to the attack. THORChain responded that it “doesn’t censor by design,” and said its past network halts are broad emergency security mechanisms rather than selective action, stating a halt “is not a selective freeze of specific funds or an individual swap.” That is a different product promise: fewer discretionary blocks, but more exposure to being the path of least resistance when attackers need liquidity.
Stablecoin issuers remain a parallel enforcement layer that can override both philosophies. Circle and Tether blacklisted a wallet linked to the Bitget exploiter on Friday relative to the Sep. 29 publication date, freezing $318,013 of USDT and USDC, per onchain data referenced by NEAR Intents. Even if a cross-chain venue does not selectively censor, settlement can still be frozen at the asset layer.
Next Disclosures That Could Reprice Cross-Chain Risk
The missing detail that could move perception fastest is who the “other providers” were that processed the blocked $50 million-plus in attempted transfers after SHIELD intervention. Venue names, destination chains, or even wallet-cluster attribution would tell traders whether this was a simple reroute to comparable liquidity or a forced move into thinner, higher-slippage paths.
The stablecoin blacklist action also needs onchain specificity to become tradable information rather than narrative. The disclosure cites $318,013 frozen, but the wallet identity, transaction references, and whether additional freezes followed were not provided.
On the protocol side, the next decision point is whether THORChain governance or operators take any action beyond its stated non-censorship posture. The line THORChain drew leaves room for broad emergency halts, and the market will care whether pressure converts into any network-wide response.
Finally, NEAR Intents said the $503,000 it froze would be returned “through an appropriate legal process.” Jurisdiction, timeline, and counterparties were not specified. Those details determine whether “frozen” means temporarily delayed or practically unrecoverable.
My Take: Hack-Flow Filtering Is Becoming a Product Choice, Not a Philosophy Debate
The threshold that matters is not the $50 million headline number. It is the admission that the blocked attempts still cleared elsewhere. If SHIELD is going to be priced as a safety feature, the market needs to learn whether it meaningfully constrains attacker outcomes or just pushes them into different pipes.
The real test is whether the ecosystem starts labeling routes by enforcement posture the way it already labels them by fees and latency. If NEAR Intents can document where the rerouted flows went and close the gap between $503,000 frozen and ~$166,000 that passed through, filtering starts to look structural rather than narrative-driven.