Skip to content

Invest1 publisher3 min readPublished

NEAR Intents turned away about $50 million of Bitget loot that the hackers routed elsewhere

NEAR Intents' SHIELD layer refused all but $166,000 of a $50 million-plus attempt by Bitget's hackers. That makes screening policy the clearest difference between NEAR and THORChain. Each protocol carries a different exposure because of it.

The Investor · Invest desk

Illustration accompanying NEAR Intents turned away about $50 million of Bitget loot that the hackers routed elsewhere

What happened

  • Bitget lost about $387.5 million on September 24 in an attack that Bankless says closely matches known North Korean hacker patterns.
  • The attackers swapped stolen USDT and USDC into ETH and BNB to get around any Tether or Circle freezes before moving the funds out.
  • THORChain turned down Bitget CEO Gracy Chen's formal request to refuse service to the attackers' tracked addresses, likening its neutrality to Bitcoin's and Ethereum's.
  • SHIELD decides which trades NEAR Intents executes but cannot freeze NEAR wallets or reverse completed transactions, because Intents sits atop NEAR outside consensus.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • contradiction Bankless headlined that NEAR stopped the hackers, yet its own account has the refused funds routed to other protocols, so the block protected NEAR's solvers with no reported benefit to Bitget's recovery.
  • exposure Each venue that screens pushes more stolen flow toward the rail that will not block, concentrating the reputational exposure of the next heist on THORChain.
  • cost NEAR pays for the block in its Confidential Intents pitch, since a network that can refuse hackers now has to argue about whom else it could refuse.

The attempt at NEAR ran past $50 million, about 12.9% of the roughly $387.5 million taken. The $6 million-plus that went through THORChain is about 1.5% [1][4][5][3][4]. Between them, the two protocols at the centre of the policy argument saw roughly a seventh of the loot [5]. At NEAR, $166,000 got through. That is at most a third of one percent of the attempt, so about $49.8 million was refused [6][1][2].

The refused money kept moving. According to Bankless, the culprits routed the Bitget funds SHIELD blocked to other protocols [11]. For the attacker, screening at one venue is a detour. For NEAR, the block means only that its own solvers did not execute those trades. Bankless ties that limit to NEAR co-founder Illia Polosukhin's pitch of SHIELD as shared infrastructure [11][12].

THORChain's stance has a record. Bankless reports it facilitated 72% of the stolen ETH moved after the $1.4 billion Bybit hack in February 2025 [10], and it declined to block again with Bitget [3]. Whatever Bybit cost THORChain, the policy did not change [3][10]. Bankless calls it "the go-to exit ramp for crypto's biggest heists" [15]. The source does not report THORChain's fee income on the $6 million or the volume NEAR gave up by refusing $50 million, so neither choice can yet be priced in dollars [4][5].

NEAR's exposure is in its privacy product. Deposits into and withdrawals from NEAR Intents are ordinary public transactions on Bitcoin, Ethereum and Zcash; balances, routes and trades sit inside Confidential Intents [9]. SHIELD compares those public deposit addresses with stolen-funds intelligence that much of the industry already shares [7]. By Bankless's account, the block opened nothing confidential. The backlash Bankless describes asks what would stop NEAR doing the same to other users later [13]. Bankless's own verdict is that SHIELD is "an opinionated, moral implementation that makes NEAR unviable for moving large amounts of illicit funds" [14].

If SHIELD spreads as shared infrastructure, neutral rails become the remaining exit and more of the flow lands on THORChain [12][15]. Kept at NEAR alone, screening remains a detour and both protocols keep the exposure they have now [11]. A privacy complaint that sticks would cost NEAR Confidential Intents users over a check that only touched public addresses [7][13]. I think compliance posture is now a real way to tell these protocols apart, because it decides which venue carries a heist's flow and the reputation attached to it. The counter-case is THORChain's own record. It moved most of Bybit's stolen ETH, and a hacker-linked wallet still used it for more than $6 million after Bitget [10][4]. The evidence here puts no measured cost on its neutrality. If the next large theft again runs mostly through THORChain with its policy and usage unchanged, the risk-factor view is wrong.

What to watch

  • Whether any other cross-chain protocol adopts SHIELD as shared infrastructure, as Illia Polosukhin has pitched.
  • Whether THORChain changes its policy on tracked hack addresses after handling stolen funds from both Bybit and Bitget.
  • Whether Confidential Intents usage holds up after the privacy backlash over the Bitget block.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories