The swap service identified more than $50 million in attempted transfers, although most rejected funds subsequently moved through other providers.

  • NEAR Intents said it stopped about $503,000 linked to Bitget’s $388 million hack during cryptocurrency swaps, while about $166,000 passed through the service.
  • The intervention contrasts with THORChain’s refusal to block attacker addresses and has fueled debate over whether NEAR Intents can accurately describe itself as permissionless.
  • NEAR Intents said the restricted funds will remain on hold pending legal and recovery proceedings, but it did not explain who can authorize their release or how wrongly flagged users can recover their money.

Crypto swap platform NEAR Intents calls itself permissionless, open and uncensorable. Yet it slammed the doors when stolen funds from Bitget tried to move through the protocol.

The attackers who siphoned off $388 million from Bitget exchange last week tried to move more than $50 million through NEAR Intents, a service that lets users exchange assets across different blockchains, according to a report by NEAR Intent’s general manager, Alex Shevchenko.

The protocol’s “SHIELD” system blocked most transfers and froze $503,000 midway through the transaction, taking a different approach from THORChain, which has resisted the exchange’s request to block attacker addresses.

About $166,000 passed through, while the restricted funds await a legal and recovery process, he said. The larger figure represents attempted transfers rather than money recovered.

Shevchenko said duplicate attempts had been removed from the tally and rejected funds subsequently went to other providers. The figures are estimates, however, and could differ from the actual amounts by up to roughly 10%.

“NEAR Intents routinely processes $100M+ of a crosschain trading volume in a day. Yet in this case, only a negligible fraction of the hacked funds were flowing through us,” he said.

“The reason for this behaviour is SHIELD. It automatically detects deviations in flows, collects numerous inputs from KYT and intelligence providers, independent researches, companies and largest centralised players in the industry. Based on these signals the protocol can decide how to handle a transaction,” Shevchenko added.

In other words, permissionless and open doesn’t automatically mean a free ride for malicious actors and their money.

Bitget disclosed the breach on Sept. 24 after attackers bypassed security controls protecting its exchange wallets. The company has since said it fixed the vulnerability, published attacker addresses, and offered bounties for eligible efforts to freeze or recover funds.

Circle and Tether, the issuers of USDC and USDT, have already frozen about $320,000 in stablecoins linked to the breach, as CoinDesk reported last week.

Intents documentation says the service checks swap requests for links to reported hacks and can delay suspicious transactions. These checks apply when someone uses the swap service, but do not give its operators control over every wallet on the NEAR blockchain.

The ability to hold funds has drawn scrutiny of NEAR Intents’ description of itself as permissionless, meaning people can use it without seeking an operator’s approval.

Who gets to stop a swap

The intervention drew criticism online over whether a service that can hold funds should describe itself as permissionless. Among those questioning the label was Vini Barbosa, a technical writer and documentation engineer building at Ramp Labs.

“Permissionless does mean neutral. It's the whole point of building something ‘permissionless’,” he wrote on X, adding the product remained useful, but warned that restrictions on supposedly unlawful users could also affect people resisting government repression.

“I'm not saying it's a bad product. It has its use/niche and is valuable for the vast majority of users,” he added.

Meanwhile, NEAR Cofounder Illia Polosukhin said allowing people to hold and transfer assets on a blockchain does not oblige every business built on it to handle their money.

“Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR,” he wrote on X. “It does not mean every application or liquidity provider must process every transaction.”

The approach is the opposite of what other projects do, where some funds are routed.

Swap service THORChain has defended allowing anyone to use its network, saying its emergency shutdown controls protect the protocol rather than selectively freeze funds.

A CoinDesk analysis on Monday identified about $6.3 million in completed ether-to-bitcoin swaps from one wallet linked to the Bitget attacker.

Read More: THORChain rejects Bitget request to block hacker as $6 million moves to bitcoin

NEAR Intents is holding its intercepted funds pending a legal and recovery process. Shevchenko asked Bitget to contact the service through legal and law-enforcement channels and said it would waive its recovery bounty.

His report did not name who can authorize the money’s release or explain how someone wrongly flagged could get their funds back.

“NEAR Intents will remain permissionless infrastructure, but with boundaries,” he wrote. “We will actively fight the laundering of hacked funds.”

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.