# The Cross-Chain Dilemma: Should Decentralized Protocols Block Stolen Funds?
## A $387.5 Million Heist Sparks a Fundamental Debate
When a major centralized exchange fell victim to a cyberattack in late September, approximately $387.5 million in digital assets vanished. Within hours, the stolen funds began weaving their way across multiple blockchain networks, with a notable portion funneling toward decentralized cross-chain swap platforms. This incident reignited one of the most pressing and polarizing questions in the cryptocurrency industry: when decentralized protocols encounter known stolen funds, should they intervene or remain hands-off?
The debate reached a fever pitch when a prominent cross-chain protocol, THORChain, refused requests from the affected exchange’s leadership to deny services to attacker-linked wallet addresses. CEO Gracy Chen made a public appeal, stating that the industry was watching closely, but THORChain held firm. Their decision didn’t just affect the immediate aftermath of the hack — it exposed a philosophical fault line running through the entire crypto ecosystem.
## The Cypherpunk Argument: Permissionless Means Permissionless
For years, the ethos of permissionless blockchain technology has been celebrated as one of its most revolutionary features. Under this philosophy, no single entity should have the power to decide who can participate, transact, or move value across a network. Protocols like THORChain operate on the principle that the system is blind to the origin or destination of any transaction — it processes everything equally.
THORChain’s lead developer, Boone Wheeler, articulated this position clearly. According to Wheeler, a truly permissionless protocol is fundamentally unable to act on information about stolen funds, and if it could, it would cease to be permissionless. The protocol’s design intentionally omits any functionality that would allow individual addresses or transactions to be screened. This is not a bug, according to its creators — it is a core feature baked into the architecture from the ground up.
This stance echoes a broader cypherpunk tradition that values censorship resistance above nearly all else. Advocates of this view argue that the ability to selectively block transactions, no matter how well-intentioned, opens the door to broader censorship and sets a dangerous precedent. As libertarian advocate and Dash head of business development Joël Valenzuela put it, a protocol that can draw a line at stolen funds is no longer truly permissionless — and the consequences of that power could be far more damaging than the hacks themselves.
## A Competing Model: Automated Screening in Practice
Not everyone agrees that permissionless must mean completely neutral. A rival cross-chain transaction platform, NEAR Intents, took a markedly different approach during the same incident. Its security layer, called SHIELD, automatically identified more than $50 million in attempted fund flows linked to the exchange hack. The system intercepted $503,000 during execution while $166,000 passed through undetected. NEAR Intents also waived its share of the exchange’s recovery bounty.
General manager Alex Shevchenko described SHIELD as an automated system that uses public on-chain data, an internal anti-money laundering database, and third-party intelligence providers to apply targeted controls to supported flows. He emphasized that NEAR Protocol remains permissionless at its base layer — anyone can build, transact, and become a validator — but individual applications built on top of it retain the ability to make their own choices about which transactions to process.
This nuanced approach draws a clear distinction between the underlying infrastructure and the applications that run on top of it. According to crypto lawyer Yuriy Brisov, because SHIELD is an automated system without a human compliance team manually controlling operations, NEAR Intents could still fall within the protections typically afforded to decentralized protocols.
## When Permissionless Meets Reality
The debate became more complicated when critics pointed out that THORChain had previously demonstrated its willingness to intervene when protocol security was at stake. In May of the same year, an automated solvency check detected an insolvency event after an attacker exploited a vulnerability and drained over $10 million from one of its vaults. The protocol automatically halted all activity, and node operators used broader emergency controls to pause trading, signing, and other network functions.
THORChain’s developers argued that these halts are only triggered by genuine protocol-level emergencies and not by attempts to police individual transactions. Wheeler stated that there is a firm consensus among THORChain’s nodes around the ideal of permissionlessness, and that the emergency halt mechanism exists solely to protect the integrity of the network itself.
Nevertheless, critics see a contradiction: a protocol that can pause itself to protect its own solvency but refuses to pause the flow of stolen funds raises questions about where the line between self-preservation and neutrality actually sits.
## The Broader Industry Perspective
Industry voices have weighed in from multiple angles. Max Shannon, a senior research associate at Bitwise Europe, suggested that protocols still in their formative stages must earn trust, and that refusing to launder hack proceeds is a sound and responsible stance. He predicted that the divergence between NEAR Intents and THORChain would likely cause more money laundering flows to shift toward the latter.
Shannon also observed that the core difference between the two platforms comes down to a question of values: some believe in credible neutrality at all costs, while others believe protocols have a responsibility to protect the broader financial ecosystem. The former camp views this as a sacred cypherpunk ideal, while the latter sees it as an impractical stance that ignores real-world consequences.
Meanwhile, the exchange that was hacked emphasized that while it respects different protocols’ architectures and governance models, there is a meaningful difference between permissionless infrastructure and facilitating the movement of known stolen funds. Chen called for the industry to collaborate on technically and legally viable approaches, whether that means tracing, declining transactions, freezing assets, or supporting recovery through law enforcement channels.
## What the Omni Exploit Reveals
Adding another dimension to the discussion, the same automated screening system at the center of the debate — SHIELD — demonstrated its capabilities during a separate incident involving a $3.8 million Omni deposit and withdrawal exploit. The system identified the suspicious behavior and halted activity automatically, showcasing how AI-driven security measures can respond to threats in real time without human intervention.
This incident illustrated a key point in the debate: automation may offer a middle ground between full permissionlessness and manual censorship. By relying on algorithmic decision-making rather than human judgment, platforms can argue that they are not introducing subjective control into the system — but rather, deploying objective security measures.
—
## Frequently Asked Questions (FAQ)
**Q1: What happened in the Bitget hack?**
A major centralized cryptocurrency exchange was compromised in late September, resulting in the theft of approximately $387.5 million in digital assets. The stolen funds quickly began moving across multiple blockchain networks, including through decentralized cross-chain swap platforms.
**Q2: Why did THORChain refuse to block the stolen funds?**
THORChain operates as a permissionless protocol, meaning it is designed to be blind to the provenance of any transaction. Its developers argue that if the protocol could selectively block stolen funds, it would no longer be permissionless. They see censorship resistance as a foundational principle of their platform.
**Q3: What is NEAR Intents and how did it respond differently?**
NEAR Intents is a cross-chain transaction platform built on NEAR Protocol. During the same incident, its automated security system called SHIELD identified over $50 million in suspicious flows linked to the hack and intercepted $503,000 in real time. It also waived its share of the recovery bounty offered by the affected exchange.
**Q4: Is SHIELD a centralized system?**
SHIELD is an automated system that does not rely on a human compliance team to make decisions. It uses public on-chain data, internal anti-money laundering databases, and third-party intelligence to apply targeted controls. Its developers argue that because it operates without manual intervention, it can still be considered decentralized in nature.
**Q5: What is the cypherpunk position on this debate?**
Cypherpunk advocates believe that permissionless protocols should not draw any line regarding stolen funds, as the ability to selectively block transactions fundamentally undermines the permissionless nature of the system. They argue that centralized exchanges should improve their own security rather than relying on decentralized protocols to police the movement of funds.
**Q6: Has THORChain ever intervened before?**
Yes. In May of the same year, THORChain automatically halted its entire chain after an automated solvency check detected a vulnerability that had been exploited to drain over $10 million from one of its vaults. Developers maintain that such halts are emergency measures for protocol-level issues, not tools for policing individual transactions.
**Q7: What are the real-world implications of this debate?**
The disagreement has practical consequences for the entire crypto ecosystem. It affects where stolen funds flow after hacks, shapes public perception of decentralized platforms, and influences how regulators view blockchain-based financial infrastructure. It also raises questions about the long-term sustainability of fully permissionless systems in a world where stolen assets need to be recovered.
**Q8: What does the affected exchange want from the industry?**
The hacked exchange seeks to understand what is technically and governance-wise possible when stolen assets are identified. It hopes the industry can find collaborative approaches that balance the ideal of permissionless infrastructure with the need to detect and respond to illicit fund flows, including through tracing, transaction declines, asset freezes, and law enforcement cooperation.
—
## Conclusion
The clash between THORChain and NEAR Intents represents more than a disagreement between two platforms — it reflects a fundamental tension at the heart of blockchain technology. On one side stands the cypherpunk ideal that permissionlessness is absolute and that any form of selective intervention erodes the very principles that make decentralized systems valuable. On the other side stands the pragmatic view that in a world where billions of dollars can be stolen in minutes, neutrality in the face of theft has its own moral cost.
As cross-chain infrastructure becomes increasingly central to how digital assets move, the answer to this question will shape the future of the entire ecosystem. Whether platforms choose to remain blind to the origins of funds or deploy automated systems to screen for illicit activity, the debate has moved beyond theory into real-world practice. The incidents of late September may serve as a turning point, forcing the industry to confront difficult questions about responsibility, neutrality, and the limits of permissionless design.
What is clear is that there is no simple resolution. The technology enables both absolute openness and targeted intervention, and different communities will continue to draw the line in different places. Understanding where each platform stands — and why — is essential for anyone navigating the rapidly evolving landscape of decentralized finance.
Thank you for reading.



