0x6161a4736161…6161a470
NEAR Intents Recovers Full $3.8M From Exploiter After 48-Hour Ultimatum
NEAR Intents says the full $3.8M taken in Thursday's exploit was returned after the protocol identified the attacker and gave them 48 hours under a responsible disclosure window.
Outputs
NEAR Intents recovered the full $3.8 million stolen in a Thursday breach of the Omni deposit and withdrawal infrastructure's interaction with its smart contract.
General manager Alex Shevchenko announced the complete return of funds on X and said the investigation is being stopped.
Blockchain investigator ZachXBT traced the stolen funds to the KuCoin exchange and bridged to Bitcoin.
NEAR Intents has recovered the full $3.8 million stolen in Thursday's security breach, after the protocol identified the individual responsible and issued a 48-hour deadline to return the funds under a "responsible disclosure" framework.
Alex Shevchenko, general manager of NEAR Intents, announced the complete restitution on Friday in a post on X. "The funds from the $3.8M NEAR Intents hack were sent back in full," Shevchenko wrote. "We are stopping the investigation. Please use bug bounties instead of disrupting the services."
The recovery closes an incident that began Thursday, when NEAR Intents detected what it described as a bug in the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. The protocol paused services immediately after detecting the flaw, a decision that limited the attack window and gave the team time to trace the exploit.
NEAR's preliminary investigation put user losses at $3.8 million. The protocol committed to compensating affected users in full, a pledge that now appears moot given the complete return of funds.
The turning point came on Friday, when NEAR Intents said it had identified the individual behind the breach and gave them 48 hours to return the funds, framing the demand as an opportunity for responsible disclosure rather than immediate legal escalation. The exploiter complied before the deadline expired.
On-chain tracing played a visible role in the pressure campaign. Blockchain investigator ZachXBT reported that funds from the incident were transferred to the KuCoin exchange and bridged to Bitcoin — movements that would have created fiat off-ramp pressure points for law enforcement and exchange compliance teams regardless of chain-hopping.
The episode illustrates a now-established playbook for mid-sized crypto exploits: pause withdrawals, trace the funds across chains and exchanges, identify the operator, and offer a disclosure window with the implicit threat of criminal referral. For exploiters, the calculus increasingly favors return. Once an identity surfaces and exchange touchpoints are flagged, laundering stolen funds becomes operationally difficult, and negotiated returns often come without prosecution.
The outcome also carries direct operational consequences for NEAR Intents. The protocol avoided a compensations process that would have stretched its treasury and sustained negative coverage. Service resumption, rather than price action, is the near-term operational question; the pause that followed the bug's discovery had cut off deposits and withdrawals across the bridge-linked infrastructure.
Shevchenko's closing message — urging attackers to "use bug bounties instead of disrupting the services" — signals that NEAR Intents intends to formalize its disclosure channel rather than rely on ad hoc ultimatums. Whether the protocol publishes a post-mortem detailing the exact flaw in the Omni–NEAR Intents smart contract interaction, and what bounty terms it offers, will shape how quickly institutional counterparties regain confidence in the bridge's deposit flow.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles