THORChain and NEAR Intents Clash Over $387.7 Million BitGet Hack Funds, Exposing Crypto's Permissionless Divide
Key Takeaways
- •Roughly $387.5 million in assets stolen from BitGet began moving across multiple blockchains after the September 24, 2026 breach, with some funds routed through THORChain and more than $80 million in XRP also moved by the attacker.
- •THORChain declined BitGet CEO Gracy Chen's request to block attacker-linked addresses, arguing that screening transactions based on fund provenance would make the protocol permissioned.
- •NEAR Intents' automated SHIELD system identified more than $50 million in attempted flows linked to the hack, blocking about $503,000 during execution while $166,000 passed through.
- •THORChain maintains it has no mechanism to screen individual addresses or transactions, while acknowledging its network can halt activity during protocol-level emergencies.
- •NEAR General Manager Alex Shevchenko said the underlying NEAR blockchain remains permissionless, but individual applications built on it are not required to process every transaction.

A dispute between cross-chain protocols THORChain and NEAR Intents over the handling of funds stolen in the $387.7 million BitGet hack has exposed a growing divide in the crypto industry over how far permissionless systems should go in preventing illicit transactions. At the center of the disagreement is a question that has long divided the sector: whether decentralized protocols should remain neutral toward all transactions, even when stolen funds can be identified, or take steps to block them.
Stolen Funds Move Across Chains
About $387.5 million in stolen assets began moving across blockchains after the September 24, 2026 breach of BitGet, with some of the funds routed through THORChain. Because cross-chain protocols exist precisely to move assets between blockchains, they sit along the paths stolen funds take once they leave an exchange — which is how routing decisions by protocols like THORChain and NEAR Intents became the flashpoint of this incident. The exchange said the stolen funds were nearing $400 million as the security breach unfolded, and the attacker was also able to move more than $80 million in stolen XRP.
BitGet CEO Gracy Chen urged THORChain to block addresses linked to the attacker, but the protocol declined, arguing that selectively blocking transactions would conflict with its permissionless design.
THORChain: Screening by Fund Provenance Would Make It Permissioned
THORChain developer Boone Wheeler said a truly permissionless protocol cannot intervene based on the provenance of funds, because doing so would make it permissioned. In that framing, a protocol that checks where money came from before moving it effectively requires transactions to be approved — the defining feature of a permissioned system. The protocol had previously faced criticism after funds linked to the $1.2 billion ByBit hack were moved through its network.
THORChain maintains that it has no mechanism to screen individual addresses or transactions, while acknowledging that its network can halt activity during protocol-level emergencies.
NEAR Intents: Automated Screening and Selective Blocking
NEAR Intents took a different approach. Its automated SHIELD system identified more than $50 million in attempted flows linked to the BitGet hack and blocked about $503,000 during execution, while $166,000 passed through, according to the report. The numbers illustrate both the reach and the limits of automated screening: attempted flows were flagged at scale, yet execution-stage blocking stopped only a small share of them. NEAR said the system uses onchain data, internal anti-money-laundering signals, and third-party intelligence to identify suspicious flows.
NEAR General Manager Alex Shevchenko said the underlying NEAR blockchain remains permissionless, but individual applications built on it do not necessarily have to process every transaction. NEAR argues that automated controls can protect users and the wider ecosystem without relying on manual intervention by a compliance team.
Censorship-Resistance Advocates Push Back
The approach has drawn criticism from advocates of strict censorship resistance, who argue that intervention undermines the meaning of a permissionless system. The debate also exposes a practical distinction between decentralized infrastructure and the applications operating on top of it — one that increasingly shapes where responsibility for stopping stolen funds is understood to sit.
A Broader Question for the Industry
The dispute reflects a broader question for the crypto industry as decentralized financial infrastructure handles increasingly large sums: whether neutrality should remain absolute when protocols can identify stolen funds, or whether protecting users and preventing money laundering justifies targeted intervention. The answer could shape how cross-chain protocols balance censorship resistance, security, and regulatory expectations as their role in the digital-asset economy grows. Developments worth tracking include whether BitGet continues pressing protocols to block attacker-linked addresses, whether THORChain invokes the protocol-level emergency halt it acknowledges having, and how remaining stolen funds move through networks with and without screening systems like SHIELD.
Source: BitcoinKE