Bitget hackers hunt new laundering routes as NEAR Intents and Chainflip turn them away

- NEAR Intents and Chainflip have both refused Bitget attacker funds, while THORChain kept processing swaps.
- The Bitget attackers, sitting on about $388 million stolen on September 24, are testing one cross-chain swap service after another.
- DeFi protocols are debating whether “permissionless” means they must serve users moving stolen funds.
The suspected North Korean attackers who stole roughly $388 million in the September 24 Bitget hack have started to run into roadblocks as the industry has continued to rally to plug exit routes.
As of September 29, NEAR Intents and Chainflip, two cross-chain swap services, have joined Tether and Circle on the list of protocols to have either turned away or frozen funds related to the hack.
NEAR Intents and Chainflip reject more than $50 million from Bitget hack
NEAR Intents general manager Alex Shevchenko said that the Bitget attackers tried to move more than $50 million through the protocol, but almost nothing got through.
Shevchenko estimated that only about $166,000 was processed through the platform, while $503,000 was frozen mid-swap and the rest was refused outright.
However, those rejected funds, according to Shevchenko, simply “went to other providers.”
NEAR Intents is a protocol that lets people trade assets across blockchains and averages more than $100 million in daily cross-chain volume.
Shevchenko credits SHIELD for blocking the fund flow, a system he says is a risk-intelligence layer that decides whether to ignore a quote or halt a swap already in flight by pulling signals from know-your-transaction vendors, researchers and large centralized players.
Blockchain-tracking firm MistTrack also reported that Chainflip rejected and refunded money from the Bitget exploiter.
THORChain is waving Bitget hackers through
THORChain is not one of the firms to reject funds from the Bitget hack, declining Bitget CEO Gracy Chen’s public request, as Cryptopolitan reported.
THORChain’s response was that the only real lever it has is an emergency network halt, which protects the whole protocol and “is not a selective freeze of specific funds or an individual swap.”
A September 28 CoinDesk review of THORChain’s public records caught about 2,390 ETH swapped into 75.2 BTC. The transactions worth roughly $6.3 million took about 27 swaps, all consolidated in a single address.
The Bybit hackers used the same route in 2025, pushing THORChain’s volume over $3 billion in five days.
Does ‘permissionless’ mean no intervention in DeFi?
NEAR Intents’ post about not processing the marked Bitget hack funds was not popular across every sector, sparking debates about what the “permissionless, open and uncensorable” label actually means.
Vini Barbosa, a technical writer building at Ramp Labs, pushed back on September 28: “permissionless does mean neutral,” he wrote to Shevchenko, calling it “the whole point of building something permissionless.”
Shevchenko rejected the premise in his response, writing: “But permissionless doesn’t mean neutral,” adding that “The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours.”
He framed it around property rights, arguing that a system where theft grants “an unrestricted right to monetize” stolen assets “is simply a system that protects the thief.”
NEAR Intents also said it would waive the 5% freeze and 5% recovery bounties Bitget is offering, so more of the money can return to the exchange, and that frozen funds will stay locked pending a legal process.
Shevchenko did not spell out who authorizes their release or how a wrongly flagged user gets money back.
What Bitget is doing meanwhile
Bitget disclosed the breach on September 24, later revising the loss up from an initial $351.6 million after Zcash and TRON transfers were counted. Chen has said an attacker exploited a third-party security product to obtain internal credentials rather than stealing private keys, with Mandiant and SlowMist assisting.
Circle and Tether have frozen roughly $318,000 in USDC and USDT tied to the wallets, and the exchange is restarting withdrawals in phases and running its recovery bounty.
The exchange has now opened the withdrawal service for ETH on the Ethereum, BSC, Arbitrum One, BASE, and Optimism networks, following the resumption of Bitcoin withdrawals.
Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.
FAQs
How much of the Bitget hacker's funds did NEAR Intents actually stop?
NEAR Intents said the attackers attempted to move more than $50 million through it, of which it froze $503,000 mid-swap and let about $166,000 pass, with the rest refused and routed to other providers, according to general manager Alex Shevchenko.
Why won't THORChain block the Bitget attacker addresses?
THORChain says its only intervention, an emergency network halt, is meant to protect the whole protocol and cannot selectively freeze one address or swap, so it rejected Bitget CEO Gracy Chen's September 26 request to refuse service to the attacker's wallets.
How did the Bitget attackers lose access to Chainflip?
According to MistTrack's September 29 post, the exploiter's attempt to move stolen funds through Chainflip was rejected by the broker and refunded, so no swap went through and no funds were frozen.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.
















