NEAR co-founder Illia Polosukhin defended NEAR Intents’ move to stop funds linked to the Bitget hack, saying on Monday that an open blockchain does not require every application built on it to handle every trade.
In a post on X, Polosukhin wrote that permissionless access means no one needs approval to own and transfer assets or deploy contracts on NEAR. He added that this does not mean every application or liquidity provider must process every transaction.
Attackers tried to move more than $50 million through NEAR Intents
His comments came hours after Alex Shevchenko, general manager of NEAR Intents, disclosed that attackers had tried to route more than $50 million in stolen funds through the network’s cross-chain trading protocol.
Shevchenko said about $166,000 got through, while $503,000 was frozen partway through execution. He added that those funds remain restricted pending the appropriate legal and recovery process.
How SHIELD flagged and blocked the flows
The blocking came from SHIELD, which Shevchenko described as a risk-intelligence layer. According to him, it combines transaction-monitoring data, outside researchers, and input from large centralized players to detect suspicious flows.
When the system links a trade to a hack, the protocol either declines to quote it or halts it if execution has already begun.
In his post, Shevchenko wrote: “Permissionless doesn’t mean neutral.” He added that the people building such systems decide what those protocols enable, and that refusing to help launder stolen assets is one of those choices.
NEAR Intents also said it would give up its share of the bounty Bitget has offered for frozen funds so the exchange can recover more.
Bitget thanked the team, while THORChain took the opposite view
Bitget CEO Gracy Chen thanked the NEAR Intents team on Monday. She wrote that a public blockchain does not have to choose between being open and excluding hackers, and that risk detection can be built in while still allowing anyone to use the chain.
THORChain, another cross-chain protocol, took the opposite position. On Monday, it again rejected Bitget’s request to block the attacker’s addresses, saying it does not censor by design.
Criticism of NEAR’s approach and the Bitget hack background
Not everyone supported NEAR’s position. A pseudonymous X user, loracle, argued that NEAR runs on a trusted execution environment controlled by its team, which means it can seize funds like a centralized exchange and request KYC at its own discretion.
Bitget has said attackers stole about $387.5 million on Sept. 24 after compromising a backend system in its wallet infrastructure. The exchange also said its User Protection Fund covers the full loss.

