NewsCryptoNear Intents Recovers $3.8 Million in Full After 48-Hour Ultimatum to Exploiter

Near Intents Recovers $3.8 Million in Full After 48-Hour Ultimatum to Exploiter

Author: Decrypt·

Key Takeaways

  • •Roughly $3.8 million stolen from Near Intents in a Thursday exploit was returned in full by Friday, and the team has ended its investigation.
  • •General manager Alex Shevchenko publicly stated the attacker had been identified and set a 48-hour repayment deadline, with the funds arriving inside that window.
  • •The breach stemmed from a bug in how the protocol's Omni deposit withdrawal layer interacted with its main smart contract, forcing a service halt with no restoration date announced.
  • •An on-chain message attributed to the exploiter admitted fault, thanked the Near team for its cordial handling, and urged others to use bug bounties.
  • •Days earlier, Near Intents blocked a $50 million swap attempt by the hacker behind the roughly $387.5 million Bitget breach, which Bitget and Elliptic have attributed to North Korea.
Near Intents Recovers $3.8 Million in Full After 48-Hour Ultimatum to Exploiter

Near Intents got its money back. The cross-chain swap service said Friday that the roughly $3.8 million drained in an exploit on Thursday has been returned in full, and general manager Alex Shevchenko said the team is ending its investigation into the incident.

"The funds from the $3.8M NEAR Intents hack were sent back in full," Alex Shevchenko, general manager of Near Intents, wrote on X. "We are stopping the investigation."

The return came one day after Shevchenko publicly told the attacker that the team knew who they were—well inside the 48-hour window he had set. On Thursday, he posted Bitcoin, BNB/Ethereum, and Solana addresses for returning the funds and addressed the exploiter directly: "We have identified you, sir."

He framed repayment as a last chance at responsible disclosure—the practice of reporting a vulnerability to developers instead of exploiting it—and warned that the window would close after 48 hours.

An on-chain message attached to a transaction, which Shevchenko shared and which appears to come from the exploiter, struck a contrite tone. "We've returned all the funds, we were in the wrong," it read. The message also thanked the Near team for being cordial during the process and urged others to use bug bounties.

Shevchenko had a parting message along the same lines: "Please use bug bounties instead of disrupting the services," he wrote.

Near Intents halted service on Thursday after a bug in how its Omni deposit withdrawal layer interacted with its main smart contract let an attacker siphon funds from the protocol. The team had pledged to compensate users in full and reported the incident to law enforcement. Blockchain sleuth ZachXBT said the stolen funds were sent to KuCoin and bridged to Bitcoin. As of Shevchenko's Friday update, the team had not said when the halted service would be restored.

Near Intents lets users swap tokens across 35 blockchains by stating what they want and letting market makers compete to fill the order. According to data from the service, the platform has processed more than $30 billion in swaps to date.

The exploit capped a turbulent week. Two days earlier, Near Intents blocked a $50 million swap attempt by the hacker behind the roughly $387.5 million Bitget breach, which Bitget and blockchain analytics firm Elliptic have pinned on North Korea. The hack also came days after Bitwise's spot NEAR ETF began trading.