The suspected North Korean attackers who stole roughly $388 million in the September 24 Bitget hack have started to run into roadblocks as the industry has continued to rally to plug exit routes. As of September 29, NEAR Intents and Chainflip, two cross-chain swap services, have joined Tether and Circle on the list of protocols that have either turned away or frozen funds related to the hack. NEAR Intents and Chainflip reject more than $50 million from Bitget hackNEAR Intents general manager Alex Shevchenko said that the Bitget attackers tried to move more than $50 million through the protocol, but almost nothing got through. Shevchenko estimated that only about $166,000 was processed through the platform, while $503,000 was frozen mid-swap and the rest was refused outright. However, those rejected funds, according to Shevchenko, simply “went to other providers.” NEAR Intents is a protocol that lets people trade assets across blockchains and averages more than $100 million in daily cross-chain volume. Shevchenko credits SHIELD for blocking the fund flow, a system he says is a risk-intelligence layer that decides whether to ignore a quote or halt a swap already in flight by pulling signals from know-your-transaction vendors, researchers and large centralized players. Blockchain-tracking firm MistTrack also reported that Chainflip rejected and refunded money from the Bitget exploiter. THORChain is waving Bitget hackers through THORChain is not one of the firms to reject funds from the Bitget hack, declining Bitget CEO Gracy Chen’s public request, as Cryptopolitan reported. THORChain’s response was that the only real lever it has is an emergency network halt, which protects the whole protocol and “is not a selective freeze of specific funds or an individual swap.”A September 28 CoinDesk review of THORChain’s public records caught about 2,390 ETH swapped into 75.2 BTC. The transactions worth roughly $6.3 million took about 27 swaps, all consolidated in a single address. The Bybit hackers used the same route in 2025, pushing THORChain’s volume over $3 billion in five days.Does ‘permissionless’ mean no intervention in DeFi?NEAR Intents’ post about not processing the marked Bitget hack funds was not popular across every sector, sparking debates about what the “permissionless, open and uncensorable” label actually means. Vini Barbosa, a technical writer building at Ramp Labs, pushed back on September 28: “permissionless does mean neutral,” he wrote to Shevchenko, calling it “the whole point of building something permissionless.”Shevchenko rejected the premise in his response, writing: “But permissionless doesn’t mean neutral,” adding that “The people who build these systems make choices about what those protocols enable. Refusing to help launder stolen assets is one of ours.” He framed it around property rights, arguing that a system where theft grants “an unrestricted right to monetize” stolen assets “is simply a system that protects the thief.”NEAR Intents also said it would waive the 5% freeze and 5% recovery bounties Bitget is offering, so more of the money can return to the exchange, and that frozen funds will stay locked pending a legal process. Shevchenko did not spell out who authorizes their release or how a wrongly flagged user gets money back.What Bitget is doing meanwhileBitget disclosed the breach on September 24, later revising the loss up from an initial $351.6 million after Zcash and TRON transfers were counted. Chen has said an attacker exploited a third-party security product to obtain internal credentials rather than stealing private keys, with Mandiant and SlowMist assisting. Circle and Tether have frozen roughly $318,000 in USDC and USDT tied to the wallets, and the exchange is restarting withdrawals in phases and running its recovery bounty. The exchange has now opened the withdrawal service for ETH on the Ethereum, BSC, Arbitrum One, BASE, and Optimism networks, following the resumption of Bitcoin withdrawals. If you're reading this, you’re already ahead. Stay there with our newsletter.