
The NEAR Intents protocol reported detecting and blocking transactions amounting to over $50 million related to assets moved after the Bitget attack, in which the exchange was robbed of $387.5 million. According to the project's general manager, Alex Shevchenko, a significant portion of the stolen funds was moved between different blockchains and directed to Ethereum after the initial withdrawal. The SHIELD system used by NEAR Intents to monitor operations detected suspicious transfer attempts and prevented them from passing through the protocol's infrastructure. During the execution of transactions, approximately $503,000 was successfully frozen. However, about $166,000 of the funds, which were presumably related to the attack, still passed through the system. The remaining assets were redirected by users to other providers after blocking the transfer attempts.
The situation is another example of the differences between open-access infrastructure and centralized services capable of selectively blocking operations. Against this backdrop, there have been calls to restrict service to addresses associated with the attack from inter-network protocols. Shevchenko stated that NEAR Intents intends to counteract the movement and legalization of stolen assets despite the open nature of the protocol. Simultaneously, the project announced its refusal of the reward offered by Bitget: 5% for freezing funds and another 5% for their subsequent return. According to a NEAR Intents representative, this will allow Bitget to receive a larger portion of the returned assets, and the frozen funds are intended to be returned to the owner as part of the appropriate legal procedure.
Other participants in the crypto infrastructure have also taken separate measures. Circle and Tether blacklisted a wallet associated with the Bitget attack, after which assets worth approximately $318,000 in USDT and USDC were frozen, according to on-chain analytics. Simultaneously, Bitget CEO Gracy Chen appealed to THORChain to cease servicing addresses related to the incident. THORChain explained that the protocol's architecture does not provide for selective censorship of individual funds or exchanges, and the previously applied network suspension was a general emergency security mechanism. Thus, the investigation concerns not only the movement of stolen assets but also the question of what control mechanisms can be applied in open inter-network protocols without changing their basic architecture.




