BLOCKCHAIN AI.NEWS

Infrastructure

NEAR Intents Holds $503,000 of the $50 Million It Turned Away

Two days after THORChain refused to filter Bitget's thief, the cross-chain protocol next door published the opposite answer. Its SHIELD system declined to quote most of the attacker's attempts, which then went to other providers. It halted $503,000 mid-swap and let $166,000 through. Its own documentation describes "allow or delay" decisions at quote time, and does not say who decides when a frozen swap is released.

Editorial illustration: a chrome pipe feeds a frosted glass gate; a dozen spheres sit held inside it in warm gold light while a broad stream of blue-lit glass spheres pours out past the gate and curves away into the distance
✓ Reported first by CoinDesk (Sep 29, 06:23 UTC) · Also Cointelegraph (Sep 29) · Alex Shevchenko's report (Sep 28) read in full · SHIELD described in NEAR Intents' security documentation and incident API, read by this desk · Bitget bounty from Gracy Chen

The number in the headlines is $50 million. The number in the vault is $503,000.

Both come from the same document, a report published on X on September 28 by Alex Shevchenko, general manager of NEAR Intents. Attackers who took about $387.5 million from Bitget on September 24, he wrote, "attempted to move through NEAR Intents more than $50M, yet only $166k passed and $503k were stopped during the execution." The rest, the report says in a parenthesis, went to other providers.

That parenthesis is the story. NEAR Intents did not recover $50 million, and does not say it did. By its account it declined to quote most of that volume, the attacker took the swaps elsewhere, and the protocol ended up holding a little over half a million dollars while a little under a fifth of a million passed through. The report carries its own caveat: "all the numbers in this report are indicative and rounded," transactions "might be mislabeled," and the true values are believed to be within 10 percent.

Two behaviours

Shevchenko attributes the outcome to SHIELD, which he describes as a "risk-intelligence layer" that "automatically detects deviations in flows" and draws on "KYT and intelligence providers, independent researches, companies and largest centralised players." When it tags a transaction as hack-linked, he wrote, one of two things happens: "either the protocol does not respond to the quotes or halts the execution if it has already started." The first behaviour accounts for the $50 million, which never entered the system. The second accounts for the $503,000, which was already moving when it stopped.

NEAR Intents' documentation describes SHIELD more narrowly than the report does. It calls it a "dedicated incident and policy service" that evaluates requests "against incident state and shared security posture before continuing execution." Its decisions at quote time are "allow or delay." It is live on 1Click swaps and public status, "rolling out" on the bridge, and at a "vision stage" for the solver pool. Incidents can be raised by "partner integrations, on-call operators, internal anomaly detection, and internal tooling," each with scoped permissions, and the anomaly engine is described as "rule-based and explainable." A separate incident API lets partners who obtain a SHIELD-typed key submit incidents scoped to a chain, token or destination; each record carries a createdBy and a resolvedBy. Neither page names an external KYT vendor, and neither says who decides when funds halted mid-execution are released, or on what standard.

The report answers the second question only by pointing at a courthouse. The $503,000 "remain restricted pending the appropriate legal and recovery process," and Bitget is told to "come to us through the appropriate legal and law-enforcement channels." Bitget has offered a 5 percent bounty for freezing stolen funds and another 5 percent for recovering them, announced by chief executive Gracy Chen on September 26. NEAR Intents says it is waiving its share. On the sum it holds, that share would be $50,300.

What NEAR Intents says it saw

AmountWhat happenedShare of $387.5M
$50M+Attempted; no quote returned; "later went to other providers"~12.9%
$503,000Halted during execution; "restricted pending" legal process0.13%
$166,000Passed through0.04%
$318,013Frozen by Circle and Tether, separately0.08%
Sources: Alex Shevchenko's report for the first three rows, which he labels indicative and rounded; Cointelegraph for the stablecoin freeze. Percentages are the Desk's arithmetic against Bitget's $387.5 million figure.

The word being argued over

The timing was not accidental. On September 28, THORChain had told Bitget that a halt "is not a selective freeze" and that it "doesn't censor by design." Shevchenko's report, published the same day, draws the line elsewhere: "We believe in building decentralised and permissionless systems. But permissionless doesn't mean neutral." Refusing to help launder stolen assets, he wrote, is a choice the builders made, and NEAR Intents "will remain permissionless infrastructure, but with boundaries."

CoinDesk, which reported the dispute first, noted that NEAR Intents describes itself as "permissionless, open and uncensorable" and put the objection to it. Vini Barbosa of Ramp Labs told the outlet that permissionless "does mean neutral" and that "it's the whole point of building something 'permissionless'," while allowing the product has its uses. NEAR co-founder Illia Polosukhin answered, in CoinDesk's account, that permissionless means nobody needs permission to own and transfer assets on the chain, not that every application built on it must process every transaction. That is a distinction between the ledger and the storefront, and it is the one THORChain declines to make about itself.

The report's sharpest paragraph is not aimed at Bitget or at THORChain. It is aimed at wallets. "What you integrate is your responsibility," Shevchenko wrote. An interface used to move stolen funds "is not simply an observer," and bad liquidity providers "pass that risk on to your users." It is a pitch as much as a warning: pick the router that screens.

What screening bought

Set against the theft, the numbers are small on every side. Circle and Tether's freezes total $318,013 by Cointelegraph's count; NEAR Intents holds $503,000; together that is well under a quarter of one percent of what left Bitget. CoinDesk's own analysis put completed swaps through THORChain at about $6.3 million, against GoPlus Security's much larger and unconfirmed estimates reported earlier by this desk. Shevchenko's claim is not that SHIELD stopped the laundering. It is that the laundering did not happen on his rails, because the rails said no before the money arrived. "NEAR Intents routinely processes $100M+ of a crosschain trading volume in a day," he wrote, and "only a negligible fraction of the hacked funds were flowing through us."

The advice to victims that closes the report is the same advice every incident-response firm gives: notify exchanges and stablecoin issuers, contact responders such as zeroShadow or SEAL 911, and "ideally, you should establish the connections and have a plan how to react beforehand." Bitget, which now says its attacker entered through a third-party security product it has not named, is presumably taking notes.

The Take

NEAR Intents has made the more defensible choice and described it less carefully than it should have. "Blocked $50 million" is doing a lot of work in the coverage; what the report actually says is that the system refused to quote, and the attacker went next door. That is a legitimate result, and probably the best a single router can achieve, but it is a deflection, not an interception, and the $503,000 is the only money anyone can point to. The harder gap is in the documentation. The public pages describe delays, pauses and incident records with a "resolvedBy" field. They do not say who can hold a user's mid-swap funds, for how long, on whose word, or how a wrongly flagged customer gets them back, and the report's answer, "the appropriate legal and recovery process," is not a policy. THORChain's position has the virtue of being fully specified: it will not filter, and it says so. If NEAR Intents wants "permissionless with boundaries" to mean something, the boundaries have to be written down where a user can read them before the swap, not after.

More on the subject