NEAR Intents Intercepted More Than $50 Million in Bitget-Linked Transfers, but Only $503,000 Was Frozen
NEAR Intents Intercepted More Than $50 Million in Bitget-Linked Transfers, but Only $503,000 Was Frozen
Cross-chain infrastructure is facing renewed scrutiny after a major security incident involving assets allegedly connected to the Bitget attacker. NEAR Intents General Manager Alex Shevchenko said that the protocol’s SHIELD system identified and blocked transfer attempts involving more than $50 million in potentially stolen funds.
However, the amount actually frozen during execution was significantly lower: approximately $503,000. Around $166,000 in suspected stolen assets reportedly completed transfers through NEAR Intents before the relevant controls took effect.
The incident highlights a critical distinction in blockchain security: detecting suspicious activity is not the same as recovering or freezing funds.
What Happened to the Bitget-Linked Assets?
According to Shevchenko, the attacker associated with the Bitget incident stole approximately $387.5 million in digital assets. A substantial portion of those funds was reportedly moved across multiple networks, including transfers into Ethereum.
Cross-chain movement can make tracing and intervention more difficult. Assets may be exchanged, bridged, or routed through different liquidity providers within a short period of time. Once funds reach another chain, investigators and service providers may need to coordinate across several ecosystems, addresses, and infrastructure layers.
NEAR Intents operates as a cross-chain transaction coordination system that allows users to express an intended outcome while relying on third-party solvers to complete the transaction. More information about the architecture is available in the NEAR Intents documentation.
In this case, the SHIELD system reportedly detected more than $50 million in attempted transfers associated with the attacker. Those transactions were subsequently redirected toward other service providers, while only a portion of the assets was frozen during execution.
This difference is important:
- More than $50 million: The value of transfer attempts identified and blocked or disrupted by the system.
- Approximately $503,000: The amount that was actually frozen during transaction execution.
- Approximately $166,000: Suspected stolen funds that reportedly completed transfers through NEAR Intents.
These figures should not be interpreted as proof that the entire $50 million was recovered. They instead demonstrate how transaction screening can interrupt suspicious flows without guaranteeing that every related asset can be immobilized.
NEAR Intents Rejects the Idea That Permissionless Means Neutral
NEAR Intents plans to waive the 5% reward offered by Bitget for freezing the attacker’s funds, as well as an additional 5% reward tied to successful recovery. The stated objective is to maximize the amount ultimately returned to Bitget.
Assets that have already been frozen are expected to be returned through appropriate legal procedures. This approach reflects the growing importance of due process in crypto asset recovery. Freezing funds may be technically straightforward in some cases, but determining ownership, jurisdiction, and the lawful recipient can be considerably more complex.
Shevchenko also argued that permissionless infrastructure does not necessarily require developers to remain neutral toward every type of activity. In his view, protocol builders still make design decisions about which actions their systems will support. Refusing to facilitate the laundering of stolen assets is one such decision.
The debate touches on a broader issue within decentralized finance: whether neutrality should mean “never intervene” or whether protocols should maintain narrowly defined safeguards against clearly identifiable criminal proceeds.
The THORChain Debate: Censorship Resistance Versus Abuse Prevention
The discussion comes as THORChain faces criticism over its handling of funds linked to the Bitget attacker.
THORChain has maintained that its protocol was designed not to selectively censor transactions. It also stated that temporarily pausing the network was an emergency security measure affecting the protocol as a whole, rather than a targeted freeze against a particular wallet or transaction.
This distinction is central to the debate. A protocol-wide shutdown can be viewed as a general risk-control mechanism, while blacklisting a specific address or asset may be seen as selective intervention. Both approaches carry trade-offs:
- Unrestricted settlement can preserve neutrality and censorship resistance.
- Address-level screening may reduce the ability of criminals to liquidate stolen assets.
- Protocol-wide pauses can limit immediate damage but may disrupt legitimate users.
- Legal recovery procedures can protect property rights but may delay restitution.
There is no single technical solution that resolves these tensions. Cross-chain systems must balance user access, security operations, legal obligations, and the principles of decentralization.
Stablecoin Issuers Are Already Part of the Response Layer
NEAR Intents is not the only participant responding to the incident. Circle and Tether reportedly blacklisted a wallet associated with the Bitget attacker and froze approximately $318,000 worth of USDC and USDT.
This demonstrates the unique position of centralized stablecoin issuers within the crypto ecosystem. Although transactions occur on public blockchains, issuers may retain the ability to restrict the movement of their tokens under defined compliance and risk-control policies.
Stablecoin intervention can be effective when stolen funds remain in the original form. However, attackers may attempt to exchange the assets, move them across chains, or route them through decentralized liquidity venues before a blacklist is applied. The speed of settlement therefore remains a major factor in asset recovery.
The Financial Action Task Force’s guidance on virtual assets and service providers also shows how regulators increasingly expect crypto infrastructure providers to address risks related to illicit finance while preserving legitimate innovation.
Why Cross-Chain Security Is Becoming a User Concern
For many users, cross-chain transactions appear simple: select the source asset, choose a destination network, and confirm the operation. Behind that interface, however, multiple components may be involved:
- A wallet signs the user’s transaction.
- A solver or liquidity provider accepts the requested intent.
- Assets may be exchanged or routed through one or more networks.
- Smart contracts settle the transaction.
- Stablecoin issuers, bridges, exchanges, or compliance systems may intervene if a risk signal is detected.
Each additional component creates another potential point of failure or intervention. The Bitget-related transfers show that security is no longer limited to protecting private keys. It also involves transaction monitoring, solver behavior, liquidity controls, address intelligence, and coordination between competing infrastructure providers.
For users, this means that a successful transaction does not automatically indicate that the underlying route was risk-free. A wallet address may be valid, a signature may be correctly generated, and a smart contract may operate as designed while the transaction still interacts with a compromised or sanctioned counterparty.
Permissionless Does Not Mean Risk-Free
The crypto industry has long used permissionless access as a foundation for open financial infrastructure. Anyone can often deploy a contract, create a market, or submit a transaction without asking for approval from a central operator.
That openness provides significant benefits, but it also creates a difficult question: should infrastructure that enables permissionless settlement also prevent the movement of assets that are publicly identified as stolen?
The answer may vary according to the type of system involved. A self-custody wallet, a decentralized exchange, a cross-chain solver network, and a centralized stablecoin issuer do not have the same capabilities or responsibilities.
A practical framework may include:
- Transparent and narrowly scoped intervention policies.
- Public explanations when transactions are blocked or delayed.
- Independent legal review for frozen assets.
- Clear separation between emergency safety controls and permanent censorship.
- Real-time collaboration among wallets, exchanges, bridges, issuers, and analytics providers.
- Better user warnings before signing high-risk or irreversible transactions.
Such measures do not eliminate the philosophical tension between neutrality and intervention. They can, however, make the rules more predictable and reduce the risk that security actions become arbitrary.
What This Means for Crypto Users
The incident offers several practical lessons for anyone using cross-chain applications or managing digital assets.
1. Verify the destination and the route
A transaction can involve more than the visible destination address. Users should review the selected network, token contract, intermediary protocol, and final recipient before signing.
2. Treat cross-chain transfers as higher-risk operations
Bridges, solvers, and liquidity providers introduce additional dependencies. Users should avoid routing large amounts through unfamiliar applications without checking their documentation, security history, and operational status.
3. Use transaction simulation when available
Simulation tools can help identify unexpected contract calls, token approvals, or asset movements before a transaction is finalized. They are not perfect, but they provide an additional layer of review.
4. Limit approval permissions
Unlimited token approvals can increase the impact of a compromised application. Where possible, users should set reasonable spending limits and periodically revoke unused approvals through established tools such as Etherscan’s token approval checker.
5. Protect the signing environment
A hardware wallet can help keep private keys isolated from internet-connected devices and reduce exposure to malware or browser-based attacks. It cannot determine whether a protocol is honest or guarantee that a cross-chain route is safe, but it can make unauthorized key extraction substantially more difficult.
The Broader Direction of Blockchain Security
The Bitget-related incident reflects a wider shift in the digital asset industry. As blockchain infrastructure becomes more interconnected, security responsibilities are moving beyond individual protocols.
In the coming years, users are likely to see greater emphasis on:
- Real-time address and transaction risk screening.
- Cross-chain monitoring and coordinated incident response.
- Solver and liquidity-provider accountability.
- Stablecoin issuer intervention policies.
- Standardized procedures for freezing and returning stolen assets.
- Wallet interfaces that provide clearer signing and counterparty information.
These developments may introduce more friction into decentralized finance, but they may also improve user protection and institutional confidence. The central challenge will be ensuring that safeguards are transparent, proportionate, and resistant to abuse.
The NEAR Intents case does not prove that automated screening can solve crypto theft. It does show that cross-chain systems can detect suspicious flows and, in some circumstances, disrupt the movement of stolen funds. At the same time, the gap between attempted transfers and assets actually frozen highlights how quickly attackers can move value through a fragmented blockchain environment.
For individual users, the most reliable strategy remains layered security: verify every transaction, minimize unnecessary approvals, use reputable applications, and keep private keys protected with a secure signing device. OneKey hardware wallets are designed to keep sensitive key operations isolated from online environments, making them a practical part of a broader self-custody and transaction-verification strategy.



