Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

$50 Million in Bitget Hacker Swaps Tests NEAR Intents’ ‘Permissionless’ Claim

A hacker sought to move $50 million through NEAR Intents, and the service stopped a portion, testing its claim of being 'permissionless.'

By mitch·3 min read
A shield-like icon sits amid a glowing blockchain network, symbolizing a service blocking funds tied to a hack.

A hacker group tried to move more than $50 million in swaps through NEAR Intents after Bitget’s $388 million hack, and the service stopped about $503,000 of it, according to a report by NEAR Intents’ general manager Alex Shevchenko.

The figures are estimates and could differ from the actual amounts by up to roughly 10%. About $166,000 passed through the service, with the larger figure representing attempted transfers rather than money recovered. Duplicate attempts were removed from the tally, and rejected funds were subsequently moved through other providers.

What NEAR Intents Actually Blocked

NEAR Intents stopped about $503,000 linked to Bitget’s hack during cryptocurrency swaps, while about $166,000 passed through the service. The restricted funds will remain on hold pending legal and recovery proceedings.

Advertisement

Shevchenko said NEAR Intents routinely processes $100M+ of crosschain trading volume in a day, yet only a negligible fraction of the hacked funds flowed through the service. He added that the SHIELD system automatically detects deviations in flows, collects signals from KYT and intelligence providers, independent research, companies, and largest centralized players, allowing the protocol to decide how to handle a transaction.

Why THORChain Refused to Block

THORChain refused to block attacker addresses, taking a different approach from NEAR Intents. The two services now represent opposing views on what a permissionless network owes to a hack.

The Numbers Behind the Story

Figure Amount
Attempted transfers More than $50 million
Blocked funds About $503,000
Funds that passed through About $166,000
Daily crosschain volume $100M+

Who Called the Claim Into Question

Vini Barbosa, a technical writer and documentation engineer at Ramp Labs, questioned whether NEAR Intents should call itself permissionless. Writing on X, she said, “Permissionless does mean neutral. It’s the whole point of building something ‘permissionless.'”

What NEAR Says Permissionless Actually Means

NEAR Cofounder Illia Polosukhin wrote that permissionless means nobody needs permission to own and transfer assets or deploy contracts on NEAR, but does not require every application or liquidity provider to process every transaction. That distinction is central to how NEAR Intents frames its position.

How the Bounty Offer Works

Shevchenko asked Bitget to contact NEAR Intents through legal and law-enforcement channels and said it would waive its recovery bounty. His report did not name who can authorize the money’s release or explain how someone wrongly flagged could get their funds back.

What Circle and Tether Did

Circle and Tether have frozen about $320,000 in stablecoins linked to the breach, as CoinDesk reported last week. A CoinDesk analysis identified about $6.3 million in completed ether-to-bitcoin swaps from one wallet linked to the Bitget attacker.

The Open Question

The core tension is whether a service calling itself permissionless can fairly hold and release funds caught up in a hack. NEAR Intents argues its SHIELD system stops funds tied to known hacks without operator approval. Critics like Ramp Labs’ Barbosa warn that blocking tools could also stop people resisting government repression.

The paper’s principles favor individual freedom and a light touch on technology. Here the question is not abstract — it is whether a service calling itself open can fairly hold and release funds caught up in a hack.

The test will be how NEAR Intents handles the funds once legal and recovery proceedings are complete.

Source material: “$50 million in Bitget hacker swaps puts NEAR Intents’ ‘permissionless’ claim to the test,” CoinDesk.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.