en
Back to the list

The Bitget hack split the cross-chain market into two products

source-logo  cryptobriefing.com 52 m
image

The $388 million drained from Bitget last week had to move before it could be spent, and cross-chain swap services are where stolen crypto moves. Two of them handled funds from the same theft in the same week and answered differently. $NEAR Intents, a swap service that routes exchanges between blockchains through a network of solvers, blocked more than $50 million in attempted transfers linked to the theft, according to a report by general manager Alex Shevchenko. THORChain, the largest decentralized swap network, processed about $6.3 million in ether-to-bitcoin swaps from a wallet tied to the attack and declined Bitget’s request to block the addresses involved. One network screens its flow. The other promises it never will.

A marketing claim meets live attacker money

The screening system behind the block, SHIELD, froze about $503,000 mid-transaction, and roughly $166,000 passed through before detection caught up, Shevchenko wrote. The $50 million counts refused transfer attempts with duplicates removed, carries an error margin he put at about 10%, and measures volume the service turned away rather than money it holds.

SHIELD works by screening quote flows against TRM Labs, AMLBot, PureFi and Binance AML data alongside an internal AML database, according to the service’s risk and compliance documentation. The test those providers passed last week ran on live attacker money, the kind of exercise no compliance vendor can stage in a pilot.

More Than Just News
Content, live market tracking, portfolio management, and price alerts — everything you need in the Crypto News app.
Download now, stay on top of the crypto market, and take control of your information.

Shevchenko framed the blocked figure against the service’s ordinary business. $NEAR routinely processes more than $100 million in daily volume, he noted, and the refusals were a negligible fraction of it. The screening did not cost the business its flow.

Cross-chain infrastructure has long been treated as structurally unable to stop stolen funds, with no operator to call and no account to freeze. The Bitget flows show the constraint is a choice. A service that takes custody mid-swap, even briefly, can screen at that moment, and whether it does is a business decision rather than a technical limit.

Permissionless, with boundaries

$NEAR markets itself as permissionless, open and uncensorable, and a service that can freeze funds halfway through a swap is doing something most people would call permissioned. Vini Barbosa, a technical writer building at Ramp Labs, wrote on X that permissionless has to mean neutral, and that a rail willing to restrict suspected unlawful users will also restrict people moving money under repressive governments.

Cofounder Illia Polosukhin answered in narrower terms: permissionless means nobody needs permission to own assets, transfer them or deploy contracts. Shevchenko’s phrasing concedes the gap between the two positions. The service will remain “permissionless infrastructure, but with boundaries.”

Institutional users, the buyers every infrastructure provider is now chasing, generally prefer a rail that screens. THORChain argued the other position in public. “A halt is not a selective freeze of specific funds or an individual swap,” the protocol wrote on X. “THORChain is permissionless and doesn’t censor by design.” It asked what responsibility Bitcoin, Ethereum and BNB Chain bear when stolen funds move across them, and noted that the addresses that took $10.7 million from its own vaults in May were never blacklisted either. The answer was the same after the $1.5 billion Bybit theft last year.

While champions of decentralization support the decision, key names from the broader industry has pushed back. Bitget CEO Gracy Chen, whose request THORChain declined, wrote that decentralization “is a design principle, not a shield for facilitating known stolen funds.” OKX founder Star Xu disputed the Bitcoin comparison from the other direction: THORChain’s validators jointly control the assets in its vaults, which makes the network an intermediary rather than a base layer, and the same node operators halted it for 39 days in May when its own vaults were at stake.

At a third layer sit the stablecoin issuers. Circle and Tether froze about $320,000 in USDC and USDT linked to the Bitget breach, a rounding error against the total loss but a reminder that issuer-level freezing remains the most reliable circuit breaker in crypto, because it operates on the asset rather than the application.

The frozen $503,000 has no owner of record

$NEAR is holding the intercepted $503,000 pending a legal and recovery process, and has waived any recovery bounty Bitget offered. Formal requests route through a Kodex law-enforcement portal, the channel where Bitget or investigators would formally claim the funds. Shevchenko’s report does not name who can authorize a release, and it describes no process for a wrongly flagged user to get money back. The screening that produced the freeze operates on estimates with a stated error margin of 10%.

A screen that halts a legitimate transfer, with no published release authority and no remedy, is a service holding someone’s money on suspicion. The securities and payments industries resolved that problem with defined processes, because holding funds without one is a liability in almost every jurisdiction. Crypto’s screening layer has reached the same point without the process.

The first dispute over the $503,000 will test whether the release of those funds follows a rule anyone can see.

cryptobriefing.com