On September 25, hackers drained $388 million from the crypto exchange Bitget. That part of the story isn’t new. What happened next is: within hours, the stolen funds hit NEAR Intents, a cross-chain swap protocol, and its automated fraud detection system caught a chunk of the money moving in real time. It’s the first time most crypto users have seen NEAR Intents fraud detection work in public, under real pressure, against real thieves.
The system is called SHIELD. It watches transaction flows in real time and cross-checks them against threat intelligence from exchanges, analytics firms, and independent researchers. When something looks wrong, SHIELD can delay or reject the transfer before it settles. The idea: catch dirty money while it’s still moving, not after it’s gone.
How the System Actually Stopped the Money
Here’s what happened with the Bitget funds. Attackers tried to push roughly $50 million through NEAR Intents to launder it across chains. SHIELD froze $503,000 mid-transaction. Separately, stablecoin issuers Circle and Tether froze another $320,000 tied to the same hack. About $166,000 slipped through before anyone caught it.
- $50 million attempted through NEAR Intents
- $503,000 frozen by SHIELD
- $320,000 frozen separately by Circle and Tether
- $166,000 got away before detection caught up
Those numbers aren’t a total win. Most of the money still moved. But six months ago, none of it would have been caught at all. That’s the actual improvement here: a decentralized protocol, not a bank or an exchange, intercepted stolen funds on its own, automatically, in minutes instead of days.
Why NEAR Intents’ Fraud Detection Matters to Your Money
Picture Priya, a rideshare driver in Sacramento who keeps part of her savings in a crypto exchange account because the app fees are lower than her bank’s. If that exchange gets hacked, her recovery odds used to depend entirely on lawyers, subpoenas, and luck. Stolen crypto usually vanishes into mixers and dead-end wallets within hours.
Real-time interdiction changes that math. Crypto thieves stole roughly $2.7 billion industry-wide last year, per TechCrunch’s review of the data. Every dollar frozen mid-flight is a dollar that can eventually go back to victims like Priya, instead of funding the next hack. That’s real money, not an abstraction.
This also saves something harder to price: peace of mind. Knowing your funds sit inside a network that can actually chase down thieves in real time is different from knowing it just gets attacked and shrugs.
Not Everyone’s Cheering
NEAR Intents calls itself permissionless. Critics say freezing funds contradicts that. Technical writer Vini Barbosa put it bluntly in an interview with Unchained:
“Permissionless does mean neutral. It’s the whole point of building something ‘permissionless.’”
NEAR cofounder Illia Polosukhin disagrees. He argues permissionless means nobody needs approval to hold or move assets, not that every application must process every transaction blindly. It’s a fair fight, and it’s worth watching, because the answer will shape how much power these systems get to wield over the next hack.
We’ve seen this pattern before. Chainlink’s CCIP 2.0 update closed the kind of bridge flaw that cost one protocol $292 million. S&P Global’s purchase of blockchain’s top security auditor shows how seriously the industry now takes this. NEAR Intents is the latest sign that crypto security is shifting from cleanup after the fact to interception in the moment.
Watch what NEAR does next: publish clearer, public rules for when SHIELD intervenes, and other cross-chain protocols will likely copy the model. Skip that step, and the “permissionless” debate will only get louder.
