0x026012ce0260…026012d1
NEAR Intents Sets 48-Hour Deadline for Attacker to Return $3.8 Million
NEAR Intents gave its attacker 48 hours to return $3.8 million, mostly USDT, drained from a BNB Chain treasury contract on October 1, and posted three return addresses.

Outputs
NEAR Intents set a 48-hour deadline for the attacker to return roughly $3.8 million, mostly USDT.
The exploit hit a treasury contract on BNB Chain on October 1, 2026, via a bug in the Omni deposit-and-withdrawal infrastructure.
The team patched the flaw within about an hour and has pledged full compensation for affected users.
Stolen funds were traced to KuCoin, where they were converted into Bitcoin.
The NEAR token fell 6-10% after the announcement despite the exploit being confined to NEAR Intents' own infrastructure.
NEAR Intents has given the attacker behind an October 1 exploit a 48-hour window to return approximately $3.8 million in stolen funds, according to the protocol's general manager, as reported by The Defiant. The cross-chain protocol published three addresses where the attacker can send the money back.
The deadline marks a shift in strategy. Earlier public communications from the team contained no return ultimatum; the new ultimatum moves the protocol from damage control toward direct pressure on whoever holds the funds.
What happened in the exploit?
The attack drained roughly $3.8 million, mostly in USDT, Tether's dollar-pegged stablecoin, from a treasury contract on BNB Chain. The root cause was a bug in how the protocol's Omni deposit-and-withdrawal infrastructure communicated with its smart contracts.
The team's response was fast. It halted services immediately after detecting the exploit and patched the contract-side flaw within roughly an hour. Core services resumed shortly after the fix, though some cross-chain features stayed offline longer while repairs continued.
Where did the stolen funds go?
Investigators traced the assets to KuCoin, the centralized crypto exchange, where the funds were converted into Bitcoin. NEAR Intents said it is working with law enforcement and blockchain analytics firms to trace the money.
The 48-hour deadline runs alongside that effort, not in place of it. The combination of a public ultimatum, exchange-level tracing and law-enforcement coordination gives the protocol multiple pressure points — a now-standard playbook for exploited DeFi teams, since funds converted on a centralized exchange leave a compliance trail that on-chain transfers alone do not.
The protocol has also pledged to fully compensate affected users.
Is this the protocol's first security incident?
No. Before the October 1 exploit, NEAR Intents had already blocked a significant volume of suspicious transactions tied to a previous hack. The prior incident suggests the protocol's monitoring systems had been tested before, though the latest attack succeeded anyway through a flaw in the Omni bridge layer rather than through the transaction flows caught earlier.
What does the incident mean for NEAR?
The NEAR token dropped between 6% and 10% after the exploit announcement, even though the breach was confined to NEAR Intents' own infrastructure. The underlying NEAR Protocol and its other applications were not directly affected.
The distinction matters for the token's market structure: NEAR Intents is a cross-chain application built in the protocol's ecosystem, and the treasury contract sat on BNB Chain, not on NEAR's own chain. The sell-off therefore reflected reputational contagion rather than a compromise of NEAR's base layer.
The timing is awkward for the ecosystem. The incident lands amid growing adoption and the launch of products such as the US spot NEAR ETF, which had extended the asset's reach into regulated US markets.
What happens next?
The clock now governs the protocol's next move. If the attacker does not return the funds within the 48-hour window, the matter defaults to the law-enforcement and analytics track, with KuCoin's conversion of the stolen USDT into Bitcoin already providing investigators an identifiable chokepoint.
via Crypto Briefing (Source)