This is the latest development in Bitget’s September 24 security incident, and it is different from the THORChain exchange that was reported earlier as a separate service’s handling. On September 29, Alex Shevchenko, CEO of NEAR Intents, said that the funds related to the attack had attempted to exchange for more than $50 million through NEAR Intents; its SHIELD risk-control system blocked most requests. About $503,000 was temporarily frozen while the exchange was in progress, and about $166,000 went through using this service. The rejected funds then mostly moved on to other services. The above amounts are NEAR’s estimates; after excluding repeated attempts, the figures may still differ from the actual values by about 10%.
To break down the three numbers separately: $50 million is the exchange attempt amount, not the amount recovered. $503,000 is the money currently being held back, pending legal and recovery procedures; it does not mean it has been returned to Bitget. $166,000 is allegedly the portion processed through the service. NEAR Intents says SHIELD determines whether to delay or deny requests based on comprehensive signals from abnormal cross-chain on-chain traffic, KYT and intelligence providers, and information from researchers and institutions. NEAR co-founder Illia Polosukhin’s response was: users do not need permission to hold assets, transfer them, or deploy contracts, which does not mean every application must process every transaction.
【My take】
The focus of this update is not that the attack funds suddenly decreased by $50 million, but that cross-chain exchange services showed a risk-handling approach different from THORChain. THORChain previously refused to selectively intercept by address; NEAR Intents, using SHIELD at its own exchange entry point, identifies risk and holds back a small amount of funds mid-transfer. Neither can control all on-chain wallets, and there is no evidence that the rejected funds therefore disappeared. The reports say that most of them switched to other services, suggesting that screening by a single platform may raise the cost of money laundering, but it is difficult to independently stop the transfer of funds.
The main transmission of such security incidents to the crypto market lies in the availability of cross-chain services, the boundaries of asset freezing, and user trust. They should not be directly inferred as an increase in demand for $NEAR tokens, or as attacked assets inevitably forming spot sell pressure. NEAR’s link to this event is through Intents services and their SHIELD handling. Binance spot NEARUSDT was queried at 15:16 Beijing time on September 29, 2026. The rolling 24-hour quoteVolume is about $234.2 million USD, with a price change of about -0.6%. The data only shows trading activity for that specific spot pair; it cannot prove the incident affected the price, nor does it represent total market trading volume.
For ordinary users, before doing a cross-chain swap, verify the service’s risk controls and pause rules, the target network, settlement conditions, and the appeal channels. If your request is delayed or frozen, submit the transaction hash and fund-source materials through official support and law-enforcement channels, and do not transfer money to so-called “recovery teams.” When using the service, you can first run small test transactions and prepare alternative routes for urgent funds, but do not split or reroute suspicious funds in an attempt to bypass risk controls.
Going forward, we should watch whether NEAR Intents will publish verifiable SHIELD hit-rate standards, the legal authorization for frozen funds and the release procedures, and the appeal path for users wrongly flagged. Also check whether Bitget or law-enforcement agencies confirm the recovery outcome. If final verification shows the intercepted amount is far lower than estimated, or the held funds cannot be handled legally and normal users lack effective appeal mechanisms, the positive assessment of this risk-control model should be reduced. If public rules, wrongful-flag remediation, and cross-service coordination are validated, then it would better demonstrate that it both limits abuse and controls adverse effects on ordinary users.
Source: CoinDesk, September 29, 2026 (report and cited public remarks from NEAR Intents’ general manager and public response from NEAR co-founder)
https://www.coindesk.com/tech/2026/09/29/usd50-million-in-bitget-hacker-swaps-puts-near-intents-permissionless-claim-to-the-test
NEAR Intents documentation (service overview and risk-check explanations): https://docs.near-intents.org/near-intents/
Market data: Binance spot public REST API, NEARUSDT, rolling 24 hours, query time 15:16 on September 29, 2026 (Beijing time); no contract quotes are cited.
The above is personal analysis and does not constitute investment advice.
#加密安全 #跨链 #NEAR
To break down the three numbers separately: $50 million is the exchange attempt amount, not the amount recovered. $503,000 is the money currently being held back, pending legal and recovery procedures; it does not mean it has been returned to Bitget. $166,000 is allegedly the portion processed through the service. NEAR Intents says SHIELD determines whether to delay or deny requests based on comprehensive signals from abnormal cross-chain on-chain traffic, KYT and intelligence providers, and information from researchers and institutions. NEAR co-founder Illia Polosukhin’s response was: users do not need permission to hold assets, transfer them, or deploy contracts, which does not mean every application must process every transaction.
【My take】
The focus of this update is not that the attack funds suddenly decreased by $50 million, but that cross-chain exchange services showed a risk-handling approach different from THORChain. THORChain previously refused to selectively intercept by address; NEAR Intents, using SHIELD at its own exchange entry point, identifies risk and holds back a small amount of funds mid-transfer. Neither can control all on-chain wallets, and there is no evidence that the rejected funds therefore disappeared. The reports say that most of them switched to other services, suggesting that screening by a single platform may raise the cost of money laundering, but it is difficult to independently stop the transfer of funds.
The main transmission of such security incidents to the crypto market lies in the availability of cross-chain services, the boundaries of asset freezing, and user trust. They should not be directly inferred as an increase in demand for $NEAR tokens, or as attacked assets inevitably forming spot sell pressure. NEAR’s link to this event is through Intents services and their SHIELD handling. Binance spot NEARUSDT was queried at 15:16 Beijing time on September 29, 2026. The rolling 24-hour quoteVolume is about $234.2 million USD, with a price change of about -0.6%. The data only shows trading activity for that specific spot pair; it cannot prove the incident affected the price, nor does it represent total market trading volume.
For ordinary users, before doing a cross-chain swap, verify the service’s risk controls and pause rules, the target network, settlement conditions, and the appeal channels. If your request is delayed or frozen, submit the transaction hash and fund-source materials through official support and law-enforcement channels, and do not transfer money to so-called “recovery teams.” When using the service, you can first run small test transactions and prepare alternative routes for urgent funds, but do not split or reroute suspicious funds in an attempt to bypass risk controls.
Going forward, we should watch whether NEAR Intents will publish verifiable SHIELD hit-rate standards, the legal authorization for frozen funds and the release procedures, and the appeal path for users wrongly flagged. Also check whether Bitget or law-enforcement agencies confirm the recovery outcome. If final verification shows the intercepted amount is far lower than estimated, or the held funds cannot be handled legally and normal users lack effective appeal mechanisms, the positive assessment of this risk-control model should be reduced. If public rules, wrongful-flag remediation, and cross-service coordination are validated, then it would better demonstrate that it both limits abuse and controls adverse effects on ordinary users.
Source: CoinDesk, September 29, 2026 (report and cited public remarks from NEAR Intents’ general manager and public response from NEAR co-founder)
https://www.coindesk.com/tech/2026/09/29/usd50-million-in-bitget-hacker-swaps-puts-near-intents-permissionless-claim-to-the-test
NEAR Intents documentation (service overview and risk-check explanations): https://docs.near-intents.org/near-intents/
Market data: Binance spot public REST API, NEARUSDT, rolling 24 hours, query time 15:16 on September 29, 2026 (Beijing time); no contract quotes are cited.
The above is personal analysis and does not constitute investment advice.
#加密安全 #跨链 #NEAR