The fight over Bitget’s hacked funds has become a direct test of how far crypto protocols should take the idea of being permissionless. After Bitget was hacked on Sept. 24, about $387.5 million in stolen assets began moving across chains, and some of that flow headed to decentralized crosschain swaps platform THORChain.

Bitget CEO Gracy Chen publicly asked the platform to deny service to addresses linked to the attacker. 「The industry is watching,」 she said.
THORChain did not intervene. That refusal set off a sharp debate between those who say protocols have a moral duty to block stolen funds and those who treat cypherpunk ideas around decentralized, permissionless systems as non-negotiable. THORChain had already faced similar scrutiny after Bybit hackers moved $1.2 billion through the protocol, and that earlier episode made its position easier to read this time.
Developer Boone Wheeler told Cointelegraph Magazine that THORChain nodes have a 「firm consensus」 around the ideal of being permissionless.
Where permissionlessness stops
Critics say THORChain has not always applied that principle in the same way. In May, validators voted to halt the chain after an automated system was triggered when an attacker exploited a vulnerability and drained more than $10 million from one of the protocol’s vaults.
That has become a central point in the criticism. If the protocol can stop activity during an emergency involving its own infrastructure, opponents ask why it should not act when known stolen funds are moving through the system.
NEAR Intents, a crosschain transaction competitor to THORChain, took the opposite approach. It intervened to block hack-linked funds. Its automated security layer, SHIELD, said it identified more than $50 million in attempted flows tied to the Bitget incident, stopped $503,000 during execution, and said $166,000 passed through.

NEAR also waived its share of Bitget’s recovery bounty. General manager Alex Shevchenko told Cointelegraph Magazine, 「NEAR Protocol is permissionless: anyone can build on it, transact on it, and become a validator…」
That move brought heavy criticism of its own. Opponents argued that intervention showed NEAR Intents was not truly permissionless or decentralized, and that the decision could expose it to broader demands to exercise similar control elsewhere. Even so, because SHIELD is an automated system, crypto lawyer Yuriy Brisov said it could still fall within protections available to decentralized protocols.
Permissionless does not automatically mean neutral
Chen told Cointelegraph Magazine that she understands different protocols have 「different architectures, governance models and technical capabilities,」 but said there is an important distinction between permissionless infrastructure and 「facilitating the movement of known stolen funds.」
Referring to NEAR Intents, she said, 「We appreciate that response and will follow the appropriate legal and recovery process for those assets.」
Chen also said Bitget wants to understand 「what is technically and governance-wise possible when stolen assets are identified,」 and whether the industry can find workable approaches together.
That complicates THORChain’s case, because the protocol has already shown it can step in during an emergency if it chooses to.
THORChain’s post-mortem on the May exploit said the protocol automatically halts activity when solvency checks detect an insolvency event. Node operators can then use broader emergency controls to pause trading, signing, and other network activity.

Wheeler said halts are used 「only when there is an active issue or problem with the protocol.」 He also said there is 「no functionality to screen individual addresses or transactions.」 According to him, that was a deliberate design choice because the system was 「intentionally designed to be truly permissionless.」
NEAR Intents offers a different model
Where THORChain sits closer to the hardline code-first end of the spectrum, the NEAR team occupies a middle position. The report notes that NEAR now has a new ETF from Bitwise and follows a different philosophy and operating model.
Shevchenko said NEAR Intents was built to support open participation, but with its own financial integrity measures. SHIELD, he said, is designed to 「automatically apply targeted controls to supported flows.」
In this case, SHIELD used public onchain data, signals from an internal anti-money laundering database, and information from third-party intelligence providers listed in NEAR Intents risk and compliance documents.
「SHIELD not only protects NEAR Intents but the whole cross-chain ecosystem it serves,」 Shevchenko said.
He also said the AI-based SHIELD identified suspicious behavior behind Thursday’s $3.8 million Omni deposit-withdrawal interaction exploit and halted activity.

Chen said that when stolen funds can be reliably identified, ecosystem participants 「should cooperate where technically and legally possible.」 That could include tracing and information sharing, declining transactions, freezing assets where infrastructure allows it, or 「supporting recovery through the appropriate legal and law enforcement processes.」
The cost of drawing a line
Joël Valenzuela, head of business and development for Dash and a libertarian cypherpunk, argued that permissionless should mean exactly that.
He said it is 「painful」 to watch stolen funds move freely, but warned that the power to step in and stop those transfers 「opens up Pandora’s Box」 and 「lets all manner of censorship of innocents eventually happen.」 In his view, centralized exchanges should strengthen their own security protocols instead.
Max Shannon, senior research associate at Bitwise Europe, took a different view. He said protocols still in their formative years, including THORChain and NEAR, still need to earn trust, and refusing to launder hack proceeds is a 「sound stance.」
He said THORChain’s position will likely push more money-laundering flows away from NEAR Intents and toward THORChain.
Shannon described 「credible neutrality at all costs」 as a 「cypherpunk ideal」 still defended by a small faction of crypto users and builders. 「They rarely ask why it is valuable, when it is valuable, or what it costs,」 he said. 「This is the core difference between NEAR Intents and THORChain.」

