Latest News

NEAR Intents Gives Alleged Attacker 48 Hours to Return $3.8…

NEAR Intents says it has identified the person behind a security breach that caused approximately $3.8 million in losses, giving the individual 48 hours to return the funds before what the protocol’s general manager described as a “responsible disclosure” window closes.

Alex Shevchenko, general manager of NEAR Intents, published three return addresses for Bitcoin, BNB Chain and Solana on Friday and addressed the suspected attacker directly. “We have identified you, sir,” he wrote, adding: “You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes.”

Shevchenko did not publicly identify the individual or provide evidence supporting the identification claim. The ultimatum follows Thursday’s incident, when NEAR Intents stopped services after detecting a bug involving the interaction between its Omni deposit and withdrawal infrastructure and a NEAR Intents smart contract.

The protocol put the preliminary loss at about $3.8 million and pledged to compensate affected funds in full. FinanceFeeds’ initial analysis of the NEAR Intents incident traced the abnormal activity to infrastructure associated with the HOT Bridge treasury on BNB Chain rather than to the NEAR blockchain itself.

What Happened to the Stolen Funds?

Blockchain investigator ZachXBT identified abnormal outflows from a BNB Chain hot wallet associated with NEAR Intents and said the assets were transferred through KuCoin before being bridged into Bitcoin. Moving assets through an exchange and across chains does not by itself establish who controls the destination wallets or whether the funds were subsequently sold.

NEAR Intents said the contract-side vulnerability had been patched shortly after the breach was detected. Its initial response temporarily affected deposits and withdrawals across 11 networks, including BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar and Scroll, while repairs to the Omni infrastructure were completed.

The team also said the incident had been reported to law enforcement and that security and blockchain analytics firms were assisting with tracing and recovery efforts. A more detailed post-mortem is expected to explain how the interaction between Omni and the Intents contract allowed the loss to occur.

Investor Takeaway

The important distinction is where the failure occurred. Available evidence points to the deposit-and-withdrawal infrastructure connecting into NEAR Intents, not a compromise of the NEAR base blockchain. The post-mortem will be critical for determining whether the weakness was isolated or exposed a wider architectural risk.

Why Does the 48-Hour Deadline Matter?

Publicly offering an attacker a route to return funds is a familiar recovery tactic in decentralized finance, but Shevchenko’s message is unusually direct because he claims the individual has already been identified.

The statement effectively turns the next phase from technical containment toward asset recovery. If the identification is accurate, the attacker’s ability to move funds through centralized exchanges may also become more constrained as wallet addresses are circulated among analytics firms, exchanges and law-enforcement agencies.

NEAR Intents has not disclosed what evidence led to the identification, nor has it named the individual. The identification claim should therefore remain separate from what can be established on-chain: funds left the affected infrastructure, some were routed through KuCoin-linked addresses, and a substantial portion was subsequently moved into Bitcoin.

The recovery process is also distinct from compensation. NEAR Intents has promised to make affected users whole regardless of whether the attacker voluntarily returns the assets. As FinanceFeeds previously examined in its guide to recovery after cross-chain exploits, patching an attack path is only one stage; operators must also reconcile losses, restore infrastructure and establish how reimbursement will be funded.

Investor Takeaway

The recovery rate now matters less for users if NEAR Intents can fulfill its full-compensation pledge, but it still matters for the protocol’s balance sheet. Investors should watch for the reimbursement mechanism, final loss calculation and evidence that all affected infrastructure has been independently reviewed.

Why Is the Timing Particularly Awkward for NEAR Intents?

The breach came only days after NEAR Intents had publicized its role in stopping assets connected to the much larger Bitget security incident. FinanceFeeds reported that its security systems blocked attempts to route more than $50 million linked to the Bitget theft and froze another roughly $503,000 that had entered its infrastructure.

That contrast puts attention on two separate parts of cross-chain security. Screening systems can identify suspicious wallets and prevent known stolen assets from moving through a protocol, while software vulnerabilities can expose the infrastructure itself even when transaction-monitoring controls operate as designed.

The distinction becomes more important as NEAR Intents expands into wallets and trading applications. Aurora Labs introduced an embeddable NEAR Intents execution layer earlier this year, extending the infrastructure to applications seeking to abstract away bridges, routing and cross-chain execution from users.

Investor Takeaway

Cross-chain abstraction can make swaps easier for users, but it does not eliminate infrastructure risk; it relocates that risk into the systems coordinating deposits, withdrawals and settlement. The forthcoming technical report will matter more than the speed of the initial patch for assessing whether NEAR Intents has closed the underlying failure mode.

What Comes Next?

The first deadline to watch expires roughly 48 hours after Shevchenko’s October 2 post. Any return of funds should be verifiable through the published addresses, although a partial repayment would not necessarily resolve the incident or determine how the remaining assets are handled.

Beyond recovery, the more consequential disclosures will be the promised technical report, the final loss figure, confirmation of user reimbursement and the status of affected Omni deposit and withdrawal routes.

Until those details are published, the $3.8 million figure remains preliminary and Shevchenko’s identification claim remains a statement from the protocol’s general manager rather than a publicly substantiated attribution.

You may also like