Key Points:
- The movement of roughly $387.5 million in stolen Bitget funds has intensified debate over whether decentralized protocols should intervene when illicit assets are identified.
- THORChain declined to block attacker-linked funds, while NEAR Intents’ automated SHIELD system identified more than $50 million in attempted flows and stopped $503,000 during execution.
- The dispute highlights a broader distinction between permissionless blockchain infrastructure and individual applications that may implement automated security controls.
The movement of hundreds of millions of dollars in stolen cryptocurrency following the Bitget hack has reopened a fundamental debate across decentralized finance: whether a protocol can remain permissionless while actively preventing the movement of known stolen assets.
After Bitget suffered a $387.5 million hack on Sept. 24, some of the stolen funds began moving across blockchain networks, including through decentralized cross-chain infrastructure. Bitget CEO Gracy Chen publicly asked THORChain to block addresses associated with the attackers.
THORChain declined, arguing that preventing specific transactions would conflict with the protocol’s permissionless design. The decision has since triggered competing arguments over whether decentralized infrastructure should remain neutral even when its operators or participants can identify potentially illicit flows.
THORChain Defends Permissionless Architecture
THORChain developer Boone Wheeler said a genuinely permissionless protocol cannot selectively determine whether individual funds are legitimate based on their history.
“A truly permissionless protocol can do nothing when it encounters known stolen funds,” Wheeler said, arguing that the ability to block specific stolen assets would mean the protocol was no longer fully permissionless.
The position follows THORChain’s handling of the Bybit hack, when approximately $1.2 billion in stolen funds were reportedly routed through the protocol.
Critics have nevertheless questioned whether THORChain’s commitment to neutrality has been applied consistently. In May, validators voted to halt activity after an attacker exploited a vulnerability and drained more than $10 million from one of THORChain’s vaults.
THORChain’s subsequent post-mortem said the protocol can automatically halt activity when its solvency checks detect an insolvency event. Node operators can also use emergency controls to pause trading, signing and other network functions.
Wheeler said those mechanisms are intended for active protocol-level problems rather than screening individual addresses or transactions.
NEAR Takes a Different Approach
NEAR Intents, a competing cross-chain transaction system, took a different approach following the Bitget incident.
Its automated SHIELD security system identified more than $50 million in attempted flows linked to the hack and stopped approximately $503,000 during execution. NEAR said roughly $166,000 nevertheless passed through the system.
NEAR also waived its share of Bitget’s recovery bounty.
NEAR Protocol general manager Alex Shevchenko distinguished the underlying protocol from applications built on top of it. He said NEAR remains permissionless because anyone can build on the network, transact or become a validator, while individual applications are not necessarily required to process every request.
The distinction has become central to the debate because NEAR Intents uses an automated security mechanism rather than a manual compliance team to intervene in transactions.
Automation Complicates the Decentralization Debate
The use of automated controls has created another layer to the argument over decentralization.
Crypto lawyer Yuriy Brisov said automated security mechanisms could potentially remain compatible with protections available to decentralized protocols because there is no centralized compliance team manually deciding which transactions to permit.
The model effectively separates permissionless blockchain infrastructure from application-level controls. A network can remain open to users and developers while applications built on it can establish their own transaction-processing rules.
That distinction, however, remains contested by critics who argue that intervention itself demonstrates a meaningful degree of centralized control.
Permissionless Does Not Mean Every Application Must Be Neutral
Bitget has acknowledged that different blockchain systems have different architectures, governance structures and technical capabilities. Chen said the company is particularly interested in understanding what can technically and operationally be done when stolen assets are identified.
She argued that permissionless infrastructure does not necessarily require the absence of mechanisms capable of detecting and responding to known illicit flows.
The distinction could become increasingly important as cross-chain protocols handle larger amounts of capital and become more frequently used to move assets between ecosystems.
Emergency Intervention vs. Individual Screening
THORChain’s architecture illustrates the tension between broad emergency intervention and selective transaction screening.
The protocol has mechanisms that can halt activity when its own solvency is threatened, but Wheeler said there is no functionality for screening individual addresses or transactions. The absence of such controls is intentional, according to THORChain.
This creates a technical boundary between stopping an entire protocol because of an active systemic problem and selectively preventing particular assets from moving through the network.
NEAR Intents’ approach effectively introduces that second layer through automated transaction screening, creating a different model for managing security risks without requiring manual intervention.
Outlook
The Bitget hack has exposed a continuing philosophical and technical divide within decentralized finance over the meaning of permissionless infrastructure.
THORChain’s approach prioritizes neutral transaction processing and avoids screening individual addresses, while NEAR Intents demonstrates a model in which applications can apply automated security controls while the underlying blockchain remains open.
As cross-chain infrastructure handles increasingly significant volumes, the distinction between permissionless networks, applications and automated security mechanisms is likely to remain an important issue for developers, users and the broader DeFi ecosystem.
Comparison, examination, and analysis between investment houses
Leave your details, and an expert from our team will get back to you as soon as possible