NEAR Intents Blocks $50M in Bitget Hack Flows

NEAR Intents Blocks $50M in Bitget Hack Flows

NEAR Intents says its SHIELD risk system identified more than $50 million in attempted transfers linked to the September 24 Bitget security breach, rejecting most of those flows before they completed through its cross-chain execution network. About $503,000 was restricted during execution, while approximately $166,000 successfully passed through. The $50 million figure represents attempted routed volume rather than assets seized or recovered by NEAR Intents.

NEAR Intents General Manager Alex Shevchenko said duplicate attempts had been removed from the calculation and cautioned that the figures were rounded estimates with potential attribution error of roughly 10%. Bitget separately confirmed that approximately $387.5 million was transferred to attacker-controlled addresses during its breach. The incident provides a live test of how an intent-based routing system can selectively refuse transactions while the underlying blockchains remain permissionless.

SHIELD Rejects Routes Without Controlling User Wallets

NEAR’s official SHIELD documentation describes the system as a policy layer that evaluates requests against incidents, anomaly signals and security conditions before execution proceeds. Current controls include quote-time evaluation, delays and scoped responses, with permissions that can target chains, tokens, addresses or destinations. SHIELD can restrict access to NEAR Intents execution paths, but it does not give the protocol unilateral control over assets held in external wallets or across every connected blockchain.

That distinction explains why most of the $50 million was blocked from using NEAR Intents rather than frozen onchain. Rejected flows remained under attacker control and could seek other liquidity providers. The episode follows expanding cross-chain activity through NEAR Intents, including substantial Zcash routing. Risk screening can reduce the usefulness of one execution venue to an attacker without preventing the same assets from moving elsewhere.

The model contrasts with permissionless protocols that avoid transaction-specific intervention. Stolen Bitcoin from the Coldcard exploit, for example, later moved through THORChain and CoinJoin, illustrating how cross-chain routing can complicate asset tracing once funds remain freely movable. NEAR Intents has explicitly chosen to place policy controls at its application and liquidity-routing layer rather than changing the permissionless nature of the underlying chains.

Frozen Funds Move Into Legal Recovery Process

Shevchenko said the approximately $503,000 intercepted during execution will remain restricted pending legal and asset-recovery procedures. NEAR Intents also plans to waive its entitlement under Bitget’s bounty program, which offers eligible participants 5% for funds successfully frozen and an additional recovery reward under defined conditions. Blocking a swap and returning assets to a victim are separate processes, because final recovery requires determining ownership and following the appropriate legal procedure.

The case adds another layer to cross-chain security, where routing controls increasingly sit alongside bridge and verifier defenses. Recent incidents such as the Verus-Ethereum bridge exploit and the KelpDAO-LayerZero dispute over a $292 million exploit exposed risks in validating cross-chain movement itself. NEAR Intents instead highlights a different control point: deciding whether known or suspected stolen assets should receive liquidity and execution services after an exploit has already occurred.

The next concrete milestone is the disposition of the restricted $503,000 and publication of any additional recovery accounting from Bitget and NEAR Intents. Those outcomes will show how effectively SHIELD can move from transaction rejection to verifiable asset recovery, while also clarifying the operational boundaries NEAR Intents places around its permissionless infrastructure.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px