MCAP $2.91T ▼ 1.63% 24H VOL $115.7B BTC.D 58.7% FEAR & GREED 72 Greed BTC FEE 3 sat/vB BTC $85,214 ▲ 0.98% ETH $2,691 ▲ 0.07% USDT $0.9998 ▲ 0.02% BNB $774.60 ▲ 0.74% XRP $1.50 ▲ 1.01% USDC $0.9999 ▲ 0.00% SOL $120.08 ▲ 2.16% TRX $0.3360 ▲ 0.36% FIGR_HELOC $1.04 ▲ 1.59% ZEC $1,366 ▲ 1.26%

Hacks & Security

NEAR Intents says it identified the hacker and sets a 48-hour deadline

NEAR Intents says it found the attacker behind a $3.8 million exploit and gave a 48-hour window to return the funds.

CoinDesk AI Desk
· 3 min read
✓ 2 SOURCES CHECKED
NEAR Intents says it identified the hacker and sets a 48-hour deadline
Image: Cointelegraph

Key takeaways

  1. Losses reached $3.8 million. NEAR Intents said a preliminary investigation found $3.8 million in user funds was stolen, and it pledged full compensation.
  2. The deadline is 48 hours. The attacker was given 48 hours to return the stolen funds under responsible disclosure.
  3. The patch took an hour. The contract vulnerability was patched within an hour of detection, while some deposits and withdrawals stayed unavailable for about 12 additional hours.

What happened

NEAR Intents says it has identified the person behind a security breach that cost $3.8 million in user funds and has given them 48 hours to return the money under responsible disclosure.

General manager Alex Shevchenko said on X on Friday: "We have identified you, sir." He also shared three different wallet addresses to receive Bitcoin, BNB and Solana.

The protocol paused services on Thursday after detecting a bug in the Omni deposit and withdrawal infrastructure interaction with its smart contract. A preliminary investigation found that $3.8 million in user funds was stolen, and the team pledged to compensate affected users in full.

Shevchenko told the attacker that responsible disclosure was the last window to use: "After 48 hours, that window closes."

Why it matters

Affected users are promised full compensation, and the incident has been reported to law enforcement.

ZachXBT said the funds went to the KuCoin exchange and were bridged to Bitcoin, and NEAR Intents says it is working with security and blockchain analytics partners to trace the stolen assets.

NEAR co-founder Illia Polosukhin said the exploit was isolated to USDT on BSC, and that SHIELD, the platform's AI security layer, flagged outlier behavior and triggered the pause. The contract vulnerability was patched within an hour of detection.

Polosukhin argued that crypto is entering a period of more sophisticated attacks, naming Bitget, MetaMask and Lido as recent targets, and said his firm plans to add formal verification to its contract release process.

What the data shows

CoinGecko data at the time of writing showed the NEAR token down more than 5% in 24 hours, with a 166% jump over the last 30 days.

NEAR Intents says the platform processes over $4 billion a month and that this was its first major exploit. Deposits and withdrawals on several chains, including BSC, Polygon, TON and Optimism, stayed unavailable for about 12 additional hours while Omni fixes were completed.

NEAR Protocol said it was fully operational and that neither it nor its native NEAR token was involved in the Intents incident.

What is still unclear

  • NEAR Intents says it identified the attacker, but the reports do not name the person publicly.
  • It is not yet clear whether the hacker will return any funds inside the 48-hour window.
  • The reports do not say how much of the stolen $3.8 million is recoverable or whether any of it has been frozen.

Questions readers ask

Who hacked NEAR Intents?

NEAR Intents says it has identified the attacker behind the $3.8 million exploit, and general manager Alex Shevchenko addressed them directly on X. The reports do not name the person.

How much was stolen in the NEAR Intents exploit?

A preliminary investigation found that $3.8 million in user funds was stolen. NEAR Intents has pledged to compensate affected users in full.

Was the NEAR token affected by the exploit?

NEAR Protocol said it was fully operational and that neither it nor its native NEAR token was involved in the Intents incident. CoinGecko data at the time of writing showed the token down more than 5% in 24 hours.

Where did the stolen funds go?

Blockchain investigator ZachXBT said the funds were transferred to the KuCoin exchange and bridged to Bitcoin. NEAR Intents says it is working with analytics partners to trace the stolen assets.

Sources · 2 publishers

  1. Cointelegraph TIER 1 FIRST REPORT
    NEAR Intents says its identified the hacker, gives 48-hour ultimatum
  2. CryptoPotato TIER 2
    NEAR Intents Identifies $3.8M Hacker, Gives Them 48 Hours to Return Funds