LIVE CRYPTONEWSINSIGHTS
CryptoNewsInsightsYour source for daily crypto insights
Altcoin News

Near Intents Recovers Full $3.8M After 48-Hour Ultimatum

Laptop screen showing an abstract network graph in a dark office, illustrating the Near Intents exploit tracing

Near Intents has recovered the roughly $3.8 million drained in an exploit on Thursday, October 1, after its general manager publicly identified the attacker and set a 48-hour deadline, Decrypt reported.

Alex Shevchenko, general manager of the cross-chain swap service, wrote on X on Friday that the funds had been sent back in full and that the team was stopping its investigation. The return came one day after Shevchenko posted Bitcoin, BNB/Ethereum and Solana addresses for returning the money and addressed the attacker directly, saying the team had identified them.

Dark crypto trading desk with a monitor showing a glowing cross-chain network diagram at nightAlso readNEAR Intents Hacked for $3.8M and Patched Within an Hour

Key facts

  • Roughly $3.8 million was drained from Near Intents on Thursday, October 1, in a bug tied to how its Omni deposit and withdrawal layer interacted with its main smart contract, per Decrypt and Cointelegraph.
  • Shevchenko gave the attacker 48 hours to return the funds under what he framed as responsible disclosure, saying the window would close. He has not publicly named the person or shared evidence backing the identification, Coincentral noted.
  • Coincentral reported that services were paused across 11 networks, including BNB Chain, Polygon, TON and Avalanche, and that NEAR co-founder Illia Polosukhin said the exploit was isolated to USDT on BSC.
  • Blockchain investigator ZachXBT said the stolen funds were sent to KuCoin and bridged to Bitcoin, a detail carried by both Decrypt and Cointelegraph.
  • Near Intents has processed more than $30 billion in swaps, according to data from the service cited by Decrypt. Coincentral put current monthly volume at more than $4 billion.

How the return unfolded

Shevchenko’s Friday post followed a tense two-day stretch. On Thursday, Near Intents paused services after detecting the bug, pledged to compensate affected users in full and reported the incident to law enforcement. Cointelegraph reported that the protocol’s preliminary investigation found $3.8 million in user funds had been taken.

An on-chain message attached to a transaction, which Shevchenko shared and which appears to come from the exploiter, struck a contrite tone, saying all the funds had been returned and that the sender had been in the wrong. The message also thanked the Near team for being cordial during the process and urged others to use bug bounties instead of disrupting services.

Security monitoring screens showing a blockchain exploit alert after Moonwell's $9M Base hackAlso readMoonwell Loses Over $9M in Base Exploit After MAMO Price Oracle Manipulation

Coincentral reported the funds moved through a BNB Chain hot wallet tied to the HOT Bridge treasury, then KuCoin, then a Bitcoin bridge. During the response, the wallet moving the funds sent small amounts of ETH and BNB to a recovery address, each transfer carrying a message asking for contact details on Signal, according to Coincentral. By October 2, Coincentral said the Bitcoin recovery address had received about 34.59 BTC.

The reports differ in minor ways. Decrypt and Cointelegraph date Shevchenko’s ultimatum to Friday, while Coincentral describes the incident as occurring on October 1 and places the ultimatum on October 2. Coincentral also names more affected networks than the other two outlets and reports that the contract vulnerability was patched within about an hour, with deposits and withdrawals staying paused for close to 12 more hours.

Why it matters

Near Intents had already promised to repay affected users in full before the money came back, so the return mainly restores the protocol’s own balance sheet rather than changing what users were owed. The quick resolution contrasts with longer-running incidents, including the roughly $387.5 million Bitget breach from September 24 that Bitget and analytics firm Elliptic have pinned on North Korea, whose hacker Near Intents blocked two days before this exploit.

Coincentral reported that Polosukhin pointed to a wider pattern of attacks using AI tools, naming Bitget, MetaMask and Lido as other recent targets, and that NEAR Protocol confirmed its core blockchain and native token were not involved. Near Intents said this was its first major exploit since launch.

What to watch

Near Intents has promised a full post mortem, which Coincentral reported had not yet been published as of its latest update. Coincentral also said most services have been restored across affected networks, so the next concrete checkpoint is the release of that post mortem and confirmation that all paused networks are fully operational.

Sources: Decrypt, Cointelegraph, Coincentral

Written by Moris Nakamura

Moris Nakamura is the editor-in-chief at CryptoNewsInsights, overseeing coverage of Bitcoin, altcoin markets, and the broader cryptocurrency industry.

How we report
More from Altcoin News

This article is for information only and does not constitute financial advice. Cryptocurrency markets are volatile; do your own research before making investment decisions.