Skip to content
CRYPTO & DECENTRALIZED TECH

The DeFi Decentralization Dilemma: THORChain and NEAR Intents Clash Over Hacked Funds and Legal Liability

The fine line between decentralized autonomy and accountability in the decentralized finance (DeFi) sector has once again been thrown into sharp relief following a massive crypto exploit. Last week, suspected North Korean hackers targeted cryptocurrency exchange Bitget, making off with an astounding $387.5 million. As security investigators and blockchain sleuths rapidly flagged and traced the recipient addresses linked to the multi-million-dollar heist, the incident quickly escalated from a routine security breach into an intense philosophical and legal debate over the responsibilities of cross-chain liquidity protocols.

The controversy centers around a public clash between Bitget CEO Gracy Chen and the decentralized cross-chain swaps platform THORChain. Following the exploit, Chen controversially demanded that THORChain "refuse service to these addresses" to prevent the bad actors from laundering or moving the stolen capital across different blockchain networks.

THORChain, however, flatly rejected the request, firing back with a statement that underscored its foundational ethos: "THORChain is decentralized and permissionless like Bitcoin, Ethereum, and BNB Chain. What responsibility should Bitcoin, Ethereum, and BNB Chain bear when handling known stolen funds?"

The refusal immediately ignited widespread debate across the cryptocurrency community. The situation is particularly complex given THORChain’s own turbulent history with platform security. In May, the protocol was forced to halt operations immediately after $10.7 million of its own native funds were exploited. Complicating matters further, THORChain permanently retired its admin key in February 2025, meaning the protocol no longer possesses a practical or direct mechanism to censor or blacklist specific addresses, even if its operators or community members wished to do so. With a decentralized network powered by roughly a hundred independent validators, THORChain has positioned itself as an immutable, trustless infrastructure layer.

This exact controversy is far from unprecedented for the protocol. THORChain previously found itself under intense scrutiny when it was used to swap approximately $1.2 billion of the funds stolen during the massive $1.46 billion hack of Bybit. That particular exploit coincidentally occurred just 11 days after THORChain had retired its admin key, cementing its status as a fully permissionless system incapable of selective intervention.

Divergent Paths: The Case of NEAR Intents

While THORChain stood firm on its permissionless principles, other projects in the ecosystem chose a vastly different route. NEAR Intents adopted the exact opposite approach to THORChain. Through its automated security program known as SHIELD, the platform successfully blocked addresses linked to the recent Bitget hack from swapping $50 million worth of assets on its protocol. Furthermore, NEAR Intents reportedly turned down a 5% bounty that Bitget had publicly offered as an incentive for freezing and returning the stolen capital.

Could THORChain face prosecution over stolen Bitget funds?

This proactive intervention, while praised by centralized exchanges and victims of the exploit, has placed NEAR Intents under heavy fire from decentralization maximalists. Critics argue that by actively filtering and blocking transactions, the platform compromises its claim to being a truly permissionless and censorship-resistant decentralized protocol.

To better understand the intricate legal landmines surrounding these competing operational philosophies, Magazine spoke with Yuriy Brisov from D&A Partners to break down the legal realities facing DeFi protocols today.

The Legal Implications of Protocol Control

When asked whether THORChain’s decentralized and permissionless nature serves as a valid legal defense and whether protocols have a strict obligation to block illicit addresses, Brisov explained that legal vulnerability often hinges on the actual degree of decentralization a project maintains.

According to Brisov, the moment a protocol demonstrates that it can—and does—block specific addresses, it effectively undermines its own argument that its nodes and operators are entirely decentralized. While exercising such power can be seen as a positive community service to prevent malicious activities, it simultaneously opens the protocol up to a wide array of alternative legal claims.

"Their only protection is ‘we are decentralized,’" Brisov noted, pointing to the notable class-action lawsuit against Uniswap. In that case, investors sued the popular decentralized exchange after purchasing 38 rug-pull and scam tokens, but a federal judge ultimately dismissed the case in March, accepting the argument that the protocol was truly decentralized and beyond the direct control of its developers.

Brisov emphasized that true decentralization remains the single strongest legal defense for any DeFi protocol. If a project demonstrates that it has the technical capability to block, control, or otherwise interfere with transactions—even if done in good faith to thwart obvious fraud—it inadvertently exposes itself to broader liability. Claimants could argue that if a protocol possesses the power to intervene in high-profile criminal cases, its control should extend to other duties, such as conducting financial due diligence, enforcing Know Your Customer (KYC) protocols, and applying Anti-Money Laundering (AML) protective measures.

Could THORChain face prosecution over stolen Bitget funds?

Addressing whether NEAR Intents’ automated intervention exposes the protocol to future regulatory scrutiny or investor lawsuits, Brisov warned that establishing a precedent of asset control cuts both ways. Once a platform shows it can step in to manage illicit flows, injured investors in other scenarios—such as pump-and-dump schemes, sudden market volatility, or failed token launches—might argue that the platform has a duty to protect users across the board. They may question why intervention was deployed in one specific instance but ignored in others, raising expectations that the platform should vet all token issuers or require standard identity verification forms akin to traditional centralized exchanges.

Automated Shielding Versus Manual Intervention

The distinction between manual intervention and automated systems plays a critical role in shaping a protocol’s legal posture. When questioned about THORChain’s inability to block addresses following its protocol halt and the retirement of its admin key, Brisov acknowledged that technical limitations could serve as a viable defense, though the argument remains untested in court.

However, when a project retains the ability to upgrade its software or manually intervene to block specific bad actors, the legal calculus shifts. Brisov drew a sharp technical and legal distinction between manual blacklisting and automated, programmatic guardrails.

"Say there is an oracle that can detect any North Korean IP and block it automatically, and there is no person who sits and presses a button… Then it’s okay," Brisov explained. Conversely, if a core development team oversees situations on a case-by-case basis, manually reviewing illicit activity and clicking a button to execute a block, the legal reality changes. Even though such actions are executed in good faith to benefit the broader ecosystem, they strip the project of the shield provided by emerging regulatory frameworks. Jurisdictions like the European Union under the Markets in Crypto-Assets (MiCA) regulation, alongside general regulatory interpretations by United States agencies like the SEC and CFTC, generally recognize that fully decentralized entities cannot be held liable for the independent actions of participants within their ecosystems.

By deploying automated solutions like NEAR’s SHIELD—which identifies addresses linked to known hacks on public blockchains and automatically restricts them without human intervention or a centralized compliance team—protocols can demonstrate good-faith protective engineering. Brisov noted that such automated, hands-off architectures represent sensible solutions that legal professionals routinely recommend to modern DeFi developers.

Money Laundering, Property Law, and Timelines

A persistent point of confusion in crypto exploits is whether protocols that facilitate token swaps for stolen funds are legally culpable for money laundering or receiving stolen property. THORChain, for instance, operates as an automated liquidity protocol rather than a privacy mixer. While users can swap stolen Bitget funds across its network, the resulting assets remain transparently traceable on public ledgers and linked to the hackers’ original destinations.

Could THORChain face prosecution over stolen Bitget funds?

Brisov dismissed the notion that such protocols are inherently liable for money laundering, drawing comparisons to the legal battles fought by privacy-focused platforms like Tornado Cash.

"American law treats something as either property or not property," Brisov explained. "And money laundering is illegally moving property through the legal channels… But smart contracts are not property at all. You don’t control them. You don’t own them." This fundamental separation formed the core of Tornado Cash’s successful defense against Office of Foreign Assets Control (OFAC) sanctions, where developers demonstrated a lack of active control over immutable smart contracts.

As the industry reflects on older incidents, such as the massive Bybit hack that occurred 18 months ago, questions linger over whether delayed legal repercussions still loom over protocols like THORChain. Brisov suggested that time alone does not entirely eliminate legal exposure, noting that high-profile incidents can leave protocols vulnerable to private or regulatory claims long after the initial dust has settled.

Leave a Reply

Your email address will not be published. Required fields are marked *