Near Intents blocks $50 million in Bitget hacker swaps, here's what happened
“The reason for this behaviour is SHIELD. It automatically detects deviations in flows, collects numerous inputs from KYT and intelligence providers, independent researches, companies and largest centralised players in the industry. Based on these signals the protocol can decide how to handle a transaction,” Shevchenko added.
In other words, permissionless and open doesn’t automatically mean a free ride for malicious actors and their money.

Bitget disclosed the breach on Sept. 24 after attackers bypassed security controls protecting its exchange wallets. The company has since said it fixed the vulnerability, published attacker addresses, and offered bounties for eligible efforts to freeze or recover funds.
Circle and Tether, the issuers of USDC and USDT, have already frozen about $320,000 in stablecoins linked to the breach, as CoinDesk reported last week.
Intents documentation says the service checks swap requests for links to reported hacks and can delay suspicious transactions. These checks apply when someone uses the swap service, but do not give its operators control over every wallet on the NEAR blockchain.
The ability to hold funds has drawn scrutiny of NEAR Intents’ description of itself as permissionless, meaning people can use it without seeking an operator’s approval.
Who gets to stop a swap
The intervention drew criticism online over whether a service that can hold funds should describe itself as permissionless. Among those questioning the label was Vini Barbosa, a technical writer and documentation engineer building at Ramp Labs.