MCAP $2.91T ▼ 2.08% 24H VOL $70.7B BTC.D 59.2% FEAR & GREED 70 Greed BTC FEE 1 sat/vB BTC $86,023 ▲ 0.87% ETH $2,717 ▲ 0.51% USDT $0.9998 ▼ 0.01% BNB $787.71 ▼ 0.32% XRP $1.51 ▲ 0.98% USDC $0.9999 ▼ 0.01% SOL $120.69 ▼ 0.58% TRX $0.3366 ▲ 0.32% FIGR_HELOC $1.07 ZEC $1,309 ▼ 2.26%

Hacks & Security

Near Intents recovers $3.8 million after 48-hour ultimatum to attacker

The cross-chain protocol said the attacker returned all funds and that it has closed its investigation.

CoinDesk AI Desk
· 4 min read
✓ 2 SOURCES CHECKED
Near Intents recovers $3.8 million after 48-hour ultimatum to attacker
Image: Decrypt

Key takeaways

  1. The full amount. About $3.8 million was drained on Oct. 1 and returned in full, the team said.
  2. The deadline. The attacker had 48 hours to return funds after Shevchenko said he had identified them.
  3. The bitcoin leg. The listed Bitcoin address received about 34.6 BTC, valued by one researcher at about 78% of the loss.

What happened

NEAR Intents, a cross-chain trading protocol, lost about $3.8 million in an exploit on Oct. 1. The attacker sent all of the money back on Friday, and the team closed its investigation. General manager Alex Shevchenko wrote on X that the funds from the $3.8M NEAR Intents hack were sent back in full.

The return followed a public ultimatum. Shevchenko posted Bitcoin, BNB/Ethereum and Solana addresses for the funds and told the attacker, "We have identified you, sir," saying they knew better than most how responsible disclosure works and had 48 hours to use it. The money arrived roughly 14 hours after that callout.

An onchain note on a transaction to the BNB/Ethereum address read, "We've returned all the funds, we were in the wrong." The message also thanked the Near team for being cordial during the process and urged others to use bug bounties.

NEAR Intents halted its services on Oct. 1, blaming a bug in the Omni deposit and withdrawal infrastructure interaction with its smart contract. It pledged to make affected users whole, said a detailed report would follow, and reported the incident to law enforcement.

Why it matters

NEAR co-founder Illia Polosukhin said the team identified the party responsible less than 24 hours after the hack, established communication, and got the funds back in full at 14:30 UTC. He credited SHIELD, the AI security layer on Intents, along with aggressive detective work.

Intents handles more than $4 billion a month in trading and payments, Polosukhin said, and he called this its first major exploit. Both executives asked hackers to use bug bounties instead of disrupting services.

The flaw was confined to USDT on BSC and was patched in under an hour, Polosukhin wrote, and the NEAR blockchain and its token were unaffected.

What the data shows

Blockchain data shows the Bitcoin address Shevchenko listed took in about 34.6 BTC over several transfers between 14:31 and 15:05 UTC on Friday. Onchain researcher Kuncoro estimated the bitcoin was worth about 78% of the $3.8 million and asked whether the rest came back another way. Shevchenko replied, "You are right. It did indeed," without saying how.

Near Intents lets users swap tokens across 35 blockchains by stating what they want and letting market makers compete to fill the order, and it has processed more than $30 billion in swaps.

Background

The hack hit days after NEAR Intents blocked stolen Bitget funds from moving through the protocol. Two days earlier, Near Intents blocked a $50 million swap attempt by the hacker behind the roughly $387.5 million Bitget breach, which Bitget and blockchain analytics firm Elliptic have pinned on North Korea.

The hack also came days after Bitwise's spot NEAR ETF began trading. Blockchain sleuth ZachXBT said the stolen funds were sent to KuCoin and bridged to Bitcoin.

What is still unclear

  • Shevchenko did not say how the rest of the loss came back beyond the bitcoin.
  • Neither executive detailed how the attacker was found, and Shevchenko answered "Internal team" when asked who did the tracing.
  • The team said a detailed report would follow, so the full account of the incident has not been published.

Questions readers ask

How much was stolen from NEAR Intents?

About $3.8 million was drained in an exploit on Oct. 1, and the service said the funds were returned in full. The team also said it would make affected users whole.

What did the attacker say when returning the funds?

An onchain message attached to a transaction read, "We've returned all the funds, we were in the wrong." It also thanked the Near team and urged others to use bug bounties.

Did NEAR Intents explain how it found the attacker?

Neither executive gave details. Asked who did the tracing, Shevchenko answered "Internal team," while Polosukhin credited SHIELD, the AI security layer on Intents, along with aggressive detective work.

Was the NEAR blockchain affected by the exploit?

Polosukhin wrote that the flaw was confined to USDT on BSC and was patched in under an hour, and that the NEAR blockchain and its token were unaffected.

Sources · 2 publishers

  1. Decrypt TIER 1 FIRST REPORT
    'We Have Identified You, Sir': Near Intents Recovers $3.8 Million After 48-Hour Ultimatum
  2. Unchained TIER 1
    NEAR Intents Says Exploited $3.8 Million Is Back, Closes Its Hack Investigation