How did Near Intents block $50 million in Bitget hacker transfers?

Near Intents blocked $50 million in stolen funds by identifying and rejecting suspicious swap requests linked to the Bitget exploit through its intent-based security filtering. While the intervention successfully protected the Near ecosystem, the attacker was able to successfully move the majority of the rejected funds through alternative, less-restricted liquidity providers.
How did Near Intents block $50 million in Bitget hacker transfers?

Near Intents successfully blocked the Bitget hacker by utilizing real-time transaction screening within its intent-based architecture to flag address signatures associated with the 2026 security breach. By identifying these high-risk transactions at the 'intent' stage—before they were finalized on-chain—the protocol was able to prevent the attacker from swapping stolen assets into more liquid or anonymous cryptocurrencies within the Near ecosystem. This represents a significant milestone for decentralized security, showing that intent-based protocols can act as a critical layer of defense against money laundering.

The incident began in early 2026 following a major exploit of the Bitget exchange, which saw tens of millions of dollars in various tokens siphoned into attacker-controlled wallets. As the hacker attempted to offload these assets via decentralized swap services, the automated monitoring systems at Near Intents intervened. However, the victory for the DeFi space was only partial. Data suggests that once the $50 million in swaps were rejected, the hacker quickly pivoted to other decentralized exchanges and cross-chain bridges that lacked similar robust monitoring, highlighting the persistent challenge of fragmented security across the crypto industry.

From a regulatory perspective, this event provides ammunition for US lawmakers who have been pushing for stricter 'know your transaction' (KYT) requirements for DeFi protocols. The success of Near Intents demonstrates that it is technically feasible for decentralized systems to block illicit flows without sacrificing their core architecture. However, the hacker’s ability to find workarounds underscores the limitations of isolated security efforts. Investors should note that while Near’s infrastructure has proven resilient, the broader market remains vulnerable to the systemic risks of cross-chain capital flight.

Moving forward, market participants should watch for a potential industry-wide adoption of shared security standards or 'blacklists' among intent-based solvers and liquidity providers. If other major players do not integrate similar defensive layers, the industry may face increased pressure from US regulators to implement mandatory compliance frameworks at the protocol level. For now, the event serves as a stark reminder that while individual protocols are getting smarter, the decentralized landscape still offers numerous exit ramps for sophisticated actors.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.