The furious debate over Bitget’s $387.7M of hacked funds comes down to whether ideals around “permissionless and decentralized” tech means never intervening — even if you could.
After Bitget got hacked on Sept. 24, $387.5 million of stolen funds quickly began moving across chains, with some headed to decentralized cross chain swaps platform THORChain.
Chief executive Gracy Chen publicly appealed to the platform to refuse service to attacker-linked addresses. “The industry is watching,” she said. Yet THORChain refused. And that refusal has kicked off a furious debate between those who believe protocols have a moral obligation to block stolen funds, and those hold the cypherpunk ideals of decentralized, permissionless technology sacrosanct. Having previously watched on as the Bybit hackers funneled $1.2 billion through the protocol, it’s pretty clear which side of the argument THORChain is on. Developer Boone Wheeler tells Magazine:
Critics argue that THORChain wasn’t quite so idealistic when validators voted to halt the chain in May after an automated system triggered when an attacker exploited a vulnerability and drained over $10 million from one of its vaults.
Bitget CEO argues THORChain should refuse services. Source: Gracy Chen
NEAR Intents, which is a cross-chain transaction competitor of THORChain, took the opposite approach and intervened to block hack-linked funds. Its automated security layer SHIELD identified more than $50 million in attempted flows linked to the Bitget incident and stopped $503,000 during execution. It said $166,000 passed through.
NEAR also waived its share of Bitget’s recovery bounty. General manager Alex Shevchenko tells Magazine, “NEAR Protocol is permissionless: anyone can build on it, transact on it, and become a validator…
NEAR Intents has since come under heavy fire for intervening, with critics arguing it demonstrates it is not permissionless or decentralized. This may expose it to claims it should exercise that control more broadly. However, because SHIELD is an automated system, crypto lawyer Yuriy Brisov believes it could still fall within the protections afforded to decentralized protocols .
Biget’s Chen tells Magazine that while she understands different protocols have “different architectures, governance models and technical capabilities,” there is an important distinction between permissionless infrastructure and “facilitating the movement of known stolen funds.”
She points to NEAR Intents’ actions and says, “We appreciate that response and will follow the appropriate legal and recovery process for those assets.”
Bitget wants to understand “what is technically and governance-wise possible when stolen assets are identified,” Chen says, and whether the industry can find workable approaches together:
Complicating THORChain’s argument, it has shown it can intervene in an emergency if it chooses to.
THORChain’s post-mortem of the May exploit said the protocol automatically halts activity when its solvency checks detect an insolvency event, and node operators can then use broader emergency controls to pause trading, signing and other network activity.
Wheeler says there is “firm consensus” among THORChain’s nodes around the ideal of being permissionless, and that “halts are only used when there is an active issue or problem with the protocol.”
Moreover, he says there is “no functionality to screen individual addresses or transactions.” This is a design choice, as the system was “intentionally designed to be truly permissionless.”
THORChain halted its chain in May over a security incident. Source: THORChain
While THORChain is located at the shadowy super-coder end of the spectrum, the NEAR team occupies the middle ground. NEAR has a new ETF from Bitwise and has a different philosophy and approach.
Shevchenko says NEAR Intents was designed to enable open participation but has its own financial integrity measures, and SHIELD is built to “automatically apply targeted controls to supported flows.”
In this incident, he says SHIELD used public onchain data and signals from an internal anti-money laundering (AML) database and third-party intelligence providers, such as those listed in the NEAR Intents risk and compliance docs.
“SHIELD not only protects NEAR Intents but the whole cross-chain ecosystem it serves,” Shevchenko says:
Chen says when stolen funds can be reliably identified, ecosystem participants “should cooperate where technically and legally possible.”
That could mean tracing and information sharing, declining transactions, freezing assets where the infrastructure allows it, or “supporting recovery through the appropriate legal and law enforcement processes.”
Joël Valenzuela, a libertarian, cypherpunk and head of business and development for Dash, argues that permissionless means exactly that.
He says that, as “painful” as it is to watch stolen funds freely moved, the ability to step in and prevent this “opens up Pandora’s Box” and “lets all manner of censorship of innocents eventually happen.” Instead, centralized exchanges should harden security protocols, he says:
Max Shannon, senior research associate at Bitwise Europe, says that protocols still in their formative years, like THORChain and NEAR, still have to earn trust and that refusing to launder hack proceeds is a “sound stance.”
He believes THORChain’s actions will likely result in more money laundering flows shifting from NEAR Intents to THORChain.
Valenzuela argues we must hold the line on permissionlessness. Source: Joël Valenzuela
“Credible neutrality at all costs,” Shannon says, is a “cypherpunk ideal” that a small faction of crypto users and builders still champion.
“They rarely ask why it is valuable, when it is valuable, or what it costs,” he says. “This is the core difference between NEAR Intents and THORChain.”