0x0c5631230c56…0c563126

ConfirmedSecurity567 vB61 sat/vB3 min decode

NEAR Intents Exploiter Returns Full $3.8M After Encrypted Negotiation

A $3.8M exploit on NEAR Intents ended with a 100% refund after the protocol team negotiated directly with the attacker through encrypted channels, per Cryptopolitan.

NEAR Intents’ hacker refunds 100% of stolen $3.8M after encrypted negotiation - cryptopolitan.com
WitnessNEAR Intents’ hacker refunds 100% of stolen $3.8M after encrypted negotiation - cryptopolitan.comAI-generated

Outputs

  1. $3.8 million was stolen from NEAR Intents before the attacker agreed to return the full sum

  2. The recovery followed encrypted-channel negotiation between the attacker and the NEAR Intents team

  3. 100% refunds remain rare in DeFi exploit settlements, where partial recoveries of 10-30% are the norm

  4. NEAR Intents operates as the cross-chain transaction layer of NEAR Protocol, routing fills through a competitive solver market

  5. No law enforcement involvement was referenced in the Cryptopolitan report preview

$3.8 million stolen from NEAR Intents has been returned in full by the attacker following encrypted-channel negotiations with the protocol team, according to a Cryptopolitan report.

NEAR Intents operates as the cross-chain transaction layer of NEAR Protocol, processing user-specified outcomes — token swaps, cross-chain transfers — through a competitive market of off-chain solvers rather than on-chain automated market makers. The architecture differs structurally from order-book exchanges: users declare what they want, and solvers compete to deliver it, with settlement routed through the NEAR chain.

The Cryptopolitan headline — the only source detail publicly available as of writing — frames the recovery as the product of direct negotiation. The report does not name the attacker, identify the encryption tool used, or specify dates for either the exploit or the refund. No on-chain transaction hashes, wallet addresses, or law enforcement references appear in the preview coverage.

What a 100% refund means for incident response

Encrypted-channel settlement between a protocol team and an exploiter remains uncommon, though not without precedent. Earlier return-of-funds episodes — including the 2016 DAO Ethereum hard fork, the 2021 Poly Network $611 million exploit, and the 2022 Mango Markets settlement — generally combined public pressure, on-chain messages, and in some cases the threat of criminal referral.

A pure encrypted-channel resolution producing a full refund without identified law enforcement involvement would mark a quieter template. For protocol operators, the open question is whether such settlements create a durable norm — or a moral-hazard opening that effectively auctions bug discovery to whichever negotiator offers the highest take.

What NEAR Intents actually is

NEAR Intents routes user transactions through a solver market rather than through pooled liquidity. Users post a desired outcome — swapping a NEAR-native asset for USDC on Arbitrum, for instance — and registered solvers bid to fill the order. The protocol aggregates the quotes and assigns the fill to the winning solver, who then bears the bridge and execution risk across the destination chain.

The model, now replicated across multiple Layer-1 ecosystems through systems including UniswapX, 1inch Fusion, and deBridge, transfers slippage and execution risk from retail users to professional solver operators. Critics argue the architecture concentrates operational complexity in solver infrastructure; supporters argue it tightens fill quality and reduces MEV exposure for retail participants.

Why a full refund matters for protocol trust

Most DeFi exploits end with attackers moving stolen funds through mixers, bridging them to non-cooperating chains, or holding them indefinitely. Partial recoveries — typically 10% to 30% of the stolen sum in exchange for a pledge not to pursue prosecution — represent the most common negotiated outcome. A full refund at the protocol's full exposure restores user balances without forcing governance-token dilution, a treasury write-down, or a chain reorganization.

For NEAR Protocol's market positioning, the recovery limits the reputational hit at a moment when several competing intent-based architectures are competing for developer mindshare and institutional integrations.

What comes next

NEAR Intents' operators have not yet published a post-mortem identifying the smart-contract path that enabled the drain, the solver behavior that allowed it, or the negotiation timeline. Until that disclosure lands, the incident functions as an unresolved entry in the protocol's operational log, with direct implications for how prospective institutional users — and the solver operators underwriting cross-chain fills — price the risk of working-capital loss on the platform.

via Google News - Crypto Hack Exploit (Source)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles