NEAR Intents successfully prevented the laundering of more than $50 million linked to Bitget’s recent $387.5 million security breach. General Manager Alex Shevchenko reported that the platform’s SHIELD infrastructure identified and stopped these transfer attempts, though approximately $166,000 evaded detection. In contrast, decentralized exchange protocol THORChain rejected a request from Bitget CEO Gracy Chen to blacklist wallet addresses associated with the attackers, citing its policy against selective transaction censorship.
The breach originated on September 24 when an intruder exploited a zero-day vulnerability in external security software to obtain administrator credentials. The attacker executed two small test transactions below risk thresholds before launching 17 large withdrawals across eight networks, totaling roughly $361 million. Bitget suspended all customer withdrawals seven minutes after detecting discrepancies. While private keys remained secure, the exchange is collaborating with Mandiant and SlowMist for forensic analysis. Circle and Tether also froze a connected wallet holding $318,013 in stablecoins.
This incident highlights the divergent operational philosophies within the crypto infrastructure sector regarding asset recovery and compliance. NEAR Intents’ proactive intervention demonstrates how centralized or semi-centralized cross-chain protocols can act as effective chokepoints for illicit flows, prioritizing victim restitution over absolute neutrality. Conversely, THORChain’s refusal to censor specific transactions underscores the persistent tension between permissionless network principles and the practical demands of post-hack mitigation. This split suggests that future regulatory frameworks may need to distinguish between different types of decentralized infrastructure based on their capacity and willingness to enforce anti-money laundering standards.
From a market structure perspective, the reliance on internal administrative interfaces and external security software remains a critical vulnerability vector for exchanges. The fact that cold storage was untouched indicates that hot wallet management and API security are currently the primary attack surfaces. Investors and institutions should monitor whether this event accelerates the adoption of stricter custody solutions and real-time anomaly detection systems. Additionally, the decision by NEAR to forgo bounty rewards sets a precedent for cooperative security efforts, potentially influencing how other protocols respond to similar requests in the future.


