A protocol that swaps assets between blockchains has stopped the outflow of stolen funds: NEAR Intents says it blocked more than $50 million in swap attempts attributed to the attack on crypt
A protocol that swaps assets between blockchains has stopped the outflow of stolen funds: NEAR Intents says it blocked more than $50 million in swap attempts attributed to the attack on crypto exchange Bitget. The team froze $503,000 mid-execution, and around $166,000 slipped through. For you as an investor this is not a price story but a question about your own custody: who can stop funds that belong to you, and what follows from that for your choice of exchange and wallet?
The figures come from an account by NEAR Intents reported by CoinDesk, among others, on 29 September 2026. The team itself describes them as estimates with a possible margin of ten percent, with duplicate attempts stripped out. That caveat belongs to the story, because sums in cases like this only become reliable once investigators have confirmed the addresses.
What NEAR Intents actually blocked in the Bitget case
NEAR Intents is a protocol on NEAR that lets assets be swapped across chains without the user opening an account at an exchange. Services of exactly that kind are attractive to someone who wants to move large sums out of a breach and break the trail in the process: swapping ether for bitcoin across two chains makes tracing far more laborious than a transfer within a single chain.
Three numbers describe what happened. First, more than $50 million in transfer attempts were rejected before they were executed. Those attempts did not vanish; according to the team they moved on to other providers. Second, $503,000 was stopped and frozen during execution. Third, around $166,000 in presumed stolen funds passed through the system before the filters caught up.
A fourth detail is notable and has nothing to do with technology. Bitget had offered a bounty: five percent for freezing attacker funds and another five percent for recovering them. NEAR Intents says it is waiving both, so that a larger share flows back to the exchange. The frozen amounts are to be returned through a regular legal process, not by a transfer between the parties involved.
SHIELD: how the filter system sorts out suspicious swaps
SHIELD is the monitoring system NEAR Intents has placed in front of its protocol. Alex Shevchenko, general manager of NEAR Intents, describes how it works: the system automatically detects deviations in the flows and gathers numerous inputs from KYT and intelligence providers in order to decide, on those signals, how a transaction is handled.
KYT stands for “know your transaction” and refers to the ongoing screening of individual transactions against known risk addresses and suspicious patterns, as distinct from the one-off identity check of a customer when an account is opened. Analytics firms maintain databases of such addresses, and a protocol can query those lists before it executes a swap.
What a filter like this can do and what it cannot
A filter of this kind works with probabilities. It recognises addresses already flagged as tainted, and it recognises atypical patterns: unusually large amounts, rapid chains of small partial transfers, movements shortly after a known incident. What it does not deliver is a guarantee. The $166,000 that ran through is the documented proof of that, and the team names it itself.

Stolen funds move between chains until a trail breaks off: that is exactly where filter systems such as SHIELD step in.
The Bitget attack of 24 September and the route the funds took
The starting point is a breach at crypto exchange Bitget that became known on 24 September 2026. Depending on the source, the loss is put at $387.5 million to $388 million; the attackers bypassed security controls on exchange wallets. A substantial part of the funds subsequently moved cross-chain to Ethereum.
How hard such funds are to stop was already visible in the same incident: the attacker moved around $83 million in XRP onward without Ripple being able to block it, because the network provides no mechanism for that (we described the limits of freezing stolen coins on 27 September). The NEAR Intents case is the counterpoint: here it was not a chain that failed, but a service on top of it that decided to reject orders. Bitget itself recorded net outflows of $463 million in the same days and pointed to its protection fund.
Stablecoin issuers intervened as well. According to the available reports, Circle and Tether together froze around $320,000 in USDC and USDT attributed to the breach. Measured against the total that is little, but it shows where an intervention is technically easiest.
“Permissionless” with limits: how the NEAR founders justify it
The episode touches a promise open protocols set out with. Permissionless means nobody has to ask for permission to use a protocol: no registration, no approval, no doorman. When such a protocol rejects transactions, that sounds at first like a contradiction.
Illia Polosukhin, co-founder of NEAR, draws the line differently. In substance, his account is that permissionless means nobody needs permission to own and transfer assets; it does not mean that every application must process every transaction. Shevchenko puts it as a commitment: NEAR Intents remains permissionless infrastructure, but with limits.
You do not have to share that distinction to see what it means in practice. The idea shifts the permission question from the base layer, the blockchain itself, up to the application layer above it. The chain still executes every valid transaction. The service that offers you the convenient swap no longer necessarily does.
THORChain let $6.3 million through: two answers to the same situation
That this is a decision rather than a technical constraint is shown by the comparison. According to CoinDesk's account, THORChain declined to block attacker addresses; swaps from ether into bitcoin worth around $6.3 million were completed there through a linked wallet.
Both houses run similar technology and decide in opposite directions. One protocol puts the recovery of stolen customer funds above censorship resistance, the other the reverse. From that contrast comes a sober conclusion for you: whether a service can stop funds is not a property of the blockchain but a house rule of the provider in question.
The flip side: false positives hit uninvolved people
A filter that works on probabilities inevitably produces false hits too. Anyone who received coins through an address later flagged as tainted can get stuck on a swap without having anything to do with the incident. For those affected this is not a theoretical risk but a blocked amount and a drawn-out proof of origin.

Frozen does not mean returned: the $503,000 is to go to Bitget through a legal process.
Stablecoins are the easiest assets to freeze
The amounts Circle and Tether locked down are small, but the mechanism behind them is fundamental. USDC and USDT are tokens whose issuers have written a blocking function into the contract. That makes it possible to immobilise a balance at a particular address without anyone having to halt the blockchain.
Bitcoin and ether have no such function. Anyone wanting to intervene there has to act at the transition points: at exchanges, at bridges, at swap protocols such as NEAR Intents. That explains why the bulk of the $388 million is still in motion while, of all things, the smallest position was locked down fastest.
For how you split your own portfolio, that is a piece of information rarely spelled out. A stablecoin is a claim against an issuer who can enforce it technically. A bitcoin in your own custody is not. Both have their place, but they are different things.
Self-custody: seed phrase, hardware wallet and the limit of an exchange
The Bitget case and the response to it come down to the same old sentence, made more concrete by every new incident: coins sitting on an exchange are a claim against that company. If it is breached, repayment depends on a protection fund, on insurance and on the provider's willingness.
A hardware wallet is a device that generates and stores the private key without ever handing it to a connected computer. The seed phrase is the sequence of words from which that key can be derived again at any time; it is the actual proof of ownership and never belongs in a cloud, in a photo or in a messenger message. Which devices differ in handling, price and supported coins is set out in our hardware wallet comparison.
One qualification belongs with this: self-custody shifts the risk, it does not erase it. Lose the seed phrase and there is no customer service. For amounts you trade regularly an exchange remains practical; the question is how much sits there permanently.
Choosing an exchange in Germany: licence, protection fund and evidence
Since the transition period ended, every provider addressing retail customers in Germany needs an authorisation under the EU regulation MiCA. That authorisation is no protection against a breach, but it brings obligations: own-funds requirements, separation of client and proprietary holdings, complaint channels and a supervisor who is a point of contact in a dispute.
Three details are worth a look before larger amounts move onto an account: whether the provider holds a MiCA authorisation in an EU state and which authority granted it; whether client holdings are kept separate from proprietary holdings; and whether there is a protection fund, including the size of it. Which houses disclose all three and which name only two of them differs markedly from provider to provider.
NEAR price at $5.11: what separates the protocol from the token
NEAR was quoted at around $5.11 on 30 September 2026, up roughly 6.5 percent over 24 hours and around 16 percent over the week (source: CoinGecko, 30 September 2026). Market observers put that mostly down to attention for projects with an AI angle and to the launch of a NEAR exchange-traded product in the United States; there is no documented connection to the SHIELD announcement.
That separation matters. Blocking stolen funds says something about how a protocol works and nothing about the fair price of a token. Deriving a price forecast from a security announcement confuses two different questions.
Blocked hacker funds: the key points for your decision
- Split your holdings. Decide which amount sits permanently in self-custody and which stays on an exchange for trading. For the permanent part the route runs through a device from the hardware wallet comparison and a seed phrase that exists only on paper or metal.
- Look up your trading venue. Check whether your provider holds a MiCA authorisation, which authority granted it and whether a protection fund is disclosed. The overview of regulated crypto exchanges lists these details house by house.
- Understand the house rules of swap services. If you swap across chains, know that the service may reject transactions and that false hits occur. If you swap often, it makes sense to hold the amounts needed for it in your own wallet rather than on the trading venue; the differences are shown in the software wallet comparison.
The larger line behind the episode: the argument over whether open protocols should stop stolen funds is not settled. NEAR Intents and THORChain acted in opposite ways in the same case, and both justify it with the same principle. As long as that holds, the answer to “can someone stop my money?” is not a property of the technology but a property of the provider you have chosen. That choice is yours, and it is the part you can influence. Further detail on the team's account can be found in the reporting by Cointelegraph.
(As of September 30, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)