The two protocols at the center of this controversy—NEAR Intents and THORChain—represent the opposing poles of modern blockchain architecture. NEAR Intents, which routes transactions through a network of solvers, chose to actively intercept and block over $50 million in attempted transfers linked to the stolen funds. Conversely, THORChain, the industry’s largest decentralized swap network, processed approximately $6.3 million in ether-to-bitcoin swaps originating from wallets associated with the attack, explicitly rejecting requests from Bitget to blacklist the malicious addresses.
A Chronology of the Breach and Subsequent Flow
The incident began last week when an unauthorized actor drained $388 million from Bitget, one of the world’s largest crypto exchanges. Following the theft, the attacker immediately sought to obfuscate the origin of the funds by pushing them through various decentralized swap services.
By mid-week, the stolen assets began hitting cross-chain liquidity providers. NEAR Intents, utilizing its proprietary screening system known as SHIELD, identified the incoming transactions as tainted. According to a report published by General Manager Alex Shevchenko, the system successfully froze approximately $503,000 mid-transaction. An additional $166,000 reportedly slipped through before the automated screening protocols caught up with the specific wallet signatures. In total, Shevchenko estimates that the platform blocked $50 million in attempted transfers, a figure that excludes duplicates and accounts for a roughly 10% margin of error.
In stark contrast, THORChain continued to operate without intervention. The protocol, which facilitates trustless cross-chain swaps, processed millions of dollars in ether-to-bitcoin conversions despite public pleas from Bitget executives to intervene. For THORChain, the refusal to act was presented as a fundamental adherence to its design philosophy.
The Mechanism of Surveillance in Decentralized Systems
The technical capability to block funds on a decentralized platform is not a static feature but a deliberate architectural choice. SHIELD, the mechanism employed by NEAR Intents, functions by cross-referencing quote flows against real-time AML data provided by institutional-grade security firms, including TRM Labs, AMLBot, PureFi, and Binance. By integrating these external data streams with an internal AML database, the protocol can make near-instantaneous decisions to halt transactions that deviate from acceptable risk profiles.
Shevchenko highlighted that the screening process had a negligible impact on the platform’s overall health. With daily volumes routinely exceeding $100 million, the $50 million in blocked attempts represented a fraction of the total activity. This challenges the long-standing industry narrative that cross-chain infrastructure is structurally incapable of stopping stolen funds due to the absence of centralized custodians. The Bitget case proves that where there is a brief moment of custody during a swap, there is an opportunity for intervention.
Divergent Philosophies: Neutrality vs. Compliance
The divide between these two services has sparked a wider conversation about the definition of "permissionless" technology. Supporters of the THORChain model argue that any form of intervention constitutes a slippery slope. Vini Barbosa of Ramp Labs noted on social media that if a rail is willing to restrict users suspected of theft, it implicitly creates a mechanism that could eventually be used to suppress individuals operating under authoritarian regimes or those whose assets are targeted for political reasons.
However, the leadership at NEAR Intents defends its position by distinguishing between access to the network and access to assets. Cofounder Illia Polosukhin argued that "permissionless" refers to the right to own, transfer, or deploy contracts without seeking external approval. By this definition, implementing "boundaries" via automated screening does not violate the core tenets of the protocol, but rather secures the environment for institutional participants.
THORChain, for its part, remains steadfast. The protocol stated via X (formerly Twitter) that it does not engage in selective freezing of specific funds. Its representatives pointedly asked why base-layer protocols like Bitcoin, Ethereum, and the BNB Chain—which also carried the stolen funds—are not subjected to the same pressure to blacklist addresses. THORChain also noted that it did not blacklist the addresses responsible for the theft of $10.7 million from its own vaults in May, maintaining consistency in its "no-censor" approach.
The Role of Stablecoin Issuers
While the debate rages over the role of swap protocols, the most effective "circuit breakers" remain the stablecoin issuers themselves. During the Bitget breach, Circle and Tether successfully froze approximately $320,000 in USDC and USDT associated with the attacker. Unlike decentralized swap networks, these issuers maintain central control over their smart contracts, allowing them to blacklist specific wallet addresses at the asset level. While $320,000 is a small portion of the $388 million loss, this intervention highlights that, in the current crypto ecosystem, the most reliable enforcement mechanism remains centralized authority.
Implications for the Future of DeFi
The $503,000 held by NEAR Intents is currently in a state of limbo, awaiting a formal recovery process. The protocol has directed affected parties to use a Kodex law-enforcement portal, but the lack of a transparent, public-facing policy for returning funds to wrongly flagged users remains a significant concern.
The industry now faces a critical inflection point. Institutional capital—the primary driver of the current bull market—is increasingly demanding "clean" liquidity rails. Platforms that prioritize strict compliance and screening, like NEAR Intents, are positioning themselves as the preferred infrastructure for regulated entities. Meanwhile, protocols that hold to a purist vision of censorship resistance, like THORChain, remain the preferred tools for users who prioritize privacy and resistance to external control.
The legal and ethical implications are profound. If a service has the power to freeze funds but lacks a transparent, court-supervised mechanism for their release, it enters a gray area that resembles traditional banking without the regulatory safeguards. As the SEC, CFTC, and international bodies continue to scrutinize the crypto sector, the "permissionless with boundaries" model may become the de facto standard for survival.
The Bitget theft serves as a reminder that the crypto landscape is no longer just about code; it is about policy. Whether the industry moves toward a bifurcated model—with "compliant" and "anarchic" rails operating in parallel—or settles on a unified standard for handling stolen assets, remains to be seen. What is clear is that the myth of the "uncensorable" network is being replaced by a more complex reality, where every swap carries a hidden, human-driven decision on whether to facilitate or obstruct the flow of capital. For now, the frozen $503,000 remains a testament to this new, contested reality, marking the beginning of a long legal process that will likely set a precedent for how DeFi protocols interact with the law for years to come.



