THORChain, NEAR Intents Debate Limits of Permissionless Crypto
Key Takeaways
- •Bitget suffered a Sept. 24 hack resulting in $387.5 million in stolen funds that moved across chains, with portions routed through the cross-chain swap platform THORChain.
- •THORChain declined to block attacker-linked transactions, with developer Boone Wheeler arguing that a truly permissionless protocol is blind to the provenance of funds and cannot screen specific addresses or transactions.
- •THORChain's earlier decision to halt its chain in May after an exploit drained more than $10 million from a vault demonstrates validators can coordinate when the protocol's own solvency is at risk.
- •NEAR Intents' automated SHIELD system identified over $50 million in hack-linked attempted flows, stopped $503,000 during execution, and waived its share of Bitget's recovery bounty.
- •Bitwise Europe researcher Max Shannon suggested THORChain's stance could shift money-laundering flows from NEAR Intents to THORChain, while Bitget's CEO urged industry cooperation on detecting and responding to stolen funds.

After Bitget was hacked on Sept. 24, $387.5 million in stolen funds began moving rapidly across chains, with some of the assets routed toward the decentralized cross-chain swap platform THORChain.
Bitget CEO Gracy Chen publicly urged THORChain to reject transactions involving attacker-linked addresses. “The industry is watching,” she said in a post on X. THORChain did not intervene, triggering a debate between those who believe protocols have a moral obligation to block stolen funds and those who regard the cypherpunk principles of decentralized, permissionless technology as fundamental. The stakes are concrete: how cross-chain protocols handle attacker-linked flows directly shapes how much stolen money can be intercepted or recovered.
THORChain had previously allowed hackers linked to the Bybit attack to funnel $1.2 billion through the protocol. Developer Boone Wheeler told Magazine that a genuinely permissionless protocol cannot act on the provenance of funds.
“A truly permissionless protocol can do nothing when it encounters known stolen funds — it is blind to their provenance. If THORChain were able to block specific stolen funds, it would not be permissionless.”
Where does permissionlessness end?
Critics argue that THORChain’s position is complicated by its decision to halt the chain in May. Validators voted to stop activity after an attacker exploited a vulnerability and drained more than $10 million from one of the protocol’s vaults. The incident was documented in THORChain’s exploit report. The halt demonstrated that validators can coordinate collective action when the protocol’s own solvency is at stake, even as the protocol maintains it has no way to screen outside flows.
NEAR Intents, a cross-chain transaction competitor to THORChain, took the opposite approach during the Bitget incident. Its automated security layer, SHIELD, identified more than $50 million in attempted flows linked to the hack and stopped $503,000 while transactions were being executed. NEAR said that $166,000 passed through. It also waived its share of Bitget’s recovery bounty.
General manager Alex Shevchenko told Magazine that permissionless infrastructure does not require every application built on it to process every request.
“NEAR Protocol is permissionless: anyone can build on it, transact on it, and become a validator…
“No one needs permission to hold or transfer assets or deploy contracts on NEAR Protocol. However, that does not mean every application built on NEAR must process every request.”
NEAR Intents has faced criticism for intervening, with opponents arguing that the decision shows the service is neither permissionless nor decentralized. The intervention could also expose NEAR Intents to claims that it should use that control more broadly.
However, crypto lawyer Yuriy Brisov said SHIELD’s automated design could allow it to remain within protections available to decentralized protocols.
“There is no compliance team, people who sit there and control the operation manually. This is a smart solution, and that’s what we recommend to all the DeFi companies.”
Permissionless does not necessarily mean neutral
Chen said she understands that protocols have “different architectures, governance models and technical capabilities,” but argued that permissionless infrastructure is distinct from “facilitating the movement of known stolen funds.”
She pointed to NEAR Intents’ response to the Bitget attack and said, “We appreciate that response and will follow the appropriate legal and recovery process for those assets.”
Bitget wants to understand “what is technically and governance-wise possible when stolen assets are identified,” Chen said, and whether the industry can develop workable approaches collectively.
“Permissionless infrastructure does not necessarily mean there can be no mechanisms for detecting and responding to known illicit flows.”
THORChain’s own emergency procedures further complicate the argument that it cannot intervene. According to a post-mortem of the May exploit, the protocol automatically halts activity when solvency checks detect an insolvency event. Node operators can then use broader emergency controls to pause trading, signing and other network activity.
A separate SlowMist investigation traced activity connected to the Bitget hack to an Aug. 31 zero-day exploit.
Wheeler said there is “firm consensus” among THORChain’s nodes around the principle of permissionlessness, adding that “halts are only used when there is an active issue or problem with the protocol.”
He also said THORChain has “no functionality to screen individual addresses or transactions.” According to Wheeler, that limitation is intentional because the system was “intentionally designed to be truly permissionless.”
NEAR Intents offers a contrasting model
NEAR Intents represents a middle-ground approach between unrestricted protocol activity and manual intervention. Shevchenko said it was designed to allow open participation while incorporating financial-integrity measures. SHIELD is intended to “automatically apply targeted controls to supported flows.”
During the Bitget incident, SHIELD relied on public onchain data, signals from an internal anti-money laundering (AML) database and information from third-party intelligence providers, including those listed in the NEAR Intents risk and compliance documentation.
“SHIELD not only protects NEAR Intents but the whole cross-chain ecosystem it serves,” Shevchenko said. “Every major hack drains capital and activity from the onchain economy, so screening for stolen funds and restricting money laundering helps protect the integrity of the wider blockchain economy.”
NEAR said the AI-based SHIELD system also identified suspicious behavior linked to Thursday’s $3.8 million Omni deposit-and-withdrawal interaction exploit and halted activity. NEAR later said it provided assistance related to the Bitget hack in a separate announcement.
Chen said that when stolen funds can be reliably identified, ecosystem participants “should cooperate where technically and legally possible.” That cooperation could include tracing transactions and sharing information, declining transactions, freezing assets where infrastructure permits, or “supporting recovery through the appropriate legal and law enforcement processes.”
The cost of drawing the line
Joël Valenzuela, a libertarian and cypherpunk who heads business and development for Dash, said permissionless systems should not draw a line when stolen funds are identified.
“Permissionless protocols, quite frankly, should not draw the line anywhere when stolen funds are identified, because being able to do so at all makes them permissioned.”
Valenzuela said that although watching stolen funds move freely is “painful,” the ability to intervene and stop them “opens up Pandora’s Box” and could allow “all manner of censorship of innocents eventually happen.” He argued that centralized exchanges should strengthen their security procedures.
“High-level exchanges custodying billions of dollars need to take their security much more seriously. Ultimately, DEXs are the way forward.”
Max Shannon, a senior research associate at Bitwise Europe, said protocols such as THORChain and NEAR, which are still in their formative years, must continue to earn trust. He described refusing to launder hack proceeds as a “sound stance.”
Shannon believes THORChain’s decision could result in more money-laundering flows shifting from NEAR Intents to THORChain.
“Credible neutrality at all costs,” Shannon said, is a “cypherpunk ideal” still championed by a small faction of crypto users and builders.
“They rarely ask why it is valuable, when it is valuable, or what it costs,” he said. “This is the core difference between NEAR Intents and THORChain.”
How the two approaches hold up in future incidents, and whether the industry can develop workable collective responses as Chen has urged, remains the open question hanging over both protocols.
Related reporting: THORChain under fire over the Bitget hack, whether THORChain faces a criminal reckoning, and THORChain’s trading halt.