The hackers behind the $387.5 million Bitget theft ran into an unexpected obstacle this week: a cross-chain swap protocol that refused to move their money. NEAR Intents says its SHIELD risk system blocked more than $50 million in attempted transfers linked to the September 24 breach, froze another $503,000 mid-execution, and gave up its own recovery bounty so the exchange could claw back more of the funds. The episode has turned into something bigger than a single recovery story. It has reopened an old argument in crypto about whether permissionless infrastructure should ever say no, and this time the industry is not answering with one voice.
The sequence began on Thursday, September 24, when attackers drained roughly $387.5 million from Bitget’s hot and warm wallets. The exchange suspended withdrawals within hours and confirmed that its cold wallets and separate self-custodial product were untouched. From there the stolen assets started moving. Investigators tracking the flows say the attackers pushed funds across several blockchains through bridges, with much of the money eventually converging on Ethereum as ETH, before heading toward mixing services including Wasabi.
What SHIELD caught
NEAR Intents, a cross-chain trading protocol that says it routinely processes more than $100 million in daily volume, was one of the stops on that route. Alex Shevchenko, the protocol’s general manager and a co-founder of Aurora, laid out the numbers in a September 28 post. SHIELD, the protocol’s automated risk layer, identified more than $50 million in attempted laundering flows tied to the hack and refused to quote or execute the transfers. Around $166,000 in suspected stolen funds slipped through anyway, a detail Shevchenko did not hide. Another $503,000 was frozen while transactions were still in flight and remains restricted pending legal process.
SHIELD works by pulling intelligence from know-your-transaction providers, independent researchers and industry partners, then screening quoted swaps against that data. When a flow matches known illicit activity, the system can decline to serve it or halt a transfer that has already started. Shevchenko argued the approach does not conflict with openness. In his framing, a public chain does not have to choose between being accessible and excluding hackers, because risk detection can be built in without gatekeeping ordinary users.
The protocol also made a financial gesture that got attention. Bitget offers a 5 percent bounty for freezing attacker funds and another 5 percent for recovering them. NEAR Intents waived both, which leaves more of any recovered money with the exchange. Shevchenko said the frozen $503,000 would be returned through appropriate legal channels rather than informal negotiation.
“Appreciate NEAR Intents / SHIELD for stepping up on the Bitget incident: flagged $50M+ in attempted laundering flows, froze $503k mid-execution, and waived their own bounty share so we can recover more. This is what permissionless but not ‘facilitating known stolen funds’ should look like. More protocols should take notes.”
That quote comes from Bitget CEO Gracy Chen, who posted it on X in response to the announcement. She added that the matter would follow legal and recovery process and called the intervention meaningful for the company and the wider industry.
THORChain sees it differently
Not every protocol made the same call. Chen had publicly asked THORChain, a decentralized cross-chain swap network, to refuse service to addresses linked to the attack. The network’s answer was that it does not censor by design. THORChain noted it has halted its network in past emergencies, but described those as broad security measures affecting everyone, not selective freezes of specific funds or individual swaps. The distinction mattered within days. As previously reported, the Bitget attacker converted 2,390 ETH into 75.2 BTC through THORChain, roughly $6.3 million at the time, after the network declined to act.
Shevchenko had sharp words for that posture. A system that will move stolen money no matter what, he argued, is simply a system that protects the thief, and such systems cannot become the economic backbone of the future. THORChain’s defenders see the same facts the other way around. Selective blocking, they argue, is censorship by another name, and a network that freezes funds on request from an exchange CEO is no longer neutral infrastructure. Both positions are internally consistent. That is what makes the disagreement hard to resolve.
ZachXBT ties the laundering to organized actors
While the protocols argued, on-chain investigators kept working. ZachXBT, the blockchain investigator who has tracked North Korean laundering networks for years, said Chinese illicit actors helped move funds connected to the exploit, which he attributed to alleged North Korean attackers. He reported that individuals involved in the laundering effort were publicly seeking assistance with orders through Discord servers and Telegram channels used by laundering services. He also linked one of the actors, whom he called Alias 4, to the earlier $292 million Kelp DAO exploit.
The stablecoin issuers moved first among centralized players. Circle and Tether blacklisted a wallet linked to the exploiter on Friday, freezing $318,013 in USDT and USDC according to on-chain data. It is a small fraction of the total, but it shows the standard playbook: centralized issuers act within hours, permissionless protocols take days and may never act at all.
Where each player landed
The responses to the hack now form a rough spectrum, and the contrast is the story.
| Player | Action taken | Amount affected |
|---|---|---|
| NEAR Intents (SHIELD) | Blocked transfers, froze funds mid-execution, waived bounty | $50M+ blocked, $503K frozen |
| Circle and Tether | Blacklisted exploiter-linked wallet | $318,013 in USDT and USDC |
| THORChain | Declined freeze request, processed swaps | $6.3M converted to BTC |
| Bitget | Halted withdrawals, offered bounties, pursuing legal recovery | $387.5M stolen |
Bitget, for its part, has been restoring service on a schedule. Withdrawals began reopening on September 28 with bitcoin first, and the exchange has said full service should return by October 2.
Why the split matters
The practical question for anyone building cross-chain infrastructure is whether screening becomes a norm or stays a differentiator. If Chen’s line, that permissionless should not mean facilitating known stolen funds, becomes the industry’s accepted middle ground, then expect more protocols to ship SHIELD-style layers and advertise them. If the THORChain position holds among decentralized networks, laundering routes will simply concentrate on the services that refuse to screen, and investigators will keep publishing their names.
There is also a legal dimension. NEAR Intents directed Bitget to pursue the frozen funds through established legal and law enforcement channels, which treats the protocol as a place where evidence gets preserved rather than a judge. That is a compromise position, and it may be the one that survives. Freezing pending a court order is defensible in a way that unilateral permanent seizure is not, at least under most current frameworks.
For Bitget, the immediate arithmetic is sobering. More than $50 million blocked at one protocol, half a million frozen, a third of a million in stablecoins blacklisted, and $6.3 million already converted to bitcoin on a network that will not cooperate. The bulk of the $387.5 million is still unaccounted for publicly. Recovery stories in crypto rarely end with most of the money back, and the mixing services still ahead of the investigators make this one look unlikely to break the pattern.
The deeper shift may be in expectations. Two years ago a hack story ended with the funds vanishing and a postmortem. This one produced a public dispute between protocols about who should move stolen money, a CEO publicly scoring participants, and a bounty waiver framed as industry citizenship. Laundering $387.5 million quietly is getting harder, not because the technology changed, but because the politics around it did.
