NEAR Intents blocked more than $50 million in attempted transfers linked to the hackers behind last week’s $387.5 million Bitget theft, according to the protocol’s general manager, as the stolen funds move across chains in one of the year’s largest laundering operations.
Alex Shevchenko, who runs NEAR Intents, said the protocol’s SHIELD detection system flagged and stopped the transfers before they could complete. About $503,000 was frozen during execution, he said, while roughly $166,000 in suspected stolen funds passed through to other providers.
Attackers stole $387.5 million from Bitget on Thursday. A significant share of the haul has since moved across chains to Ethereum, and security teams across the industry have spent the days since the breach trying to intercept it.
Bitget detected the breach the same day and moved to contain it, though the scale of the theft became clear within hours as on-chain watchers tracked the outflows in real time. The exchange kept its published schedule for restoring ETH withdrawals, which resumed Monday. Chen’s team has balanced that openness against operational security, publishing attacker addresses while declining to detail which countermeasures remain active.
How the interception worked
NEAR Intents runs a cross-chain swapping service built on NEAR Protocol infrastructure. Because it executes swaps rather than simply relaying messages, it sits at a chokepoint where transfers can be screened before assets move. Shevchenko said SHIELD checks transfer requests against intelligence on attacker-controlled addresses and rejects matches before execution.
The rejected amounts later surfaced as attempted transfers at other providers, meaning the attackers kept routing the same funds through different venues after the rejections. The figures have not been independently verified, and the split between frozen, blocked and passed-through money may shift as other platforms report their own numbers. The total that never leaves attacker wallets will likely remain unknown.
Cross-chain bridges have become the standard first hop for stolen crypto because they convert one asset into another without a centralized custodian that can freeze balances on request. Each hop adds a venue where cooperation, or refusal, decides whether an address gets flagged.
Permissionless rails under pressure
The response has exposed a split in how crypto infrastructure handles stolen money. THORChain, another cross-chain protocol, has faced calls to block addresses linked to the attack. The episode captures the tension permissionless systems face between open access and cooperation with tracing efforts.
Protocols that block transfers voluntarily point to cases like this as justification. Critics answer that once interception becomes routine, the neutrality of public chains erodes, and the cost lands on users in sanctioned or contested jurisdictions who have no other rails. Neither approach has a clean answer, and the industry has lived with the contradiction for years.
Bitget itself reopened ETH withdrawals on schedule after the theft, but chief executive Gracy Chen has said she expects only a small share of the stolen amount to be frozen or recovered. That is unusual candor for a chief executive in the middle of a breach, and it sets expectations for a recovery process that could stretch years. The exchange has published attacker-controlled addresses and worked with other platforms to flag deposits.
Blockchain intelligence firms have clustered around the case, and their address lists feed the screening systems that platforms like NEAR Intents rely on. Tracing stolen funds across chains is slow work, and each new hop can take days to map before the next interception becomes possible.
A familiar playbook
The $387.5 million theft ranks among the largest exchange hacks on record. After the Bybit theft in early 2025, in which attackers drained about .5 billion in ethereum, the funds were laundered slowly over months through THORChain and other venues while investigators tracked each hop. A share of that haul was never recovered.
Funds stolen in attacks of this size typically move through mixers, bridges and peer-to-peer desks in the days that follow, and historical recovery rates drop sharply once assets reach decentralized venues. Security researchers expect laundering attempts around the Bitget theft to continue for weeks as the attackers work through the remaining balance.
Regulators have watched this pattern for years. Exchanges in major jurisdictions now freeze flagged deposits as a matter of course, which pushes launderers toward protocols that cannot freeze anything. The result is a two-tier system where centralized venues cooperate and decentralized ones absorb the flow.
For NEAR Intents, the episode doubles as a demonstration of its compliance tooling. Cross-chain protocols face growing pressure from regulators and exchanges to show they are not passive conduits for stolen funds, and a publicized interception makes that case better than any policy document. Whether other intent-based protocols follow with their own screening announcements will say something about where the sector is heading.
For Bitget customers, the open question is whether the exchange covers any shortfall itself. Large platforms have sometimes absorbed losses after major hacks, and how Bitget handles this one will test how far exchange insurance stretches at this scale. The company has not said whether user balances were affected or whether the stolen assets belonged to the platform’s own reserves.
The episode also lands in the middle of a broader debate about whether crypto’s cross-chain infrastructure can ever be both open and safe. Every major theft since 2022 has revived the same argument, and every interception like this one gets cited by both sides. What is different this time is the speed: a screening system stopped eight figures worth of transfers within days rather than after months of litigation and negotiation, which is the outcome platforms have promised for years and rarely delivered.
