NEAR Intents blocked more than $50 million in attempted transfers associated with the Bitget hack, while its security system froze about $503,000 during the execution of suspicious swaps, according to a Monday post by NEAR Intents General Manager Alex Shevchenko.
The intervention came after the September 24 Bitget security breach, which the exchange now estimates resulted in about $387.5 million in stolen assets. The attackers subsequently moved portions of the funds across multiple blockchains in an effort to convert and transfer the assets.
NEAR Intents said its SHIELD security system identified the suspicious transfers and rejected most of the attempted transactions before they entered its liquidity network. However, about $166,000 in suspected stolen funds still passed through the protocol.
NEAR Intents SHIELD Blocks Most Attempted Transfers
SHIELD is the risk-monitoring system used by NEAR Intents to identify potentially illicit transactions. According to NEAR Intents General Manager Alex Shevchenko, the system identified more than $50 million in attempted transfers associated with wallets linked to the Bitget attacker.
Those rejected transactions were later routed toward other service providers. The $50 million figure therefore does not represent funds that NEAR Intents seized or froze.
The protocol said approximately $503,000 actually entered an active transaction and was frozen during execution, while roughly $166,000 completed successfully before the suspicious activity could be stopped. The figures are estimates and may contain some attribution errors.
$503,000 Remains Frozen
The approximately $503,000 that was frozen during the swaps remains restricted while Bitget works through the recovery process.
NEAR Intents said it will waive the recovery bounty offered by Bitget, allowing more of the recovered funds to remain available to the exchange.
Bitget had offered a 5% bounty for freezing stolen assets and another 5% for recovering them. NEAR Intents said it would not claim either payment. The frozen funds are expected to be handled through the appropriate legal and recovery process.
Bitget CEO Gracy Chen thanked NEAR Intents and SHIELD for identifying the attempted transfers, freezing funds and giving up its potential bounty share.
Bitget Hackers Continue Moving Funds Across Chains
The NEAR Intents intervention is part of a wider effort to track the assets stolen from Bitget.
The exchange initially reported about $351.6 million in losses before revising the figure to approximately $387.5 million after identifying additional transfers involving other networks. Bitget has said its own users’ balances remain unaffected and that its protection fund will cover the loss.
Blockchain tracking has shown the stolen assets moving between networks as the attacker attempts to convert them into different cryptocurrencies.
On September 28, an address linked to the attacker reportedly used THORChain to swap about 2,390 ETH worth roughly $6.3 million into 75.2 BTC. The activity has added pressure on cross-chain protocols to decide how they should handle funds linked to known hacks.
NEAR Intents and THORChain Take Different Approaches
The response from NEAR Intents has also highlighted a debate over what permissionless means for cross-chain protocols.
NEAR Intents has chosen to screen individual transactions through SHIELD and reject transfers it identifies as connected to stolen assets.
THORChain, meanwhile, has defended its approach of not selectively blocking individual addresses. The protocol has emergency controls that can halt broader network activity, but it says those mechanisms are not designed to freeze a specific wallet or individual swap.
The difference shows the challenge facing decentralized infrastructure: protocols can allow users to move assets without traditional account controls while still deciding whether to restrict transactions associated with known criminal activity.
Shevchenko argued that refusing to help move stolen assets does not require abandoning permissionless infrastructure.
Bitget Continues Restoring Withdrawals
The intervention comes as Bitget restores withdrawal services following the security breach. The exchange resumed Bitcoin withdrawals on September 28, with ETH withdrawals scheduled to return across several networks on September 29.
USDT withdrawals are scheduled to follow on September 30, while other assets and services are expected to return later.
Bitget said the vulnerability involved in the incident had been identified and fixed. The exchange has also been conducting additional security checks with external security firms.
The withdrawal suspension was described as a security measure rather than a liquidity problem, with Bitget maintaining that user account balances were not affected.
What Comes Next
NEAR Intents will continue monitoring transactions linked to the Bitget exploit, while Bitget works through the legal process to recover frozen assets. Blockchain investigators are also tracking where the remaining stolen funds move as the attacker uses bridges, swap protocols, and other services.
The incident could also influence how cross-chain protocols approach suspicious transactions. NEAR Intents’ response shows one model in which permissionless infrastructure can still use automated screening, while THORChain’s position highlights a different approach that avoids selective freezes.
What This Means for You: NEAR Intents says it stopped more than $50 million in attempted Bitget-linked transfers, but only about $503,000 was actually frozen and roughly $166,000 passed through. The incident highlights why stolen crypto can move quickly between blockchains and why users should verify wallet addresses and avoid interacting with funds connected to known hacks.

