NEAR Intents system intercepts most of $50M attempted from Bitget hack, but not all
Security & Exploits ·
Aurora co-founder says a risk-detection tool caught the bulk of stolen funds routed through NEAR, while a separate protocol declined to do the same.
Attackers behind the September 24 breach of Bitget tried funneling more than $50 million through NEAR Intents, according to Aurora co-founder Alex Shevchenko, as detailed in a report from wublockchain. The platform's SHIELD monitoring layer flagged the activity, though roughly $166,000 still made it through before detection, while about $503,000 was halted mid-transaction and remains frozen pending legal review. Shevchenko put the total value lost in the hack at approximately $387.5 million, noting that most of the diverted assets across chains were eventually funneled into ETH on Ethereum.
The incident highlights a tension in decentralized infrastructure between staying open to all users and intervening against funds known to be illicit. Bitget's chief executive, Gracy Chen, said NEAR Intents agreed to give up its portion of any recovery bounty tied to the case, a move meant to let Bitget reclaim a larger share of the stolen assets. Chen argued that permissionless networks are not necessarily forced to pick between openness and screening out flagged funds, suggesting that detection mechanisms can operate without shutting out unrestricted access. She said Bitget would pursue formal legal channels and asset-recovery procedures going forward.
Not every network handling the hack's proceeds has taken the same approach. A parallel case involving THORChain shows the protocol declining to block roughly $387.5 million in funds tied to the same breach as they moved through its swap infrastructure, drawing criticism over what obligations, if any, permissionless systems bear toward halting known stolen assets, according to coverage from CryptoPotato. The contrast between NEAR's intervention and THORChain's inaction has become a reference point in the broader argument over whether decentralized platforms should build in filtering capability at all.
What remains unclear is how much of the $387.5 million total will ultimately be recovered through legal or cooperative channels, and whether other protocols that processed hack-related flows will adopt similar detection measures. It is also not yet established what legal outcome will apply to the $503,000 currently frozen, or how consistently exchanges and networks will coordinate on bounty terms in future incidents of this kind.