NewsCryptoBitget Hackers Seek New Laundering Routes as NEAR Intents and Chainflip Reject Over $50 Million

Bitget Hackers Seek New Laundering Routes as NEAR Intents and Chainflip Reject Over $50 Million

Author: Cryptopolitan·

Key Takeaways

  • •NEAR Intents blocked more than $50 million in attempted transfers from the Bitget attackers, processing only about $166,000 and freezing $503,000 mid-swap using its SHIELD risk-intelligence layer.
  • •THORChain declined Bitget CEO Gracy Chen's request to reject the stolen funds, explaining it can only halt the entire network, and handled roughly 2,390 ETH swapped into 75.2 BTC worth about $6.3 million across 27 transactions.
  • •Tether and Circle have frozen roughly $318,000 in USDC and USDT linked to the hack, while confirmed freezes overall cover only a small fraction of the approximately $388 million stolen.
  • •The episode sparked a debate over permissionless neutrality, with NEAR Intents' Alex Shevchenko arguing that builders make design choices and that refusing to help launder stolen assets is one such choice.
  • •Bitget revised its loss upward to roughly $388 million from an initial $351.6 million, is restarting withdrawals in phases including ETH across five networks, and NEAR Intents said it would waive the exchange's 5% freeze and 5% recovery bounties.
Bitget Hackers Seek New Laundering Routes as NEAR Intents and Chainflip Reject Over $50 Million

The suspected North Korean attackers behind the September 24 Bitget hack, which drained roughly $388 million from the crypto exchange, are running into mounting resistance as industry participants rally to shut down potential exit routes for the stolen funds. The standoff has made cross-chain swap services a frontline in containing large-scale exchange thefts, with responses diverging sharply across the industry.

As of September 29, NEAR Intents and Chainflip, two cross-chain swap services, have joined stablecoin issuers Tether and Circle on the list of protocols that have either turned away or frozen funds linked to the breach. Unlike centralized issuers, which can freeze tokens outright, swap protocols must make that call transaction by transaction.

NEAR Intents and Chainflip reject more than $50 million from the Bitget hack

Alex Shevchenko, general manager of NEAR Intents, said the Bitget attackers attempted to move more than $50 million through the protocol, but almost nothing got through. He estimated that only about $166,000 was actually processed on the platform, while $503,000 was frozen mid-swap and the remainder was refused outright. According to Shevchenko, those rejected funds simply "went to other providers."

NEAR Intents is a protocol that lets users trade assets across blockchains and averages more than $100 million in daily cross-chain volume. Shevchenko credited SHIELD with blocking the fund flow, describing it as a risk-intelligence layer that decides whether to ignore a quote or halt a swap already in flight by pulling signals from know-your-transaction vendors, researchers, and large centralized players. The stakes reflect a core laundering dynamic: chain-hopping—converting stolen assets across blockchains and into different tokens—complicates direct tracing, which is precisely the step a screening layer like SHIELD is built to disrupt.

Blockchain-tracking firm MistTrack also reported on X that Chainflip rejected and refunded money sent by the Bitget exploiter.

THORChain is waving the hackers through

THORChain, by contrast, has not moved to reject the funds, declining a public request from Bitget CEO Gracy Chen, as Cryptopolitan reported. The protocol's position, detailed in a follow-up report, was that the only real lever it has is an emergency network halt, which protects the whole protocol and "is not a selective freeze of specific funds or an individual swap." In practice, that means the network can stop everything or nothing—there is no per-user or per-swap freeze.

A September 28 CoinDesk review of THORChain's public records caught about 2,390 ETH being swapped into 75.2 BTC. The transactions, worth roughly $6.3 million, took about 27 swaps and were all consolidated into a single address. The Bybit hackers used the same route in 2025, pushing THORChain's volume above $3 billion in five days, as Cryptopolitan reported—making the network a recurring venue in recent high-profile laundering episodes.

Does 'permissionless' mean no intervention in DeFi?

NEAR Intents' post about not processing the flagged Bitget hack funds was not welcomed in every corner of the industry, sparking debate over what the "permissionless, open and uncensorable" label actually means.

Vini Barbosa, a technical writer building at Ramp Labs, pushed back on September 28, writing to Shevchenko on X: "permissionless does mean neutral," calling it "the whole point of building something permissionless."

Shevchenko rejected the premise in his response, writing: "But permissionless doesn't mean neutral," and adding that "The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours." He framed the issue around property rights, arguing that a system in which theft grants "an unrestricted right to monetize" stolen assets "is simply a system that protects the thief."

NEAR Intents also said it would waive the 5% freeze and 5% recovery bounties Bitget is offering, so that more of the money can return to the exchange, and that frozen funds will stay locked pending a legal process. Shevchenko did not spell out who would authorize their release or how a wrongly flagged user could recover funds—open questions as screening layers take on a larger role in deciding which cross-chain transactions go through.

What Bitget is doing in the meantime

Bitget disclosed the breach on September 24 and later revised the loss upward from an initial $351.6 million once Zcash and TRON transfers were counted. Chen said the attacker exploited a third-party security product to obtain internal credentials rather than stealing private keys, with Mandiant and SlowMist assisting.

Circle and Tether have frozen roughly $318,000 in USDC and USDT tied to the wallets, and the exchange is restarting withdrawals in phases while running its recovery bounty. Based on public reporting, confirmed freezes so far cover only a small fraction of the roughly $388 million taken. Following the resumption of Bitcoin withdrawals, Bitget has now opened the withdrawal service for ETH on the Ethereum, BSC, Arbitrum One, BASE, and Optimism networks, according to an official announcement.