NEAR Intents has blocked more than $50 million in attempted cross-chain transfers that it linked to wallets involved in the $387.5 million Bitget hack. Summary NEAR Intents says SHIELD blocke
NEAR Intents has blocked more than $50 million in attempted cross-chain transfers that it linked to wallets involved in the $387.5 million Bitget hack.
Summary
- NEAR Intents says SHIELD blocked more than $50 million in Bitget-linked attempted transfers across chains.
- SHIELD froze $503,000 during execution while roughly $166,000 in suspected stolen funds passed through successfully.
- Bitget confirmed approximately $387.5 million reached attacker-controlled addresses after its September 24 exchange security breach.
- THORChain says emergency halt mechanisms protect protocol security but do not selectively freeze individual swaps.
- NEAR Intents says it will waive Bitget’s bounty and return frozen funds through legal processes.
Alex Shevchenko, general manager of NEAR Intents, said on Sept. 29 that the protocol’s SHIELD system identified the flows as suspected stolen funds and prevented them from completing through its infrastructure. NEAR Intents lets users exchange assets between blockchains through a network of solvers.
During execution, SHIELD froze approximately $503,000, while roughly $166,000 in funds suspected of being connected to the theft passed through before being stopped, according to Shevchenko. More than $50 million in transfers rejected by the system subsequently moved toward other service providers.
The disclosure comes five days after Bitget suffered one of 2026’s largest crypto exchange thefts. Bitget confirmed that approximately $387.5 million was transferred to attacker-controlled addresses during the Sept. 24 incident, raising its first estimate of $351.6 million after tracing additional Zcash and Tron assets.
You might also like: Bitget hacker moves $6.3 million into Bitcoin after THORChain rejects freeze request
NEAR Intents says SHIELD rejected stolen funds
Shevchenko described SHIELD as the system NEAR Intents uses to detect potentially illicit activity before swaps are completed. His statement drew a direct distinction between the protocol’s approach and services that allow transactions to proceed without screening individual wallets.
“Refusing to help launder stolen assets is one of ours,” Shevchenko said, arguing that developers of permissionless systems still make decisions about what their infrastructure permits.
He described property rights as necessary for functioning markets and rejected the view that unrestricted movement of stolen assets makes a system more open.
“A financial system where stealing an asset gives you an unrestricted right to monetize it isn’t a freer system,” Shevchenko said. “It is simply a system that protects the thief.”
NEAR Intents plans to forgo the reward Bitget offered participants who help freeze or recover attacker funds. Bitget’s program offers 5% of eligible assets frozen through a participant’s work and another 5% for funds successfully recovered. Bitget’s recovery bounty program covers both asset freezes and successful recoveries, as previously reported by crypto.news.
Shevchenko said the $503,000 frozen during NEAR Intents transactions would instead be returned through an appropriate legal process, leaving a larger amount available for recovery by the exchange.
THORChain rejects selective Bitget hacker freezes
The NEAR Intents statement arrived while THORChain faced requests from Bitget executives and security firms to prevent attacker-controlled wallets from using its cross-chain liquidity.
Bitget CEO Gracy Chen urged THORChain to deny services to identified addresses after investigators traced stolen assets through multiple networks. Some of the stolen crypto has moved into Bitcoin through cross-chain swaps, while other funds remain in wallets linked by investigators to the attack.
In one tracked route, blockchain compliance firm AMLBot found that funds originating on Tron moved through USDT0 to Ethereum before being converted into roughly 145 ETH. The ETH then passed through THORChain and became approximately 4.59 BTC. Around 4 BTC tied to the Bitget theft later entered a Wasabi CoinJoin transaction, according to crypto.news coverage citing AMLBot.
THORChain stated that its protocol does not selectively censor individual transactions by design. The network can be halted during emergencies, but THORChain said those controls apply to protocol security and affect network operations more generally.
Its response said an emergency halt “is not a selective freeze of specific funds or an individual swap.”
Security firm GoPlus has challenged that position, pointing to THORChain’s validator-controlled vaults, Mimir governance controls and ability to halt chain signing. Questions over THORChain’s decentralization intensified as Bitget-linked assets crossed the protocol, with GoPlus arguing that its operational controls differ from base-layer networks such as Bitcoin and Ethereum.
THORChain maintains that the presence of emergency mechanisms does not mean operators should selectively stop externally identified funds.
Stablecoin issuers have already frozen Bitget-linked assets
Centralized stablecoin issuers took a different route after the attack. Circle and Tether blacklisted an Ethereum address linked to the exploiter, freezing 99,990 USDC and 218,023 USDT, or approximately $318,000 combined, according to on-chain information cited in Bitget recovery updates.
Chen thanked both issuers for acting on the addresses and asked exchanges, custodians, bridges and blockchain investigators to participate in the recovery program.
As previously reported, Circle and Tether froze roughly $318,000 of stablecoins linked to the Bitget attacker while the exchange expanded its list of known addresses.
The distinction comes from the architecture of the assets involved. Circle and Tether can blacklist individual token addresses through controls built into USDC and USDT contracts, while protocols such as THORChain and NEAR Intents operate under different transaction and governance systems.
NEAR Intents is not claiming that it can freeze assets across an entire blockchain. Shevchenko’s account concerns transfers attempting to use NEAR Intents itself, where SHIELD can reject activity before the requested exchange completes.
Bitget continues tracing $387.5M stolen in the hack
Bitget detected the first unauthorized transfers at 18:31 UTC on Sept. 24. The exchange later said investigators found that attackers compromised a critical backend component within its wallet infrastructure.
CEO Gracy Chen said attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials, then sent fraudulent withdrawal instructions directly into Bitget’s wallet systems. Private keys were not stolen, according to the exchange, and cold wallets were unaffected.
Bitget said the underlying vulnerability has since been fixed. Independent security firms Mandiant and SlowMist continue assisting with forensic work, asset tracing and recovery. The exchange has not publicly confirmed the identity of the attackers.
Investigators have followed stolen assets across Ethereum and other EVM chains, XRP Ledger, Zcash and Tron. The affected assets include ETH, XRP, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX.
AMLBot estimated on Sept. 25 that around $343 million, or roughly 88% of the funds it was tracking at that point, remained dormant in 13 attacker-linked wallets. Eight Ethereum addresses contained approximately 68,300 ETH, four XRP wallets held around 83 million XRP and another address held close to 18,900 ZEC.
Meanwhile, Bitget has begun restoring withdrawals after completing additional security checks. The exchange scheduled Bitcoin withdrawals for Sept. 28, followed by ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism on Sept. 29. USDT withdrawals are scheduled for Sept. 30, with remaining token, fiat and peer-to-peer withdrawal services expected to return on Oct. 2.
Bitget said its Protection Fund will absorb the financial loss and that customer account balances remain unchanged. Mandiant and SlowMist continue supporting the forensic investigation while the exchange traces attacker wallets and works with industry participants on asset recovery.
Read more: Coinbase can now settle derivatives 24/7 with USDC