NEAR Intents Says It Has Identified $3.8M Hacker, Gives 48-Hour Ultimatum
Key Takeaways
- •NEAR Intents suffered a security breach on Thursday that drained $3.8 million in user funds via a bug in the interaction between its Omni deposit and withdrawal infrastructure and the protocol's smart contract.
- •The protocol says it has identified the attacker and issued a 48-hour deadline for the funds to be returned under responsible disclosure, with general manager Alex Shevchenko sharing three wallet addresses for Bitcoin, BNB, and Solana.
- •NEAR Intents paused its services after detecting the exploit and has pledged to compensate affected users in full.
- •Blockchain investigator ZachXBT reported that the stolen funds were transferred to the KuCoin exchange and subsequently bridged to Bitcoin.
- •The exploit came after NEAR Intents assisted in connection with the earlier Bitget breach and highlights that cross-chain trading infrastructure remains a recurring target for industry attacks.

NEAR Intents, a cross-chain trading protocol in the NEAR ecosystem, said it has identified the individual behind a security breach that drained $3.8 million in user funds on Thursday, giving the attacker 48 hours to return the money under what the protocol called “responsible disclosure.”
“We have identified you, sir,” NEAR Intents general manager Alex Shevchenko said in an X post on Friday, sharing three different wallet addresses to receive Bitcoin, BNB and Solana.
“You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes,” he added.
Responsible disclosure is a long-standing convention in cybersecurity under which someone who discovers a flaw reports it privately so it can be fixed, typically in exchange for a reward rather than facing efforts to recover the extracted funds. By naming a deadline publicly, NEAR Intents is pushing the attacker toward that route.
The ultimatum came after NEAR Intents paused its services on Thursday upon detecting a “bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.”
The protocol’s preliminary investigation found that $3.8 million in user funds had been stolen, and it pledged to compensate affected users in full.
Blockchain investigator ZachXBT reported that the stolen funds were transferred to the KuCoin exchange and subsequently bridged to Bitcoin. Tracing funds to a centralized exchange is often a pivotal step in such cases, since platforms like KuCoin apply identity-verification checks to their users — a point where stolen assets have historically been flagged.
Cross-chain trading infrastructure, which shuttles assets between networks, has been a recurring target for exploits across the industry, and the incident places NEAR Intents among the protocols in that category to come under attack.\nThe exploit followed NEAR Intents’ assistance in connection with the earlier Bitget breach, according to Cointelegraph’s related reporting.
With its services paused, the immediate questions are whether the attacker uses the 48-hour window and how the protocol’s full-compensation pledge is carried out.
Source: Cointelegraph