Invest1 publisher3 min readPublished
Blocking $50 million from the Bitget hack opens NEAR Intents to wider claims, a lawyer says
NEAR Intents' SHIELD blocked $50 million of Bitget hack funds while THORChain declined Bitget's request to stop the flow. Lawyer Yuriy Brisov says claimants can use that shown control against NEAR in cases far beyond this one.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- THORChain replied that it is decentralized and permissionless like Bitcoin, Ethereum and BNB Chain, and asked what responsibility those chains bear for known stolen funds.
- THORChain's refusal drew criticism because the protocol halted immediately in May when $10.7 million of its own funds were exploited.
- About $1.2 billion of the $1.46 billion stolen from Bybit was swapped through THORChain, whose admin key had been retired 11 days before that hack.
- NEAR Intents turned down the 5% bounty Bitget offered for blocking the funds.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure THORChain's claim that it cannot block addresses has not been tested in court, and a claimant can point to its May halt over its own losses as proof it can stop the protocol when it wants to.
- precedent Under Brisov's logic, one visible block lets claimants argue NEAR owed broader screening, down to checking token issuers and collecting KYC the way a centralized exchange does.
- decision Anyone holding DeFi exposure now has a specific test for each protocol's blocking tools, namely whether a program makes the call or a person presses the button.
THORChain carried roughly 82% of the Bybit haul [2]. The interview does not say how large the Bitget hack was or how much of it went through THORChain, so NEAR's $50 million is the only hard Bitget figure [7]. At 5% of the $50 million stopped, the bounty NEAR declined comes to about $2.5 million [8] [1].
Yuriy Brisov of D&A Partners was asked whether THORChain had a duty to block [2], and he put the protocol's position in one line. He said its only protection is that it is decentralized [11]. He called that "the strongest defense for any DeFi protocol" [12]. It held for Uniswap, where a judge in March dismissed a suit by investors who had bought 38 rugpull and scam tokens [13].
By the same reasoning, NEAR's block is evidence of control. Once a protocol has used it, Brisov said, a claimant can ask: "Why do you use it in one case and not use it in another case? Why don't you check all your token issuers on your platform?" [14] Bitget thanked NEAR for the block [10]. Decentralization maximalists are attacking it for not being permissionless enough [9].
THORChain's own position has a weak point in the May halt [3]. The protocol says an automated system triggered that stop and that it cannot block particular addresses [15]. It has retired its admin key and has no easy way to censor addresses [4]. Asked whether that is a defense, Brisov said: "It might be. We don't know yet, because it hasn't been challenged yet." [16]
His test for a safe block turns on who decides. An oracle that blocks automatically, where "there is no person who sits and presses a button," passes. "Then it's okay," he said [17]. A team that spots illicit activity and presses the button manually "still makes the project not fully decentralized from the legal perspective," he said [18]. Cointelegraph describes SHIELD as automated [7].
The dispute can resolve in a few ways. A claimant who goes after THORChain first could persuade a court that the May halt proves it can stop flows when it chooses. Someone suing NEAR over an unrelated token loss could cite the Bitget block as proof it could have screened issuers. Or nobody sues, and each protocol pays only in reputation. In my view NEAR carries more legal exposure than THORChain on this record. Brisov's argument treats intervention as the evidence, and NEAR's intervention came with a $50 million figure and Bitget's public thanks attached [7] [10]. The counter-case is Brisov's own automation test: if no person pressed SHIELD's button, NEAR sits on the side he calls okay [17]. The view is wrong if a court holds a keyless router liable for passing known stolen funds, or treats an automated block as control.
What to watch
- A lawsuit or prosecution that tests THORChain's argument that it cannot block addresses, which Brisov says has not yet been challenged.
- Whether NEAR discloses if any person approved SHIELD's Bitget block, the fact that decides which side of Brisov's automation line it sits on.
- A claimant citing NEAR's Bitget block in a suit over token issuers or KYC on NEAR Intents.