NEAR Intents Says SHIELD Blocked $50M in Bitget Hack Transfers

Daily Feed
NEAR Intents Says SHIELD Blocked $50M in Bitget Hack Transfers

NEAR Intents says its SHIELD system blocked more than $50 million in attempted transfers tied to wallets linked to the Bitget exploit, while a smaller amount of suspected stolen funds still slipped through before being stopped. It is another ugly reminder that crypto’s “open rails” can move value fast, for honest users and thieves alike.

  • NEAR Intents says SHIELD blocked more than $50 million in attempted cross-chain transfers linked to the Bitget hack.
  • Bitget’s updated loss estimate is $387.5 million, up from an earlier $351.6 million figure.
  • Circle and Tether froze about $318, 000 in stablecoins tied to one attacker-linked wallet.
  • The real fight is policy, not just plumbing: how much should crypto infrastructure do to stop laundering?

According to NEAR Intents, SHIELD flagged the flows as suspected stolen funds and stopped more than $50 million in attempted transfers. The protocol also says it froze about $503, 000 during execution, while roughly $166, 000 in suspected stolen funds passed through before being halted. The rejected transfers later moved toward other service providers, which is exactly the sort of messy relay race criminals love and investigators hate.

Bitget’s breach is the larger crime scene here. The exchange said the Sept. 24 incident resulted in roughly $387.5 million being transferred to attacker-controlled addresses, revising an earlier estimate of $351.6 million after tracing additional assets. Bitget said the first unauthorized transfers were detected at 18:31 UTC on Sept. 24.

The company says attackers compromised a critical backend component within its wallet infrastructure. Bitget CEO Gracy Chen said the attackers exploited a vulnerability in a third-party security product to obtain high-level internal credentials. Bitget also said private keys were not stolen and cold wallets were unaffected.

That distinction matters. If attackers can tamper with the systems that authorize or route transfers, they may not need the keys at all. They just need enough control over the machinery to tell it to lie for them. That kind of failure makes “we didn’t lose the keys” sound less like a comfort and more like a technicality.

Bitget has been tracing the stolen assets across Ethereum, other Ethereum-compatible networks, the XRP Ledger, Zcash and Tron. The affected assets include ETH, XRP, USDT, USDC, USDT0, ZEC, XAUt, BNB, AVAX and TRX.

AMLBot also tracked one route where funds moved from Tron through USDT0 to Ethereum, became about 145 ETH, then passed through THORChain and ended up as roughly 4.59 BTC. In a later step, around 4 BTC tied to the theft reportedly entered a Wasabi CoinJoin transaction, which makes tracing harder by mixing inputs from multiple users.

That is the practical reality of laundering on-chain. Cross-chain transfers are useful infrastructure when normal people are trying to move assets efficiently. They are also a great way for thieves to break the paper trail before anyone can piece it back together.

Bitget has responded with a bounty program offering 5% of eligible assets frozen and another 5% for funds successfully recovered. The exchange says it is working with Mandiant and SlowMist on forensics, asset tracing and recovery, and that its Protection Fund will absorb the financial loss while customer balances remain unchanged.

Withdrawals were scheduled to resume in stages, with Bitcoin withdrawals on Sept. 28, ETH withdrawals on Ethereum, BSC, Arbitrum, Base and Optimism on Sept. 29, USDT withdrawals on Sept. 30, and the remaining token, fiat and peer-to-peer withdrawals expected on Oct. 2.

The bigger argument, though, is not just about Bitget. It is about what “permissionless” should mean when stolen money is moving fast. NEAR Intents says its answer is simple: refusing to help launder stolen assets is part of the job.

“Refusing to help launder stolen assets is one of ours.”
“A financial system where stealing an asset gives you an unrestricted right to monetize it isn’t a freer system. It is simply a system that protects the thief.”

That is a direct shot at the idea that neutrality must include helping criminals cash out. It does not. “Permissionless” means users do not need a gatekeeper to join or transact. It does not automatically mean protocols should provide a free laundering lane for anyone with stolen funds and enough gas fees.

THORChain’s response sits on the other side of that divide. The protocol said an emergency halt “is not a selective freeze of specific funds or an individual swap.” That is an important distinction. Refusing selective freezes is not the same thing as knowingly helping launder stolen money, but it does show how hard crypto’s decentralization debate gets when real theft is involved.

Circle and Tether took the opposite approach, and their action shows both the power and the limits of centralized stablecoins. The issuers blacklisted an Ethereum address linked to the exploiter and froze 99, 990 USDC and 218, 023 USDT, about $318, 000 combined.

Useful? Absolutely. Enough? Not even close.

Stablecoin issuers can freeze the tokens they control. They cannot freeze ETH or BTC at the protocol level. That means once stolen funds are swapped into native assets, bridged across chains, or pushed through privacy tools, recovery becomes far less likely. The freeze is a brake, not a cure.

That is why the Bitget incident matters beyond one exchange’s security headache. It shows how on-chain transparency, blacklists, cross-chain routing, and selective blocking all interact when a major theft hits the public rails. Transparency helps investigators follow the money. It does not, by itself, get the money back.

Key takeaways and questions

  • What did NEAR Intents say it blocked?
    It says SHIELD blocked more than $50 million in attempted transfers tied to wallets linked with the Bitget exploit, while freezing about $503, 000 during execution.
  • How big was the Bitget breach?
    Bitget says about $387.5 million was transferred to attacker-controlled addresses, up from an earlier estimate of $351.6 million after additional tracing.
  • Did Circle and Tether freeze any of the stolen funds?
    Yes. They blacklisted one linked Ethereum address and froze 99, 990 USDC and 218, 023 USDT, or about $318, 000 combined.
  • Why didn’t that solve the problem?
    Most of the value was not sitting in freezeable stablecoins. Once assets are swapped into ETH, BTC, or other native tokens, issuer-level blacklisting no longer applies.
  • Why is THORChain part of the debate?
    Because attackers used cross-chain routes to move funds, and THORChain says it will not selectively freeze specific funds or swaps.
  • What does this say about “permissionless” crypto?
    Permissionless systems are powerful, but they are not morally neutral when they actively help launder stolen money. The real challenge is building infrastructure that stays open without becoming a thief’s exit ramp.

Bitget is still cleaning up a major mess, investigators are still tracing funds, and the wider crypto industry is still arguing over where neutrality ends and complicity begins. The tech is fast. The money is fast. Unfortunately, so are the criminals.

Further reading

For more on exchange security, stolen-funds tracing, and the messy politics of crypto’s “open rails, ” these are worth a look:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog