NewsCryptoNEAR Intents Says It Blocked Over $50 Million in Flows Tied to the Bitget Hack

NEAR Intents Says It Blocked Over $50 Million in Flows Tied to the Bitget Hack

Author: AI Crypto Core·

Key Takeaways

  • •NEAR Intents claims to have blocked more than $50 million in transaction flows connected to the Bitget hack, a figure that has not been independently verified.
  • •The protocol's intent-based architecture relies on competing solvers fulfilling user-expressed outcomes, creating a checkpoint where suspicious flows can be screened before settlement.
  • •Blocking a flow does not equate to fund recovery, as the underlying assets were not frozen, returned, or seized by the protocol.
  • •Industry responses have diverged, with THORChain declining to blacklist hack-related addresses—a move that drew comment from Vitalik Buterin—while AMLBot traced four BTC from the hack to Wasabi CoinJoin.
  • •If substantiated with on-chain evidence, the episode would highlight solver networks as both a defensive screening capability and a potential centralization risk in cross-chain infrastructure.
NEAR Intents Says It Blocked Over $50 Million in Flows Tied to the Bitget Hack

NEAR Intents says it intercepted more than $50 million in transaction flows linked to the Bitget hack, according to the protocol's own account of events. The claim casts NEAR's intent-based transaction layer as a real-time filtering mechanism capable of identifying and blocking suspicious fund movements at the infrastructure level, though the figure has not been independently verified.

What NEAR Intents Says It Blocked

According to the protocol, more than $50 million in flows connected to the Bitget hack were blocked. The figure originates from NEAR Intents itself, and no independent on-chain verification has been cited. A blocked flow also does not confirm fund recovery or establish the final disposition of the assets.

NEAR Intents describes its system as a smart routing layer that processes user-expressed outcomes rather than routing transactions through fixed smart contract paths. In this architecture, competing solvers fulfill user intents, creating a point of control where flows can be screened before settlement. The protocol says this design allowed it to identify transactions carrying signatures of the Bitget hack and refuse to process them.

The more-than50-million figure remains a self-reported claim. As of this writing, the protocol has not published a transaction-level breakdown or block explorer evidence linking specific wallets or transaction hashes to the Bitget incident. Readers should treat the stated amount as an unconfirmed assertion until it is corroborated by on-chain data or independent review. Broader ecosystem activity on NEAR can be tracked via DeFiLlama's NEAR chain dashboard.

The Bitget hack has drawn responses from multiple layers of the industry. THORChain declined to implement a blacklist for addresses connected to the incident, a decision that drew comment from Ethereum co-founder Vitalik Buterin. Separately, AMLBot traced four BTC from the Bitget hack to Wasabi CoinJoin, illustrating that portions of the funds had already moved through privacy-preserving infrastructure before any blocking mechanism engaged.

Why Protocol-Level Blocking Matters, and What Remains Open

If the NEAR Intents claim holds up to scrutiny, it would represent a meaningful data point for intent-based architectures as a security layer. Unlike mempool-level blocking, which requires miner or validator cooperation, an intent protocol can theoretically screen flows at the solver level before a transaction is even constructed and broadcast.

Blocking flows, however, is not the same as recovering funds. A blocked intent means the protocol refused to route a transaction; it does not mean the underlying assets were frozen, returned, or seized. Hackers who encounter a blocked route typically attempt alternative bridges or decentralized exchange paths, as illustrated by the Bitget attacker's activity documented when Bitget resumed Bitcoin withdrawals after the hacker swapped ETH via THORChain.

Key open questions include how NEAR Intents identified the flows as hack-related, what methodology was used to attribute the $50 million figure, and whether any portion of those funds has been frozen at a custodial level rather than simply rerouted. Verification would require the protocol to publish the wallet addresses flagged, the transaction hashes refused, and the criteria used to link them to the Bitget incident. Token-level data for NEAR's market activity has shown no anomalous movement that would independently corroborate the blocking claim.

For the broader AI-crypto infrastructure stack, the episode highlights an emerging design question: as intent-based protocols gain adoption for cross-chain execution, their solver networks become potential compliance and security chokepoints. That creates both a defense capability and a centralization risk, depending on who controls the blocklist and under what governance framework decisions are made to refuse flows.

What to watch next is an official disclosure from NEAR Intents with on-chain evidence, any response from Bitget confirming or disputing the figure, and whether other intent or solver networks disclose similar interventions in the same incident.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.