
Crypto · updated 1h ago · 2 min read
NEAR Intents Recovers $3.8 Million After 48-Hour Ultimatum To Exploiter
NEAR Intents suffered a $3.8 million security exploit Exploiter identified and given a 48-hour ultimatum to return funds
Whether the key takeaway is ETF/investor risk or fund recovery.
8 of 10 outlets skipped it: exploitors were given a 48-hour ultimatum to return funds.
13outlets compared
Same story, two versions
tap a side to read it in full
SSource: CryptoSlate
“The timing gives new ETF investors an immediate test of whether ecosystem risk can overwhelm fresh institutional demand.”Read the original ↗
SSource: Cointelegraph
“NEAR Intents recovers entire stolen $3.8M after ultimatum to exploiter”Read the original ↗
CryptoSlate emphasises investor timing around the ETF, while Cointelegraph emphasises responsible disclosure and recovery after an ultimatum.
Ultimatum, then full return
NEAR Intents recovered the entire $3.8 million stolen from its platform after it issued a 48-hour ultimatum to the exploiter to return the funds. NEAR Intents said the theft involved an attacker exploiting a reentrancy flaw that transferred $3.8 million in NEAR tokens to an address controlled by the attacker. NEAR Intents told the attacker that if the funds were not returned within the deadline, legal action would be taken and relevant authorities would be notified.
Alex Shevchenko announced the complete return of funds later on Friday, writing on X, "The funds from the $3.8M NEAR Intents hack were sent back in full." NEAR Intents said it stopped the investigation and told users, "Please use bug bounties instead of disrupting the services."

What broke, what paused
NEAR Intents said it paused services after detecting a "bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract." NEAR Intents attributed the exploit to a bug in how its Omni deposit-and-withdrawal infrastructure interacted with the NEAR Intents smart contract, and it said the contract-side vulnerability had been patched. ZachXBT said the funds were transferred to the KuCoin exchange and bridged to Bitcoin after the exploit began with irregular withdrawals from a BNB Chain hot wallet linked to NEAR Intents.
NEAR Intents said it would fully reimburse losses caused by the incident, and it also pledged to compensate affected users in full. NEAR Intents and near.com resumed operations after the temporary suspension, while deposits and withdrawals on 11 networks remained unavailable for roughly 12 more hours.

Aftermath and next steps
NEAR Intents said it reported the incident to law enforcement and enlisted security and blockchain analytics firms to trace the funds. NEAR Intents said it would review its internal protocols and collaborate with third parties to strengthen the security of its smart contracts. NEAR Intents also planned to launch a series of educational workshops for NEAR developers, aiming to reduce the incidence of similar vulnerabilities in the future.
“The crypto space is entering a new era of far more sophisticated cyber attacks.”
Illia Polosukhin said the exploit was isolated to USDT on BSC and that NEAR Intents’ SHIELD security system detected unusual activity before pausing services. Polosukhin argued that "The crypto space is entering a new era of far more sophisticated cyber attacks" and said the ecosystem needs to raise the bar on both onchain contract standards and offchain monitoring and proactive prevention.