
NEAR Intents says SHIELD blocked $50M+ in Bitget hack laundering attempts, while $166K slipped through and $503K was frozen.
Author: Akshay
29th September 2026 āĀ NEAR Intents said its SHIELD system blocked more than $50 million in attempted laundering tied to the Bitget hack. The claim landed on September 28, 2026. It quickly became one of the most debated numbers in crypto security this year.
High Signal Summary For A Quick Glance
Rain
@raintures
@Cointelegraph real time transaction screening is becoming increasingly important for crypto security
šØ TODAY: NEAR Intents says its SHIELD system rejected over $50M in Bitget hack funds and froze $503K mid-transaction. https://t.co/C4uxBFlI2v
08:21 AMĀ·Sep 29, 2026
āš¼š
@rexnotrekt
@Cointelegraph thatās a massive win for infra, finally something actually protecting the users.
šØ TODAY: NEAR Intents says its SHIELD system rejected over $50M in Bitget hack funds and froze $503K mid-transaction. https://t.co/C4uxBFlI2v
05:11 AMĀ·Sep 29, 2026
High attention and emotional sentiment detected.
The figure needs context. Only about $669,000 actually moved through the platform, according to NEAR Intents. So the headline number describes rejected quotes, not funds seized.
NEAR Intents GM Alex Shevchenko posted the primary account on X. He said SHIELD detected $50 million-plus in laundering flows after filtering duplicates. He also flagged a self-declared error band of up to 10%.
The real interactions were small. About $166,000 slipped through, according to Shevchenko. SHIELD then froze another $503,000 mid-execution, and that sum now sits restricted pending recovery.
No public transaction hashes back the $50 million yet. Shevchenko cited internal logs, the Bitget tracer, and Arkham data. So far, no independent firm has published a matching on-chain reconstruction.
The Bitget hack began at 18:31 UTC on September 24, 2026. Attackers drained several hot wallets across eight networks. Bitget first estimated the loss at $351.6 million in its security notice.
On September 25, Bitget revised the confirmed outflow to about $387.5 million. It added Zcash and TRON assets to the count. The company called it fuller accounting, not a second theft.
CEO Gracy Chen said the attackers never stole a private key. Instead, a zero-day in a third-party security product handed them high-level credentials. They then injected fake withdrawal commands into wallet backend systems.
Two tiny test transfers moved first, both below risk thresholds. Larger withdrawals followed about 30 minutes later. Reconciliation flagged the gap at 19:05 UTC, so Bitget paused withdrawals.
Chen counted 17 transactions across eight networks between 18:58 and 20:09 UTC. Together they moved about $361 million, by her account. Bitget also pointed to a User Protection Fund of more than $464 million to cover users.
The September 2026 Bitget breach involved a compromised wallet-backend path, followed by multi-chain laundering attempts and NEAR Intents refusing most attacker quotes.
Bitget detects unauthorized hot/warm-wallet transfers. The first tests were 0.184 ETH and 193 TRX, while cold wallets remained untouched.
Multiple signing waves drain assets across eight networks. Bitget later reported an initial loss of about $351.6 million.
Bitget adds Zcash and TRON to the confirmed outflow, publishes attacker receivers, and announces a 5% freeze plus 5% recovery bounty.
Attackers attempt more than $50M through NEAR Intents. SHIELD refuses most quotes, while about $166K completes and about $503K is frozen mid-execution.
Gracy Chen asks THORChain to refuse listed attacker addresses. THORChain declines selective freezes; Chainflip is separately reported to have rejected funds.
Bitget begins a phased withdrawal restart, with Bitcoin withdrawals going first.
Alex Shevchenko reports that NEAR Intents refused most attacker flows, froze about $503K, and waived Bitgetās 5%+5% bounty.
Gracy Chen thanks NEAR Intents and SHIELD. Illia Polosukhin explains that permissionless infrastructure can still refuse suspicious application flows.
The roughly $503K frozen through Intents remains restricted pending legal and recovery processes. The wider $50M+ attempted flow was mostly refused, not seized.
The gap between $50 million and $669,000 matters. SHIELD screens swaps at quote time and during execution. When it refuses a quote, the stolen funds simply route elsewhere.
That is exactly what happened here. Rejected flows later went to other providers, according to Shevchenko. So āblocked $50 millionā means refused demand, not recovered money.
Independent coverage stressed the same point. CoinDesk and AInvest both noted that only about $669,000 touched the rails. AInvest also highlighted the 10% mislabeling risk in the data.
Other players moved faster on the parts they could reach. Circle and Tether froze roughly $318,000 in stablecoins at address 0xe07bd590e1198666230932bad5db3dbbe21e7d57 on September 25. That freeze happened on-chain, so anyone can verify it.
THORChain took a different path. It declined to block specific attacker addresses. CoinDesk reported that about $6.3 million in ETH became BTC through one linked wallet.
Cryptopolitan reported that Chainflip also turned some funds away. So the response split across venues. Some screened the flow, while others let it pass.
The intercept reignited an old fight over what āpermissionlessā should allow. NEAR co-founder Illia Polosukhin argued that open money does not force every app to process every transaction. Refusing to launder stolen funds is a choice, he said.
Critics pushed back hard. Developer Vini Barbosa said permissionless does mean neutral, calling it the whole point. Others argued that SHIELD makes NEAR Intents permissioned at the app layer.
Shevchenko framed it as a values call. He said crypto cannot demand property rights while optimizing for stolen property. Still, even he admitted the rejected funds moved on.
Not everyone read the post as pure defense. Analyst zacodil called it partly a SHIELD product launch. The bounty waiver, he noted, doubles as smart announcement design.
The NEAR token barely flinched on the news. It traded near $4.77 on September 29, down about 4% on the day, according to CoinDesk data. Still, NEAR sat up roughly 160% over the prior month.
That rally started well before the SHIELD post. So analysts warn against crediting the whole move to this single event. Bitgetās own BGB token slipped to about $1.96 on September 25, then recovered toward $2.00.
NEAR Intents also waived its Bitget bounty. The program pays 5% of frozen funds plus 5% of recovered funds. The team declined its share so Bitget can return more to users.
Bitget has resumed withdrawals in phases and engaged Mandiant and SlowMist. TRM Labs flagged Lazarus-adjacent clues, though nobody has confirmed North Korea. The frozen $503,000 still waits on a legal process.
The bigger question now sits with builders. More screening tools may follow if this model spreads. For traders, the takeaway is blunt: stolen funds face more friction, yet determined actors still find open doors.
None of this is financial advice. NEAR Intents just showed that app-layer defense can bite, even if it cannot catch every dollar.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check ourĀ Terms and conditions for more info.
NEAR Intents Says SHIELD Blocked $50M in Bitget Funds
Cosmos Links Banks to Swift Ledger for Cross-Border Payments
RLUSD Supply Hits Record High, Nears PYUSD Market Cap
Solana Alpenglow Goes Live on Devnet TowerBFT Retired
NEAR Intents Says SHIELD Blocked $50M in Bitget Funds
Cosmos Links Banks to Swift Ledger for Cross-Border Payments
RLUSD Supply Hits Record High, Nears PYUSD Market Cap
Solana Alpenglow Goes Live on Devnet TowerBFT Retired