Signal Snapshot
- A swap tool that calls itself open just blocked hacker money. That choice matters now.
- NEAR Intents flagged more than $50 million in swap tries tied to the Bitget hack.
- Most rejected funds subsequently moved through other providers. The block did not stop movement.
- The top risk is trust. Users must now ask what permissionless really covers.
Key Takeaways
- NEAR Intents says hackers tried to move more than $50 million through its swaps after the Bitget theft.
- It matters because a tool that calls itself open and uncensorable chose to block transfers. That breaks expectations.
- The real read for investors is simple. Swap tools can freeze flows. Price that control into your risk plan.
What Happened
NEAR Intents says it stopped hacker swaps tied to Bitget. The news puts permissionless claims to test.
The team calls itself permissionless, open and uncensorable. It still slammed the door when stolen funds arrived.
That theft set off a hunt across swap services.
The hackers then tried to move more than $50 million through NEAR Intents. NEAR Intents lets users swap assets across chains.
It blocked most transfers before they cleared.
Most rejected funds then moved through other providers. The block did not stop the hackers cold.
It only pushed them to new routes. That detail matters for recovery hopes.
That gap fuels user fear.
NEAR Intents said yes to blocking. That choice has sparked a loud debate.
Can a service call itself permissionless and still censor? That is the core fight now.
The story broke on Sept 29, 2026. The timing was days after the Bitget theft.
Speed mattered here. Hackers move fast in the first week.
Swap tools sit in the middle. They see flows from many chains at once.
That spot gives them power. It also gives them blame when they act or sit out.
NEAR Intents chose to act. It will now face legal and social tests.
Who owns frozen crypto? How long can a hold last? Those points are still open.
The team has not shared full rules for its screening. Users do not know exact trip wires.
They do not know false hit rates. They do not know review times.
That lack of detail adds doubt. Open tools need open rules.
For now the facts are tight. More than $50 million in tries were flagged.
The rest went elsewhere. Recovery is still being worked out.
Why It Matters
This is a security event with a market structure twist. Stolen coins test every swap route.
For investors the lesson is direct. Swap access is not neutral in a hack.
Tools can pause your trade. They can hold funds mid path.
That power helps victims. It hurts the open image.
NEAR Intents lives on the exchanges and settlement rail. It moves value across chains. It settles swaps for users.
When that rail adds screens, flows change fast. Hackers reroute. Regular users face checks.
Builders feel it too. Apps that plug into intents must plan for pauses.
They must tell users about holds. They must staff support for flags.
Big buyers feel it in a soft way. They want fast exits. Screens can slow exits in stress.
Regulators will watch this case. A block that works looks like control.
Control brings questions. Who runs the screen? Who picks bad addresses?
DeFi users face a trade. Do they want help to stop thieves? Or do they want no stops at all?
You cannot have both at full strength. This case proves that point.
The second order point is trust pricing. If screens stay vague, users add a risk haircut.
They will split orders across tools. They will favor routes with clear rules.
What would change the read? Clear proof that only hacker funds were hit.
A public list of flagged wallets would help. A third party review would help more.
Fast return of any wrongly held funds would calm fears. Silence would do the reverse.
What would make this matter less? If held funds are freed soon through courts.
If flows return to normal with no new flags, the noise fades. If hackers cash out elsewhere, the block looks small.
If the headline was mostly noise, we would see two signs. First, tiny held sums with no victim return. Second, no shift in how swap tools screen.
So far neither sign is clear. But the rule shift is real.
Market Context
This story fits in security and sentiment. It is not about macro or new rules.
It is about how theft moves through open pipes. Hack weeks stress those pipes.
Swap services face the same pinch each time. Thieves need to swap fast.
They need to jump chains. They need to blur trails.
Intents based swaps were built for speed. Users state what they want. Solvers fill the order.
That speed helps normal traders. It also helps thieves in week one.
Screening style screens try to break that use. They flag bad wallets. They stop bad fills.
But flagged funds do not vanish. They seek the next open door.
Here most rejected funds moved through other providers. That shows the limit of solo blocks.
One tool can say no. The pack can still say yes.
Users now see the split in plain view. The market must price that split.
Sentiment splits too. Some cheer the freeze. They want thieves stopped.
Some jeer the freeze. They bought into uncensorable talk.
Both views have a cost. Full blocks need full control. Full openness lets thieves pass.
No Token Metrics historical analogs were supplied for this piece. So we will not force a past case.
No Token Metrics signal data was supplied either. So we will not guess at flows.
What we can say is why now matters. The hack is fresh. The sums are large.
Screens are not walls.
Liquidity feels this in small ways. Solvers may pause on odd orders.
They may ask for more checks. That can widen spreads for a spell.
Everyday users may see slower fills. They may see more pop up checks.
That friction is the price of screens. It is small until it hits your trade.
For Token Metrics readers the frame is risk. Do not assume all swap routes act the same.
Map which tools screen. Map which tools do not. Plan for reroutes in hack weeks.
Risks to Watch
The first risk is wrong flags. Good users could get caught in screening nets.
No clear appeal path was shared. That leaves stuck funds in limbo.
Watch for complaints of frozen swaps. Watch for slow support replies.
The second risk is legal grip. Held funds sit pending legal steps.
No owner of the release key was named. Courts could take months.
Watch for claims from Bitget or victims.
The third risk is reroute success. Most rejected funds used other paths.
If thieves cash out fully, the freeze means little. Recovery odds drop fast then.
Watch for new swap hops.
The fourth risk is brand harm. Permissionless talk meets block action.
Users may leave for tools with fewer stops. Builders may hedge with two routes.
Watch for volume shifts away from NEAR Intents. Watch for harsh posts from big traders.
The fifth risk is copycat rules. Other tools may add fast screens.
Hasty screens make more errors. That can freeze normal flow in stress.
Watch for new block lists. Watch for vague screen notes.
The sixth risk is solver pullback. Solvers fill intent orders for fees.
If holds trap their cash, they may step back. Less fill power means worse fills.
Watch for solver notes. Watch for slow fills on odd pairs.
What to Watch Next
- Watch for a wallet list from NEAR Intents. A public list lets all check the $50 million claim.
- Watch for a screening rule post. Clear rules on flags, reviews and appeals would ease trust fears.
- Watch for peer moves. If more tools block, hacker routes will shrink fast.
- This piece is for info only. It is not financial advice. Do your own checks before you trade.