📈 Get daily crypto insights that make you smarter about your money

THORChain Let 387.5 Million USD in Stolen Bitget Funds Pass Through — and the Fight Over Permissionless Ideals Is Splitting DeFi

When 387.5 million USD in stolen Bitget funds started moving through cross-chain swap protocols, two rival platforms made opposite choices — and the fight over who was right has split the crypto industry down its oldest fault line: should permissionless technology ever refuse to touch stolen money?

By David Chen | October 5, 2026

The Hook: One Hack, Two Answers

After the Bitget exchange was hacked on September 24, 2026, the stolen funds quickly began moving across blockchains — and a chunk of them headed for THORChain, a decentralized platform that lets people swap tokens between different blockchains without a middleman.

Bitget chief executive Gracy Chen publicly appealed to THORChain to refuse service to the attacker’s addresses, warning that “the industry is watching.” THORChain refused the request and kept processing the swaps, Cointelegraph Magazine reported in a long-form piece published October 2.

Meanwhile, NEAR Intents, a competing cross-chain transaction protocol, did the opposite. Its automated security layer, called SHIELD, flagged hack-linked flows and stepped in. The contrast between the two responses has ignited a furious debate about what “permissionless” — technology anyone can use without asking permission — actually requires.

On-Chain Evidence: What Each Protocol Actually Did

The numbers from the NEAR Intents side, as reported by Cointelegraph: SHIELD identified more than 50 million USD in attempted flows linked to the Bitget incident. It stopped 503,000 USD during execution, while 166,000 USD passed through. NEAR also waived its share of Bitget’s recovery bounty.

  • 387.5 million USD — total funds stolen from Bitget on September 24
  • Over 50 million USD — hack-linked flows SHIELD identified attempting to cross NEAR Intents
  • 503,000 USD — amount SHIELD blocked during execution
  • 166,000 USD — amount that slipped through
  • 1.2 billion USD — funds from the Bybit hack that previously moved through THORChain

THORChain developer Boone Wheeler defended the platform’s stance in stark terms: “A truly permissionless protocol can do nothing when it encounters known stolen funds — it is blind to their provenance. If THORChain were able to block specific stolen funds, it would not be permissionless.”

The Core Conflict: Where Does Permissionless End?

Critics point out that THORChain was not always so absolutist. In May 2026, validators voted to halt the chain after an attacker exploited a vulnerability and drained over 10 million USD from one of its vaults. If the protocol can pause itself to protect its own solvency, the argument goes, why can it not act when stolen funds flow through it?

THORChain’s answer: the May halt was triggered automatically by its own safety checks — the protocol halting to fix a problem with itself — and Wheeler says there is simply “no functionality to screen individual addresses or transactions.” That blindness, he says, was a deliberate design choice.

NEAR’s position is more nuanced. General manager Alex Shevchenko argues the base layer stays fully permissionless — anyone can transact or deploy on it — but “that does not mean every application built on NEAR must process every request.” In his framing, SHIELD is not a compliance department; it is an automated system using public onchain data, an internal anti-money-laundering database and third-party intelligence to apply targeted controls.

Crypto lawyer Yuriy Brisov believes that automation matters legally. Because no human team is manually approving or blocking transactions, he argues NEAR Intents could still fall within legal protections afforded to decentralized protocols. “There is no compliance team, people who sit there and control the operation manually. This is a smart solution, and that’s what we recommend to all the DeFi companies,” he said.

Not everyone is convinced. The libertarian counterargument was laid out bluntly by Joël Valenzuela, head of business development at Dash: permissionless protocols “should not draw the line anywhere when stolen funds are identified, because being able to do so at all makes them permissioned.” The moment a protocol can block anyone, he says, “you open Pandora’s Box” to censoring innocent users too.

Market Implications: Clean Rails May Win the Flows

For a regular investor, this debate is not academic philosophy — it shapes which platforms institutions will touch. Bitget’s Chen says she understands different protocols have different technical capabilities, but draws a line between permissionless infrastructure and “facilitating the movement of known stolen funds,” and she welcomed NEAR’s cooperation.

Max Shannon, senior research associate at Bitwise Europe, predicted the practical consequence: THORChain’s stance will likely push more laundering flows its way and away from NEAR Intents. He called refusing to launder hack proceeds a “sound stance” for young protocols trying to earn trust, and dismissed “credible neutrality at all costs” as a cypherpunk ideal whose champions “rarely ask … what it costs.”

The SHIELD system has already proven it works beyond the Bitget case: it flagged the suspicious behavior behind a 3.8 million USD exploit of an Omni deposit-withdrawal interaction on NEAR Intents and halted activity — and the protocol later recovered the entire stolen amount after issuing an ultimatum to the exploiter.

The Verdict: Two Philosophies, Your Choice

What this really exposes is that “decentralized” is not a yes-or-no switch — it is a spectrum, and every project sits somewhere different on it. THORChain sits at the uncompromising end: truly blind, truly neutral, and openly comfortable being the rail stolen funds can use. NEAR Intents occupies the middle ground: open at the base layer, but with an automated tripwire that catches known-bad flows.

If you hold crypto, the practical takeaway is simple. If you ever need to move funds across chains, the platform you choose now carries a philosophy along with your money. One will never question your transaction — including, unfortunately, a thief’s. The other might pause a suspicious transfer — which is reassuring if you are a victim, and a reminder that someone, or something, is watching the pipes.

Which model wins long-term may decide whether decentralized finance grows up to be the censorship-resistant alternative it promised — or something closer to the traditional financial system, rebuilt on a blockchain.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

17 thoughts on “THORChain Let 387.5 Million USD in Stolen Bitget Funds Pass Through — and the Fight Over Permissionless Ideals Is Splitting DeFi”

  1. 387.5M in stolen Bitget funds and THORChain just kept the swaps flowing because permissionless. ideology is great until youre the one who got hacked i guess

    1. ideology is great until youre the one who got hacked is exactly it. bitget ate a 387.5M loss and thorchain still booked the volume. neutrality that pays you fees isnt neutral, its just business

    2. gracy Chen warned them publicly and they still processed everything. thats not neutrality, thats a cut of the fees talking

      1. gracy chen flagged those wallets publicly and routing still went through. seeing the warning and processing anyway is a choice, not neutrality

  2. boone wheeler calling the protocol blind to provenance is wild when twitter was tracking those exact bitget wallets in real time. blind is a choice here

    1. Celeste Marquez

      Boone Wheeler calling the protocol blind never sat right with me either. Twitter had those wallets tagged within the hour, so the data existed. The protocol just has no lever to pull once it sees it.

    2. to be fair the moment you start freezing swaps you get the opposite problem. who decides what counts as stolen? slippery both ways

    3. blind is a choice is easy to say from outside. a protocol that blocked the swap would have just pushed it to the next router, same money moves anyway

  3. The NEAR Intents comparison is what makes this interesting. SHIELD caught over 50 million in hack linked flows automatically, no team vote needed. Shows you can have controls without becoming a gatekeeper.

    1. SHIELD catching 50M in hack flows automatically is the strongest point in this thread. router level controls with no snapshot vote theater and no team playing judge

    2. Brisov makes a fair point in the piece. automated blocking looks better legally than a team manually deciding, even if the outcome is similar

      1. brisov has a point on optics. a team manually approving a flagged 387.5m flow reads far worse in court than an automated filter missing it

    1. free marketing is exactly right. every degen watching this saga now knows which router does not ask questions when the next nine figure hack moves

  4. genuinely wondering what freezing even looks like here. those funds hit thorchain within hours of the hack, nobody votes that fast

    1. twitter had those wallets tagged in under an hour so the data clearly exists. the filtering tech is there, the will to run it on a chaosnet is not

  5. blacklist_beacon

    near intents shield catching 50m in hack flows proves router level blocking works. thorchain ran the math and decided flagged volume still counts as volume

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$85,589.00+0.9%ETH$2,703.16+0.4%SOL$120.40-0.3%BNB$789.28+0.6%XRP$1.50+0.8%ADA$0.2656+9.3%DOGE$0.0950+2.5%DOT$1.21+2.8%AVAX$10.90-1.3%LINK$14.07+0.3%UNI$8.99-0.4%ATOM$1.73+1.4%LTC$70.11-0.2%ARB$0.2005-0.9%NEAR$4.83+0.7%FIL$1.05-0.9%SUI$1.22+3.6%BTC$85,589.00+0.9%ETH$2,703.16+0.4%SOL$120.40-0.3%BNB$789.28+0.6%XRP$1.50+0.8%ADA$0.2656+9.3%DOGE$0.0950+2.5%DOT$1.21+2.8%AVAX$10.90-1.3%LINK$14.07+0.3%UNI$8.99-0.4%ATOM$1.73+1.4%LTC$70.11-0.2%ARB$0.2005-0.9%NEAR$4.83+0.7%FIL$1.05-0.9%SUI$1.22+3.6%
Scroll to Top