NEAR Intents says its compliance and security systems blocked attempts to move more than $50 million in assets stolen from Bitget, while another approximately $503,000 that entered its infrastructure was subsequently frozen.
The intervention followed the September 24 attack on Bitget, which the exchange now estimates affected $387.5 million in assets across multiple blockchains.
NEAR Intents said addresses associated with the attacker attempted to route stolen funds through its cross-chain liquidity infrastructure after the breach. Its automated screening systems identified and rejected transactions totaling more than $50 million before the assets could enter the Intents liquidity network.
A separate $503,000 linked to the attack did reach the system before being identified. NEAR said those assets were frozen.
The distinction is important: NEAR Intents did not seize or freeze the entire $50 million. It says its systems prevented attempted transactions worth more than $50 million, while approximately $503,000 represents assets that were actually frozen after entering the infrastructure.
Screening Stops Funds Before Settlement
NEAR Intents is designed to allow users to specify a desired outcome — such as exchanging an asset on one blockchain for another asset elsewhere — without manually executing every intermediate bridging and swapping step.
Independent market participants known as solvers compete to fulfill those requests.
That architecture can simplify cross-chain transactions but also makes intent-based systems potentially attractive to attackers attempting to convert stolen assets between networks.
NEAR Intents has incorporated transaction monitoring and address-screening systems intended to detect funds associated with hacks, sanctions and other identified illicit activity before solvers complete transactions.
In the Bitget case, those controls appear to have been triggered as the attacker attempted to move a substantial portion of the stolen assets through the system.
Blocking more than $50 million would represent over 12% of Bitget’s revised $387.5 million loss, although the attempted transactions should not be interpreted as additional losses beyond the hack itself.
The assets were already associated with the attacker; NEAR’s infrastructure was being used as a potential route for converting or moving them.
Bitget Attack Highlights Cross-Chain Laundering Challenge
Bitget initially estimated its September 24 loss at approximately $351.6 million before raising the figure to $387.5 million after incorporating additional affected Zcash and TRON assets.
The exchange has stressed that the revised total reflects more complete accounting rather than a second theft.
Security analysis has also indicated that the attackers did not obtain Bitget’s private keys. Instead, investigators including GoPlus have described the incident as a compromise of the exchange’s transaction-signing trust chain, in which malicious transaction information reached an otherwise authorized signing process.
Bitget has said the underlying vulnerability has been remediated and that cold wallets and customer balances were unaffected. It is working with security firms including Mandiant and SlowMist and has notified law-enforcement authorities.
The attack also illustrates how the response to major crypto thefts increasingly extends beyond the compromised exchange itself.
Attackers frequently attempt to split stolen assets across wallets, swap them into different cryptocurrencies and move them between blockchains to make tracing and recovery more difficult.
Public blockchains allow investigators and infrastructure providers to follow those movements in real time. Exchanges, stablecoin issuers, bridges and cross-chain protocols can then screen identified addresses or, where their systems permit, restrict transactions.
NEAR Intents’ intervention demonstrates how those controls can now operate inside cross-chain execution infrastructure itself.
It also exposes a broader tension for decentralized finance. Systems designed to move assets permissionlessly across networks increasingly incorporate screening mechanisms capable of rejecting identified funds.
In this case, NEAR Intents says those mechanisms prevented more than $50 million associated with one of 2026’s largest exchange hacks from entering its liquidity network — while allowing another half-million dollars that had already entered the system to be immobilized.
