THORChain will not block addresses linked to the $387.5 million Bitget hack, citing its decentralized and permissionless design. This decision follows last week's exploit of crypto exchange Bitget by suspected North Korean hackers.

Investigators quickly flagged and traced the recipient addresses. Bitget CEO Gracy Chen then publicly demanded that THORChain "refuse service to these addresses."

THORChain responded by confirming its decentralized and permissionless operational model. The protocol retired its admin key in May after its own $10.7 million exploit, eliminating any mechanism to censor addresses even if developers wanted to intervene.

THORChain faced a similar situation previously, facilitating swaps of approximately $1.2 billion from the $1.46 billion Bybit hack. The protocol's admin key had been retired 11 days before that incident, precluding intervention.

In contrast, NEAR Intents implemented its automated SHIELD program to block addresses linked to the Bitget hack, preventing the swap of $50 million on its platform. NEAR Intents also declined a 5 percent bounty offered by Bitget for its assistance.

This action drew criticism from decentralization advocates who argue NEAR Intents is not permissionless enough. Crypto lawyer Yuriy Brisov of D A Partners said that while blocking malicious activity benefits the community, it opens protocols to legal claims.

Brisov explained that if a protocol demonstrates control—by blocking, interfering, or censoring—it undermines its defense of being truly decentralized. He cited the Uniswap case, where a judge dismissed a lawsuit after Uniswap argued it was decentralized and could not control scam tokens.

According to Brisov, showing control, even in good faith to prevent fraud, implies an obligation to implement Know Your Customer (KYC) and Anti-Money Laundering (AML) measures. This can impact liability analysis under regulatory frameworks like MiCA or how the SEC and CFTC view fully decentralized systems.

NEAR Intents' move demonstrates it has protective measures and acts as a good-faith actor. While Brisov described its automated blocking as a solution that avoids manual control by a compliance team, he warned that by demonstrating control, NEAR Intents opens itself to broader legal claims and liability exposure that could undermine the decentralization defense.

By demonstrating the capacity to interfere, NEAR Intents has signaled that its nodes are not truly decentralized, creating a framework where future interference might be expected or legally mandated.