TL;DR:
- NEAR Intents blocked hacker-linked swaps tied to the Bitget breach, freezing about $503,000 while allowing $166,000 to pass through its infrastructure.
- Attackers attempted to route more than $50 million through the service, but most rejected funds later moved through other providers, limiting impact.
- The intervention has intensified debate over whether NEAR Intents can remain permissionless while using SHIELD compliance controls to halt cross-chain transactions and hold funds pending legal review.
NEAR Intents blocked hacker-linked transfers tied to the Bitget breach, putting scrutiny on its claim to offer permissionless cross-chain infrastructure. In a public explanation, general manager Alex Shevchenko said attackers attempted to route more than $50 million through the service, with duplicate attempts removed. SHIELD stopped most flagged flows, froze $503,000 mid-transaction and allowed about $166,000 to pass through. The episode connects to the Bitget exploit, which reached about $387.5 million in identified losses.
— Alex Shevchenko 🇺🇦 (@AlexAuroraDev) September 28, 2026
NEAR Intents Faces a Permissionless Design Test
NEAR Intents uses its SHIELD system to screen transaction flows using KYT data, intelligence providers, independent research and signals from industry participants. When suspicious activity is detected, the protocol can delay or halt a swap rather than execute it automatically. That control introduces a boundary around a product marketed as open and permissionless. A similar tension surfaced in a NEAR Intents compliance dispute, where a user reported funds remaining frozen after a cross-chain conversion.

Shevchenko argued that permissionless infrastructure does not require the protocol to process illicit funds, while NEAR co-founder Illia Polosukhin distinguished permissionless asset ownership from application-level service. Under that interpretation, users can hold assets and deploy contracts without approval, but liquidity providers are not obligated to process every swap. The debate centers on whether censorship-resistant infrastructure can coexist with compliance-controlled applications layered above it. That question matters as NEAR Intents expands cross-chain routing and handles large transaction volumes.
The blocked funds remain on hold pending legal and recovery proceedings. Shevchenko asked Bitget to engage through legal and law-enforcement channels and said NEAR Intents would waive its recovery bounty. The explanation did not specify who authorizes release or how wrongly flagged users can recover funds. That lack of clarity leaves governance questions around appeals, custody and operational discretion. It also contrasts with THORChain’s refusal to block Bitget-linked addresses, where the protocol defended a stricter permissionless model.
Most rejected transfers reportedly moved through other providers after NEAR Intents blocked them, showing that filtering one venue does not necessarily stop laundering across a fragmented cross-chain market. The intervention limited NEAR Intents’ exposure to the stolen funds but did not prevent attackers from seeking alternative routes. The dispute goes beyond a single hack: it tests how cross-chain systems balance open access, compliance controls and recovery obligations when illicit funds attempt to use infrastructure designed for frictionless movement.


