Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
  • Opinion
    OpinionShow More
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

NEAR Intents Blocked $50M in Bitget Hack Funds, but Only $503K Was Frozen

Attackers shifted rejected funds to other venues as SHIELD stopped $503K mid-swap and NEAR Intents waived a potential $50,300 bounty.

Written By Dishita Malvania
Edited by Divya Mistry
Published 1 hour ago·Updated 7 minutes ago
Make The Crypto Times preferred on GoogleGoogle
NEAR Intents Blocked $50M in Bitget Hack Funds, but Only $503K Was Frozen

NEAR Intents, a cross-chain swap protocol, says attackers behind the September 24 Bitget hack tried to route more than $50 million in stolen assets through its network, but only about $669,000 actually touched its rails. Of that, $503,000 was frozen mid-swap and $166,000 got through. The rest of the attempted volume was refused before any swap began and moved to other venues.

The distinction matters for how the headline number is read. NEAR Intents did not seize $50 million. It declined to process that volume, froze a small slice already in flight, and published the gap between the two outcomes.

AI Summary
Show
Sept 24 hack; attackers attempted $50M cross‑chain swaps via NEAR Intents within days after breach.
By Sept 28, NEAR Intents froze $503K mid‑swap and allowed $166K to complete, rejecting the rest.
Following the freeze, Bitget declined bounty shares and pursued legal recovery of the restricted $503K.

What SHIELD Did

Alex Shevchenko, general manager of NEAR Intents, set out the figures in a September 28 post and accompanying report on X. According to the report, attackers attempted to move more than $50 million through the protocol. After duplicate attempts were removed, $166,000 completed and $503,000 was stopped during execution.

Shevchenko labelled every figure as indicative and rounded, noting that transactions can be mislabelled, and said the true values should not deviate by more than 10%. The analysis drew on Bitget’s public fund tracer, blockchain analytics platform Arkham, internal NEAR Intents logs, SHIELD telemetry, and other open sources.

NEAR Intents is an intent-based protocol. Instead of specifying an exact transaction path, a user states a desired outcome, such as swapping ether on Ethereum for bitcoin, and a network of market makers called solvers competes to fill it, according to the protocol’s documentation. That design creates a control point: a solver can simply decline a job.

SHIELD is the protocol’s risk-intelligence layer. Shevchenko said it detects deviations in flows and draws signals from Know Your Transaction (KYT) providers, independent researchers, companies, and large centralised exchanges. When it flags activity, the protocol can take one of two actions. It can refuse to return a quote, so the swap never starts, or it can halt a swap already underway.

The $50 million-plus figure reflects mostly the first action. The $503,000 reflects the second.

The Numbers in Context

Read together, the three figures tell a narrower story than the headline. Attempted flow exceeded $50 million. Leaked flow was $166,000. Frozen flow was $503,000. Combined, about $669,000 passed into the system, roughly 0.17% of the $387.5 million Bitget has disclosed as transferred to attacker-controlled addresses.

The attempted $50 million represents about 12.9% of the total theft, which indicates how heavily the attackers leaned on cross-chain routers in the days after the breach.

Shevchenko presented the gap as evidence the design worked. He said NEAR Intents routinely clears more than $100 million in cross-chain volume per day, and that only a negligible fraction of the stolen funds came through because SHIELD made the venue costly for known hack flow.

The opposite reading is also supported by his own report. Attackers who receive a refused quote do not stop; they try the next bridge. Shevchenko acknowledged the flagged volume later went to other providers. Screening one router changes the path the funds take. It does not trap them.

Stablecoin issuers ran into the same limit earlier in the week. Circle and Tether blacklisted a wallet labelled “Bitget Exploiter 8,” freezing about 99,990 USD Coin (USDC) and 218,023 Tether (USDT), worth roughly $318,000. The ether (ETH) in that wallet remained movable because issuers can freeze only their own tokens. In the same way, a solver network can refuse a job but cannot freeze assets on the destination chain.

Taken together, the issuer freezes, and the NEAR Intents hold restrict about $821,000, or roughly 0.21% of the disclosed loss.

The Bounty Waiver

Bitget’s Recovery Bounty Program pays 5% of funds frozen through a participant’s voluntary efforts, and a further 5% of funds successfully recovered, as The Crypto Times reported when the exchange published its withdrawal schedule. Shevchenko said NEAR Intents would waive both, so Bitget could recover as much of the stolen funds as possible.

Based on the $503,000 frozen, the waiver is worth at most about $50,300 if the full amount is ultimately returned: roughly $25,150 for the freeze and $25,150 for recovery.

The frozen amount is not a completed recovery. Shevchenko directed Bitget to pursue it through legal and law-enforcement channels. Until that process concludes, the $503,000 is restricted inventory, not returned funds.

Bitget’s Response

Chen replied the same day, thanking NEAR Intents and SHIELD for flagging the attempted laundering flows, freezing $503,000 mid-execution, and declining the bounty share. “This is what permissionless but not ‘facilitating known stolen funds’ should look like,” she wrote, adding that a public chain does not have to choose between openness and excluding hackers.

Her wording echoes the phrase she used days earlier in her public dispute with THORChain, another cross-chain swap protocol.

The THORChain Contrast

Shevchenko’s report lands inside an argument the industry is already having. The Crypto Times reported that THORChain declined Chen’s formal request to refuse service to published attacker addresses, and that stolen assets continued moving into bitcoin through the protocol. THORChain’s position is structural: it does not apply selective address blocks, and past network halts were emergency security measures affecting the whole protocol rather than targeted freezes of individual swaps.

Shevchenko took the opposite position without claiming NEAR Intents is a base-layer blockchain. “Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR,” he wrote. “It does not mean every application or liquidity provider must process every transaction.”

He framed the choice as a matter of builder responsibility. “Refusing to help launder stolen assets is one of ours,” he wrote, adding that “property rights are fundamental to functioning markets.” He argued that an industry seeking recognition of digital property rights cannot at the same time build rails designed to help convert stolen property into cash.

The Critique

Replies to the post split along the same line. One user argued that permissionless does mean neutral, and that this is the point of the design. Another argued that NEAR Intents is not permissionless in the strict sense, because participation by solvers and by Multi-Party Computation (MPC) signing nodes is gated, and SHIELD can revoke access at any time.

That criticism does not dispute that the filter worked. It questions whether the marketing term matches the control structure. Both can be true: NEAR Intents remains open to ordinary users, while SHIELD acts as a discretionary filter at the solver layer. Chen is praising that filter. Neutrality advocates are pointing to it.

Who the Report Addressed

Shevchenko closed with messages to four groups. He told attackers not to use NEAR Intents. He told Bitget to use legal channels for the frozen $503,000. He told wallet providers that integrating routes that move stolen funds exposes their users to legal and reputational risk. He advised hacked teams to contain incidents early, contact incident-response firms such as ZeroShadow or the SEAL 911 security community, and notify exchanges and stablecoin issuers before stolen funds fragment across chains.

The report did not include a transaction-level appendix. No public list of transaction hashes ties each refused intent to a Bitget-labelled wallet cluster. Until such data is released, the $50 million-plus figure should be read as an operator disclosure with a stated 10% margin, not an independently audited result.

What Has Not Changed

The disclosure does not reduce the $387.5 million loss, which Bitget says its User Protection Fund will cover. At the time of the breach, the fund held more than $464 million. Attribution also remains unsettled. 

On-chain investigator ZachXBT has linked the laundering activity to operators working for suspected Democratic People’s Republic of Korea (DPRK), or North Korea, attackers, while Bitget has not released the technical evidence behind its own assessment, as The Crypto Times detailed in its breakdown of how the attackers moved funds.

What the episode does show is that intent-based routing has a control point that automated market maker (AMM) pools and hash-locked bridges often lack: solvers can decline to act. Whether that becomes an industry norm depends on three tests. SHIELD’s false-positive rate, given the stated 10% mislabeling margin, will determine whether it is seen as compliance infrastructure or an arbitrary gate. 

The outcome of the legal process for the $503,000 will show whether the freeze produces an actual recovery. And trading volume over the coming weeks will show whether users treat the filter as a feature or as a reason to route elsewhere, as the Bitget attackers already did.

Also Read: MEXC Confirms $340,000 Loss From API Key, Fully Compensates Affected User

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BitGetCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Anthropic IPO Prospectus Shows $42B Loss as Crypto Pre-IPO Perps Hold Near $2T
Anthropic IPO Prospectus Shows $42B Loss as Crypto Perps Hold Near $2T 
The Dinari, Kakaopay Securities, and Ondo Finance logos displayed side by side on colorful blocks against a textured wall.
Kakao Pay Securities Explores Tokenized Korean Stocks With Dinari, Ondo
An illuminated blue MEXC logo with digital glitch effects on a dark background.
MEXC Confirms $340,000 Loss From API Key, Fully Compensates Affected User
A smartphone displaying the Apple logo positioned in front of an illuminated SlowMist wall logo. JPG
SlowMist Warns Apple Zero-Day May Put Crypto Wallet Data at Risk
A physical Hedera (HBAR) token coin resting on a rugged surface with a financial candlestick chart showing an upward trend in the background.
HBAR Price Soars 22% as Hedera App Lands on IBM Cloud: Can $0.12 Hold?

Find Us on Socials

You may also like

NVIDIA Launches Open Agent Safety Platform as AI Agents Enter Finance 

NVIDIA Launches Open Agent Safety Platform as AI Agents Enter Finance 

Coinbase Wins CFTC Approval to Run Its Own USDC Clearinghouse

Coinbase Wins CFTC Approval to Run Its Own USDC Clearinghouse

Green Tether (USDT) coin with the U.S. Capitol dome and the flag of Iran in the background.

Senate Investigation Finds Widespread Use of Tether’s USDT in Iran-Linked Wallets

Chainlink CCIP 2.0 Goes Live With New Institutional Guardrails, LINK Surges

Chainlink CCIP 2.0 Goes Live With New Institutional Guardrails, LINK Surges

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information