Following a suspected North Korean hacker attack on crypto exchange Bitget that resulted in $387.5 million in stolen funds, Bitget CEO Gracy Chen publicly demanded that decentralized cross-chain swaps platform THORChain refuse service to the recipient addresses. THORChain responded by highlighting its permissionless nature and lack of an admin key, which prevents it from easily censoring specific transactions. This stance contrasts with NEAR Intents, which utilized its automated SHIELD program to block addresses linked to the hack from swapping $50 million on its platform, even declining a 5% bounty offered by Bitget for doing so.
The controversy revisits previous incidents where THORChain was used to swap approximately $1.2 billion of funds stolen in the $1.46 billion Bybit hack, occurring just 11 days after THORChain retired its admin key. Yuriy Brisov from D&A Partners noted that while blocking malicious activities benefits the community, demonstrating control opens protocols to legal claims regarding due diligence, KYC, and AML obligations. Conversely, maintaining strict decentralization serves as a strong legal defense, similar to the dismissal of investor lawsuits against Uniswap in March. The debate centers on whether technical immutability or automated compliance tools provide better protection against liability for facilitating illicit fund movements.
The tension between operational security and regulatory compliance is starkly illustrated by the divergent responses of THORChain and NEAR Intents. THORChain’s reliance on its retired admin key and hundred validators creates a technical barrier to censorship, reinforcing its claim to true decentralization. However, this rigidity exposes the protocol to reputational risk if perceived as aiding money laundering, despite legal arguments that smart contracts are not property under US law. The precedent set by Tornado Cash suggests that immutable code offers some protection against sanctions, but the evolving definition of 'control' in DeFi remains legally ambiguous.
NEAR Intents’ approach highlights a potential middle ground where automated systems like SHIELD can enforce compliance without human intervention, thereby preserving a degree of decentralization while mitigating misuse. Yet, this strategy invites criticism from decentralization advocates who view any form of address blocking as a violation of permissionless principles. As regulators scrutinize market structure, protocols must navigate the fine line between being good-faith actors preventing fraud and entities exercising control that triggers broader liability for pump-and-dump schemes or other investor harms. The outcome of these debates will likely shape future institutional adoption and regulatory frameworks for cross-chain infrastructure.


