# NEAR Stopped Bitget's Hackers Without Breaking Privacy *Author: William Peaster* *Published: Sep 29, 2026* *Source: https://www.bankless.com/read/near-stopped-bitget-s-hackers-without-breaking-privacy* --- **On September 24th, Bitget was drained of ~$387.5M in an attack that, ****surprise****, closely matches known North Korean hacker patterns. ** Accordingly, the culprits quickly moved to scatter the loot into more defensible positions, wasting no time in swapping stolen USDT and USDC into ETH and BNB to bypass any Tether and Circle freezes. Once those swaps were done, it was escape time. Numerous protocols were approached for making this flight, including crosschain rails like THORChain and NEAR Intents. However, the results the hackers got were markedly different across these two particular platforms. After Bitget CEO Gracy Chen formally asked THORChain to refuse service to the attackers’ tracked addresses, THORChain declined, likening its “neutrality” to that of Bitcoin and Ethereum. Since then, a hacker-linked wallet has swapped more than $6M worth of ETH into BTC through the protocol. Conversely, when the attackers tried to move +$50M through NEAR Intents, the solver network’s risk intel layer, **SHIELD**, refused basically all of it. Only $166k, or a fraction of the attempted funds, slipped through. [The Bitget Hack: What We Saw at NEAR Intents On 24th of September @bitget was hacked. Approximately $387.5M of the funds were stolen. A significant part of these funds moved across chains, mainly into Ethereum. Hackers attempted to move through X (formerly Twitter) • Alex Shevchenko 🇺🇦 ![](https://pbs.twimg.com/media/HTTflqQXAAAuk8h.jpg) ](https://x.com/AlexAuroraDev/article/2104554958754357482) This defensive mechanism naturally drew mixed responses. Plenty of people in the industry applauded the move as balanced and sensible. Why let bad actors win when you can clamp them in such a way that doesn’t affect the UX or assurances of regular users? On the flip side, backlash also arose since NEAR has been leaning into permissionless privacy via Confidential Intents. If NEAR can find and stop the hacker’s money, what’s to stop them from doing the same to you later under different circumstances? To get at the nuance here, it helps to understand how the mechanics work. Deposits into and withdrawals out of NEAR Intents are ordinary transactions on Bitcoin, Ethereum, Zcash, etc. Anyone with a block explorer can see them. It’s what in between, like balances, routes, trades, etc., that live inside Confidential Intents. As such, SHIELD works as a de facto gate at the entryway of this system. It checks public deposit addresses against stolen funds intel that much of the industry already shares and then declines access to nefarious accounts. In that sense, nothing confidential was ever “opened” when NEAR denied the Bitget attackers. And SHIELD's reach is limited, too. As [mert noted](https://x.com/mert/status/2104940667457753420), Intents is a crosschain layer atop NEAR rather than part of the chain's consensus. SHIELD decides which trades Intents will execute, but it can't freeze NEAR wallets or reverse completed transactions. > [ — (@) > ](https://twitter.com/mert/status/2104940667457753420) Thus the Bitget incident was an example of SHIELD stopping hackers while not affecting/preventing/unmasking regular users. They were essentially blocked at the entrance once questionable addresses appeared in SHIELD. But could this system be abused in the future? For example, we can imagine a despotic government putting out formal calls for stopping the legitimate funds of its domestic political opposition. In that case, though, I’d imagine SHIELD would reject the requests, or people would fork off the questionable addresses. This implementation is certainly an opinionated, moral implementation that makes NEAR unviable for moving large amounts of illicit funds. It also positions NEAR as the compliant alternative to its more impartial competitor, THORChain (which facilitated 72% of the stolen ETH moved after the $1.4B Bybit Hack in February 2025). Both projects have certain human levers in various places. Yet one has become a crosschain powerhouse that turns away stolen funds, while the other has become the go-to exit ramp for crypto’s biggest heists. To be clear, I think it’s good that there are neutral chains, networks, apps, etc. How to deal with crime in these contexts is complicated and always comes with tradeoffs and different philosophies. I just also think it’s good to experiment with new techniques to stop the scourge of North Korean hacks. > [ — (@) > ](https://twitter.com/TrustlessState/status/2104955420401955273) And still SHIELD’s no panacea. The Bitget funds that it blocked were simply routed by the culprits to other protocols. That's why NEAR co-founder Illia Polosukhin has [pitched SHIELD](https://x.com/ilblackdragon/status/2104706901837795348) as shared infra that other protocols can plug into, improving data for the ecosystem. If this leads to a new paradigm of solutions that are private for users but hostile to thieves, and with open transparency around their key levers, then the mechanism was definitely worth trying. Now let’s see if other high-profile crypto projects adopt this approach, too. --- *This article is brought to you by [NEAR](https://www.bankless.com/sponsor/near-1785257427?ref=read/near-stopped-bitget-s-hackers-without-breaking-privacy)*