A dispute between cross-chain protocols THORChain and NEAR Intents over the handling of funds stolen in the $387.7 million BitGet hack has highlighted a growing divide in the crypto industry over how far permissionless systems should go in preventing illicit transactions.
MILESTONE | BitGet Says Stolen Funds Nearing $400 Million as Security Breach Unfolds
About $387.5 million of stolen assets began moving across blockchains after the September 24 2026 BitGet breach, with some funds routed through THORChain. BitGet CEO, Gracy Chen, urged THORChain to block addresses linked to the attacker but the protocol declined arguing that selectively blocking transactions would conflict with its permissionless design.
REALITY CHECK | Why BitGet Hacker Used THORChain to Move Stolen Funds
THORChain developer, Boone Wheeler, said a truly permissionless protocol cannot intervene based on the provenance of funds because doing so would make it permissioned. The protocol had previously faced criticism after funds linked to the $1.2 billion ByBit hack were moved through its network.
CRYPTO CRIME | ByBit Sues North Korea Over the $1.5 Billion Hack in 2025, Secures Asset Freeze
NEAR Intents took a different approach.
Its automated SHIELD security system identified more than $50 million in attempted flows linked to the BitGet hack and blocked about $503,000 during execution, while $166,000 passed through, according to the report. NEAR said its system uses onchain data, internal anti-money-laundering signals and third-party intelligence to identify suspicious flows.
NEAR General Manager, Alex Shevchenko, said the underlying NEAR blockchain remains permissionless but individual applications built on it do not necessarily have to process every transaction. The approach has drawn criticism from advocates of strict censorship resistance who argue that intervention undermines the meaning of a permissionless system.
The debate also exposes a practical distinction between decentralised infrastructure and applications operating on top of it.
CASE STUDY | How This Hack Set a Precedent for Freezing Stolen Stablecoins Without Legal Request
THORChain maintains that it has no mechanism to screen individual addresses or transactions while acknowledging that its network can halt activity during protocol-level emergencies.
NEAR, meanwhile, argues that automated controls can protect users and the wider ecosystem without relying on manual intervention by a compliance team.
The dispute reflects a broader question for the crypto industry as decentralised financial infrastructure handles increasingly large sums, whether neutrality should remain absolute when protocols can identify stolen funds, or whether protecting users and preventing money laundering justifies targeted intervention.
The answer could shape how cross-chain protocols balance censorship resistance, security, and regulatory expectations as their role in the digital-asset economy grows.
CRYPTO CRIME | Why BitGet Hacker Was Able to Move Over $80 Million in Stolen XRP
Sign up to BitKE to get the latest updates on crypto globally.
Join our WhatsApp channel here.
Follow us on X for the latest posts and updates
Join and interact with our Telegram community
_________
