NEAR Intents Gives $3.8M Attacker 48 Hours to Return Funds

NEAR Intents Gives $3.8M Attacker 48 Hours to Return Funds

NEAR Intents General Manager Alex Shevchenko said the team has identified the person behind a security breach that drained approximately $3.8 million and gave the alleged attacker 48 hours to return the assets. The ultimatum followed an October 1 exploit involving the service’s cross-chain deposit and withdrawal infrastructure. Shevchenko’s identification claim is a company-side assertion and has not been independently substantiated through publicly disclosed evidence.

NEAR Intents said its preliminary investigation traced the vulnerability to a bug in the interaction between its Omni deposit and withdrawal infrastructure and a NEAR Intents smart contract. The affected flow was narrowed to USDT on BNB Smart Chain, while the underlying NEAR Protocol, the NEAR token and other applications were not identified as compromised. The security boundary therefore sits within NEAR Intents’ cross-chain infrastructure rather than the NEAR blockchain itself. The project’s architecture normally uses Omni Bridge to receive assets and move them across supported networks.

Stolen Funds Move Across Bitcoin and KuCoin

Blockchain analysis cited by Bitquery traced approximately 34.69 BTC across four Bitcoin addresses, representing roughly 76% of the stolen value at the time of its October 1 snapshot. Another approximately $802,000 reached KuCoin deposit infrastructure through two routes. Those movements describe where investigators tracked portions of the proceeds, not separate losses that should be added to the $3.8 million exploit estimate.

Reaching exchange deposit addresses also does not establish the identity of the account holder. KuCoin can potentially associate deposit infrastructure with customer records, subject to its internal data and applicable legal processes, but that information is not visible from blockchain data alone. On-chain attribution can identify transaction paths and service endpoints without independently revealing the person controlling an exchange account.

Shevchenko subsequently published return addresses covering Bitcoin, EVM networks and Solana and described the 48-hour period as the attacker’s final opportunity to return the assets under responsible disclosure. The deadline runs to approximately October 4 based on the timestamp of his October 2 post. The public demand marks a shift from technical containment toward attempted asset recovery, but it does not itself establish that restitution will occur.

The episode creates an unusual contrast with NEAR Intents’ activity only days earlier. Its SHIELD system had rejected more than $50 million in attempted routes associated with assets linked to the Bitget breach, although only about $503,000 was actually restricted during execution. That distinction was central to an earlier examination of how NEAR Intents blocked Bitget-linked transaction routes. Blocking suspicious assets from using an execution service and recovering funds already stolen from that service are fundamentally different security problems.

Cross-Chain Infrastructure Remains the Security Boundary

NEAR Intents temporarily paused services after detecting the exploit and later restored its main execution layer after patching the vulnerability. Some deposits and withdrawals across connected networks remained restricted longer while repairs to Omni infrastructure were completed. The response indicates that the incident affected a specific interoperability layer rather than requiring a halt or rollback of the NEAR base network.

That distinction mirrors a wider pattern in cross-chain security. Recent incidents have exposed vulnerabilities at very different layers, including a Verus-Ethereum bridge validation failure and the dispute surrounding the KelpDAO and LayerZero cross-chain exploit. In each case, identifying whether the failure originated in contracts, verifier infrastructure, routing logic or the underlying chain materially changes the risk assessment. “Cross-chain exploit” describes a category of activity, not a single technical failure mode.

The recovery effort may also involve exchanges and other liquidity venues where the proceeds traveled. The recent Bitget-linked THORChain compliance debate showed how intervention capabilities differ sharply between centralized services, intent-based routing systems and permissionless protocols. Whether suspicious funds can be blocked, frozen or recovered depends on where control actually exists in the transaction stack.

NEAR Intents has pledged to compensate affected users in full, limiting direct user losses if reimbursement is completed as stated. The more durable issue is narrower: a service built to coordinate liquidity across many chains inherited a vulnerability in the infrastructure that moves assets between those environments. The $3.8 million loss, subsequent tracing and 48-hour demand now provide a concrete test of both its recovery procedures and the operational controls surrounding Omni-based deposits and withdrawals.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px