THORChain and NEAR Clash Reveals Boundaries of Crypto Idealism

THORChain and NEAR Clash Reveals Boundaries of Crypto Idealism

The heated controversy surrounding Bitget's $387.7M hack recovery highlights a fundamental question: do principles of "permissionless and decentralized" systems require never intervening — even when intervention is possible?

Following the September 24th Bitget security breach, $387.5 million in compromised assets rapidly began migrating between blockchains, with a portion flowing toward THORChain, a decentralized platform for cross-chain swaps.

A genuinely permissionless system cannot take action when it encounters assets known to be stolen — it remains blind to their origin. If THORChain possessed the capability to block specific stolen assets, it would cease to be permissionless.

Where does permissionlessness end?

Detractors contend that THORChain wasn't quite as principled when its validators chose to halt the network in May following an automated trigger that activated after an attacker exploited a security flaw and extracted more than $10 million from one of the protocol's vaults.

Bitget CEO statement
Bitget's CEO contends THORChain should decline services. Source: Gracy Chen

NEAR Intents, a cross-chain transaction platform that competes with THORChain, adopted a contrasting approach by intervening to prevent the processing of hack-related assets. The platform's automated security infrastructure SHIELD detected over $50 million in attempted transactions connected to the Bitget breach and successfully halted $503,000 while in execution. According to their report, $166,000 managed to pass through.

NEAR additionally declined to accept its portion of Bitget's recovery bounty program. The platform's general manager Alex Shevchenko explains to Magazine, "NEAR Protocol is permissionless: anyone can build on it, transact on it, and become a validator…

No one needs permission to hold or transfer assets or deploy contracts on NEAR Protocol. However, that does not mean every application built on NEAR must process every request.

NEAR Intents has subsequently faced significant criticism for its intervention, with detractors maintaining it proves the platform is neither permissionless nor decentralized. This position may leave it vulnerable to arguments that it should employ that control more extensively. Nevertheless, given that SHIELD operates as an automated system, cryptocurrency attorney Yuriy Brisov suggests it might still qualify for the protections granted to decentralized protocols.

There is no compliance team, people who sit there and control the operation manually. This is a smart solution, and that's what we recommend to all the DeFi companies.

Social media response
Source: Omid Malekan

Permissionless does not necessarily mean neutral

Bitget's Chen explains to Magazine that while she recognizes different protocols possess "different architectures, governance models and technical capabilities," there exists a crucial distinction between permissionless infrastructure and "facilitating the movement of known stolen funds."

She references NEAR Intents' response and states, "We appreciate that response and will follow the appropriate legal and recovery process for those assets."

Bitget seeks to comprehend "what is technically and governance-wise possible when stolen assets are identified," according to Chen, and whether the industry can discover viable approaches collectively:

Permissionless infrastructure does not necessarily mean there can be no mechanisms for detecting and responding to known illicit flows.

Adding complexity to THORChain's position, the platform has demonstrated its capacity to intervene during emergencies if it decides to do so.

THORChain's analysis following the May security incident explained the protocol automatically stops activity when its solvency verification systems identify an insolvency event, and node operators can subsequently utilize broader emergency controls to suspend trading, signing and additional network activity.

Wheeler indicates there exists "firm consensus" among THORChain's node operators regarding the principle of maintaining permissionlessness, and that "halts are only used when there is an active issue or problem with the protocol."

Furthermore, he states there is "no functionality to screen individual addresses or transactions." This represents a deliberate design decision, as the system was "intentionally designed to be truly permissionless."

THORChain security announcement
THORChain suspended its chain in May due to a security incident. Source: THORChain

NEAR Intents provides a contrasting model

While THORChain occupies the shadowy super-coder segment of the spectrum, the NEAR team positions itself in the middle ground. NEAR features a new ETF from Bitwise and embraces a distinct philosophy and methodology.

Shevchenko explains NEAR Intents was engineered to facilitate open participation while incorporating its own financial integrity safeguards, and SHIELD is constructed to "automatically apply targeted controls to supported flows."

During this particular incident, he notes SHIELD utilized public onchain information and indicators from an internal anti-money laundering (AML) database and third-party intelligence sources, including those referenced in the NEAR Intents risk and compliance documentation.

"SHIELD not only protects NEAR Intents but the whole cross-chain ecosystem it serves," according to Shevchenko:

Every major hack drains capital and activity from the onchain economy, so screening for stolen funds and restricting money laundering helps protect the integrity of the wider blockchain economy.

As a matter of fact, the artificial intelligence-powered SHIELD identified the suspicious activity behind Thursday's $3.8 million Omni deposit/withdrawal interaction exploit, and suspended activity.

Chen maintains when stolen assets can be dependably identified, ecosystem participants "should cooperate where technically and legally possible."

That might involve tracing and information exchange, refusing transactions, freezing assets where the infrastructure permits it, or "supporting recovery through the appropriate legal and law enforcement processes."

The cost of drawing the line

Joël Valenzuela, who identifies as a libertarian and cypherpunk and serves as head of business and development for Dash, contends that permissionless means precisely that.

Permissionless protocols, quite frankly, should not draw the line anywhere when stolen funds are identified, because being able to do so at all makes them permissioned.

He maintains that, as "painful" as it is to observe stolen funds moved freely, the capability to intervene and stop this "opens up Pandora's Box" and "lets all manner of censorship of innocents eventually happen." Rather, centralized exchanges ought to strengthen security protocols, he argues:

High-level exchanges custodying billions of dollars need to take their security much more seriously. Ultimately, DEXs are the way forward.

Max Shannon, who works as senior research associate at Bitwise Europe, suggests that protocols still in their developmental stages, such as THORChain and NEAR, must still establish trust and that declining to launder proceeds from hacks represents a "sound stance."

He anticipates THORChain's decisions will probably lead to additional money laundering flows migrating from NEAR Intents toward THORChain.

Valenzuela's perspective
Valenzuela maintains we must defend the principle of permissionlessness. Source: Joël Valenzuela

"Credible neutrality at all costs," according to Shannon, represents a "cypherpunk ideal" that a limited segment of crypto users and developers continue to uphold.

"They rarely ask why it is valuable, when it is valuable, or what it costs," he notes. "This is the core difference between NEAR Intents and THORChain."

← Zurück zum Blog