0x2751e5aa2751…2751e5a7
NEAR Intents Hack Totaled $3.87M; 76% of Funds Bridge to Bitcoin
The NEAR Intents exploit drained $3.87 million, with on-chain data showing 76% of stolen funds routed to Bitcoin as the team says it identified the hacker.
Outputs
NEAR Intents exploit totaled $3.87 million in losses
On-chain data shows roughly 76% of stolen funds (~$2.94M) routed to Bitcoin
NEAR Intents team says it has identified the hacker behind the exploit
The NEAR Intents exploit resulted in losses of $3.87 million, with on-chain flows showing that roughly 76% of the stolen funds — approximately $2.94 million — moved to Bitcoin, according to blockchain-tracing data cited in the incident's aftermath.
The attack targeted NEAR Intents, the cross-chain swap service operating within the NEAR Protocol ecosystem that lets users trade assets across blockchains without conventional bridging infrastructure. The exploit drained $3.87 million from the protocol before the movement of funds could be contained.
On-chain records show the attacker routed the majority of the proceeds to Bitcoin. The 76% allocation to the Bitcoin network complicates recovery efforts, because Bitcoin's UTXO model and the attacker's presumed use of mixing services make fund tracing materially harder than on EVM-compatible chains, where forensic firms can tag addresses and coordinate with centralized exchanges.
The remaining quarter of the stolen assets stayed within other chains, according to the tracing data. The split suggests the attacker deliberately diversified the destination of proceeds across networks with different transparency profiles, a tactic security analysts associate with attempts to frustrate attribution and freezing requests.
The NEAR Intents team stated it has identified the individual behind the exploit. The team did not initially disclose how the identification was made — whether through on-chain forensics, exchange KYC records tied to cash-out attempts, or internal operational clues — and it has not publicly named the perpetrator. The claim, if substantiated, would shift the incident from an anonymous exploit toward a potential negotiation or legal recovery track, a path previously taken in cases where protocols offered bug-bounty-style settlements to attackers who returned funds.
The identification claim carries operational weight for affected users. Protocols that can attribute an exploit to a specific actor gain leverage: they can pursue civil claims, engage law enforcement in a targeted manner, or open direct communication channels for a negotiated return. Several high-profile incidents in past cycles ended with partial or full restitution after teams publicly identified attackers and applied pressure through exchanges and authorities.
The Bitcoin routing, however, works against that leverage. Funds converted to Bitcoin and dispersed through mixers or chain-hopping techniques can sit dormant for months or years before attackers attempt cash-outs. Recovery in such scenarios typically depends on the moment stolen bitcoin touches a regulated off-ramp.
The exploit itself adds to the incident record for cross-chain intent-based trading infrastructure, a sector that has grown as an alternative to traditional token bridges. Intent-based systems match users with solvers or fillers who execute swaps across chains, reducing direct bridge exposure but concentrating risk in the smart-contract and signing logic that orchestrates settlement. A $3.87 million loss is modest by historical exploit standards, yet it tests the sector's core pitch: that architectural changes reduce, rather than relocate, attack surface.
For NEAR Protocol's broader ecosystem, the incident puts operational scrutiny on NEAR Intents at a time when cross-chain usability remains a key adoption argument for the network. How the team handles restitution, and whether its identification claim produces an actual recovery or legal action, will likely shape user confidence in the service going forward.
The team's stated next steps center on the identified attacker and the traced fund flows. Watch for a public disclosure of the perpetrator's identity, a law-enforcement referral, or a negotiated return of funds — the three outcomes that historically follow attribution claims of this kind.
via Google News - Crypto Hack Exploit (Source)