NEAR Intents says it stopped about $503,000 during execution and blocked over $50 million in attempted transfers linked to Bitget's September 24 hack.

Bitget's exhibition stand at an event in May 2025. Photo: Harris de Weerd via Wikimedia Commons (CC BY-SA 4.0; resized and compressed). Source
NEAR Intents says it froze approximately $503,000 in assets linked to Bitget's September 24 hack after stopping transactions during execution. Alex Shevchenko, general manager of the cross-chain trading service, disclosed the intervention in a September 28 account of how its SHIELD risk system responded to the theft.
The frozen balance is separate from the much larger volume of attempted transfers the service detected. Attackers tried to move more than $50 million through NEAR Intents, while roughly $166,000 passed through, Cointelegraph reported. The rejected flows subsequently went to other providers. The $50 million figure therefore describes attempted use of the service, rather than money held for recovery.
"The funds remain restricted pending the appropriate legal and recovery process," Shevchenko wrote about the assets stopped mid-execution. He cautioned that the figures were indicative and rounded: transactions could be mislabeled, affecting the amounts attributed to the hack. He estimated that the true values were within 10% of the reported totals.
Bitget chief executive Gracy Chen acknowledged the intervention later on September 28. She thanked NEAR Intents and SHIELD and said the exchange would follow the appropriate legal and recovery process on its side. Her statement did not announce that the frozen assets had already been returned.
Unchained reported that Bitget attributed the roughly $387.5 million theft to a compromised backend system in its wallet infrastructure.
NEAR Intents allows users to swap assets across blockchains. SHIELD supplies risk information used to decide whether those trades should proceed. The system draws on transaction-monitoring providers, outside researchers, companies and large centralized industry participants, according to Unchained's account of the response.
The controls can operate at two stages. Before execution, the service can decline to provide a quote for a flagged transaction. If execution has begun, it can halt the trade. The reported frozen balance came from the second category, where funds were stopped during execution, rather than from a request that received no quote.
For its reconstruction of the Bitget flows, the team's report cited Bitget's tracing explorer, Arkham, internal NEAR Intents logs, SHIELD records and other open sources. It said much of the stolen value reaching cross-chain protocols had been consolidated into ether on Ethereum. Duplicate attempts were filtered out of the reported attempted-transfer total.
Shevchenko put the service's routine cross-chain trading volume at more than $100 million a day. The incident account does not provide an overall detection rate for SHIELD or a historical series against which to compare the reported results.
NEAR co-founder Illia Polosukhin defended the approach in a separate September 28 post. He described permissionless access as the ability to own and transfer assets and deploy contracts on NEAR without asking permission. "It does not mean every application or liquidity provider must process every transaction," he wrote.
Polosukhin described SHIELD as shared, real-time risk intelligence that participants can use to identify hacks and decide which transactions to serve. Partners can contribute incident data as well as consume it. His explanation placed those decisions with applications and liquidity providers while maintaining the claim of open access to the underlying network. He invited others to help extend SHIELD across the industry.
THORChain has defended a different policy. In its September 28 statement, the cross-chain network said a network-wide halt protects protocol security and is not a selective freeze of individual funds or swaps. It said it "doesn't censor by design." Its refusal to block wallets tied to the Bitget theft was covered in our earlier report.
The recovery process also involves a financial incentive that NEAR Intents says it will decline. Bitget offered a 5% bounty for freezing attacker funds and another 5% for recovery, according to the reporting on the intervention. NEAR Intents said it would waive its share so that more of the money could be returned to the exchange.