NEAR Intents reported that attackers behind the September 24 Bitget hack attempted to route more than $50 million in stolen assets through its cross-chain swap protocol. General Manager Alex Shevchenko stated that SHIELD, the protocol’s risk-intelligence layer, detected deviations and refused quotes for most of the volume, preventing swaps from starting. Of the approximately $669,000 that actually entered the system, $503,000 was frozen mid-swap, while $166,000 completed execution. The remaining attempted funds were redirected to other venues.
The figures are indicative and rounded, with a stated margin of error under 10%, derived from Bitget’s public fund tracer, Arkham analytics, and internal logs. Combined with stablecoin issuer freezes totaling roughly $318,000, restricted assets amount to about $821,000, or 0.21% of the disclosed $387.5 million loss. NEAR Intents waived its right to a 5% recovery bounty, valued at up to $50,300, to facilitate legal recovery efforts by Bitget.
This incident highlights the operational limits of intent-based routing protocols in combating large-scale theft. While NEAR Intents successfully utilized its solver network as a control point to refuse service to known malicious addresses, the actual financial impact was minimal compared to the headline attempt. The protocol froze only $503,000 out of a $387.5 million breach, demonstrating that screening one router merely shifts laundering paths to other bridges rather than trapping funds. This underscores the fragmented nature of crypto infrastructure, where individual compliance measures cannot stop capital flight across decentralized networks without coordinated, universal enforcement.
From a regulatory and institutional perspective, the waiver of the recovery bounty signals a strategic alignment with centralized exchanges and law enforcement priorities. By prioritizing the return of funds over profit, NEAR Intents positions itself as a compliant infrastructure provider, distinguishing its model from protocols like THORChain that maintain strict neutrality. However, the reliance on discretionary filters raises questions about the definition of permissionlessness. As the industry debates whether builders have a responsibility to exclude illicit flows, the effectiveness of such measures will depend on their consistency and transparency, particularly given the lack of independent audit data for the reported figures.


