
Thanks to its SHIELD filter, the NEAR Intents protocol claims to have prevented the passage of funds stolen during the Bitget hack and frozen transactions in progress.
NEAR Intents claims to have blocked more than $50 million linked to the Bitget hack and froze an additional $503,000 using its SHIELD filter before solvers intervened.
AI-generated summary
Cross-chain exchange protocols are regularly targeted for laundering hacked funds, such as during the Bybit and Bitget cases.
Deadlock for stolen funds. NEAR Intents claims to have prevented the passage of more than $50 million related to the Bitget hack and froze an additional $503,000 after transactions were already initiated. The filter causing this blockage is called SHIELD, and it intervenes before any solver touches the funds.
Key Points
The SHIELD filter rejected around fifty million dollars linked to the theft suffered by Bitget
An additional half a million dollars was tied up while execution had started
The check takes place before the solvers handle the user request
The previous THORChain, criticized after the theft of 1.46 billion from Bybit, weighs on these arbitrages
SHIELD, the filter that cut off the Bitget hack funds
In fact, the blockage occurs upstream. The NEAR Intents user does not place an order in the traditional sense. It declares a desired outcome, converting bitcoin to USDC on Solana for example, and specialized actors called solvers compete for the right to execute it.
The funds pass through a deposit contract (which we recall is not an inter-chain bridge, the latter having concentrated a good part of the biggest thefts ever recorded). SHIELD intervenes at this step and compares incoming addresses to clusters already marked by on-chain analysis companies. Address reported, deposit refused.
The format attracts money launderers for one simple reason. An Intents swap converts native assets from one chain to another without creating a wrapped token, which breaks the thread that investigators usually follow. Classic bridges left at least a trace of locking and then emission. Here, the track is diluted in the solver.
The team still puts forward two figures. More than $50 million was blocked at entry, and $503,000 held up after routing had already begun. The second amount, more modest, is the most informative on a technical level.
Freezing assets during a transaction assumes that the protocol maintains control during execution. A classic atomic swap leaves no such window: once the transaction is signed and broadcast, no one catches up. By keeping the funds in a contract while the solver completes the operation, NEAR Intents gives itself a right of veto of a few seconds.
From Bybit to Bitget, the cross-chain under surveillance
This filtering reflex has a recent history, and it has been costly to those who have dispensed with it. In February 2025, the Bybit hack took away $1.46 billion in ether. The North Korean group Lazarus is held responsible. More than a billion dollars was then recycled through THORChain, whose validators collected several million dollars in fees in a handful of days. A developer of the protocol resigned publicly in the process.
eXch chose to refuse. The exchange platform without identity verification did not filter funds outflows from Bybit, and the German federal police seized its servers in April 2025 with 34 million euros in cryptocurrencies. Chainalysis has counted $1.34 billion stolen in 2024 by actors linked to North Korea across 47 separate incidents, or more than 60% of the global annual loot.
Automated filtering also has its detractors, and their argument is valid: a protocol capable of freezing $503,000 can freeze yours. NEAR Intents takes on the arbitrage and bets that clean cross-chain rails will attract more volume than it leaks. The calculation is justified, at a time when European and American regulators are scrutinizing these passages.

China's Ministry of State Security claims that the anonymity of cryptocurrencies is an illusion, explaining that all transactions leave traceable traces via fiat-crypto exchanges and IP addresses, and cites the Bitfinex affair as proof, while banning the use of Bitcoin on its territory despite tolerance of detention.

Four days after Bitget's $387.5 million theft, on-chain investigator ZachXBT claims Chinese intermediaries are laundering funds on behalf of suspected North Korean attackers, publicly asking for help on Discord and Telegram when their XRP-bitcoin swaps on THORChain fail, captures of support tickets and transactions show.

On-chain analyst Wazz claims to have identified a coordinated operation linked to 53 memecoin launches on Robinhood Chain, which extracted at least $18.43 million between July 10 and September 21, by exploiting a loophole in the Pons V2 anti-sniping tax to concentrate the supply and immediately resell to investors.

The UNCTAD statistics portal (UNCTADstat) underwent a massive automated collection of 16,000 requests between April and June 2026. IP addresses and identifiers suggest a link to OpenAI agents, although the site only contains public data.

Solana is testing Alpenglow, an overhaul of its consensus replacing TowerBFT and Proof of History. This protocol aims to reduce transaction finality from 12.8 seconds to 150 milliseconds, improving efficiency for payments and bridges.

Block has joined the x402 Foundation, integrating Bitcoin's Lightning Network into the payment standard for AI agents. This protocol, based on the HTTP 402 code, allows automated micropayments without a user account, alongside players like Google and Microsoft.