Coin Brief ENDE

One Bitget hacker, two swap services, two meanings of “permissionless”

The attacker who took about $388 million from the exchange Bitget on 24 September has spent the days since moving the proceeds through cross-chain swap services. Two of them answered the same request in opposite ways, and each says its answer is what "permissionless" means.

THORChain let it through. On Monday, 28 September, a wallet linked to the attacker swapped about 2,390 ETH, worth about $6.3 million, for 75.2 BTC through THORChain, according to CoinDesk's reading of 27 successful swaps in the network's public records. Bitget's chief executive Gracy Chen had publicly asked THORChain to refuse the attacker's addresses. THORChain declined: its emergency controls can halt swaps across a chain or the whole network, it said, but "a halt is not a selective freeze of specific funds or an individual swap". When THORChain itself lost about $10.7 million in May it halted trading for about five weeks, and even then, it says, the attacker's addresses were never blacklisted.

NEAR Intents turned most of it away. Its general manager Alex Shevchenko reported that the attacker tried to move more than $50 million through the service, that its SHIELD system, which combines flow anomalies with signals from tracing firms and exchanges, blocked most attempts, and that about $503,000 was frozen mid-transaction and about $166,000 passed. The figures are estimates that may be off by about 10%, he said, and the rejected funds went on to other providers. NEAR Intents has not said who can release the frozen funds or how a wrongly flagged user gets money back.

One Bitget hacker, two swap services, two meanings of “permissionless”
One Bitget hacker, two swap services, two meanings of “permissionless” — Coin Brief

What separates them

The argument is not about whether blocking is possible; both services can stop flows. It is about which layer promises what. NEAR co-founder Illia Polosukhin put one side: "Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR. It does not mean every application or liquidity provider must process every transaction." Critics answer that a service able to hold funds has a gatekeeper, whatever the chain underneath allows. What the week showed in practice is that stolen funds rarely stop: turned away at one service, they moved to the next. The difference lies in who carries the decision, and who answers for it when the flag is wrong.