Published Updated

NEAR Intents Recovers $3.8 Million After 48-Hour Ultimatum To Exploiter
Image: خبرپو

Crypto · updated 1h ago · 2 min read

NEAR Intents Recovers $3.8 Million After 48-Hour Ultimatum To Exploiter

Happened

NEAR Intents suffered a $3.8 million security exploit Exploiter identified and given a 48-hour ultimatum to return funds

Split on

Whether the key takeaway is ETF/investor risk or fund recovery.

Left out

8 of 10 outlets skipped it: exploitors were given a 48-hour ultimatum to return funds.

13outlets compared

@coindeskBigGo Financebitcoin.esbloomingbitCoinGapeCointelegraphCryptopolitanCryptoSlate

Same story, two versions

tap a side to read it in full

SSource: CryptoSlate

“The timing gives new ETF investors an immediate test of whether ecosystem risk can overwhelm fresh institutional demand.”
Read the original ↗

SSource: Cointelegraph

“NEAR Intents recovers entire stolen $3.8M after ultimatum to exploiter”
Read the original ↗
VS

CryptoSlate emphasises investor timing around the ETF, while Cointelegraph emphasises responsible disclosure and recovery after an ultimatum.

Ultimatum, then full return

NEAR Intents recovered the entire $3.8 million stolen from its platform after it issued a 48-hour ultimatum to the exploiter to return the funds. NEAR Intents said the theft involved an attacker exploiting a reentrancy flaw that transferred $3.8 million in NEAR tokens to an address controlled by the attacker. NEAR Intents told the attacker that if the funds were not returned within the deadline, legal action would be taken and relevant authorities would be notified.

Alex Shevchenko announced the complete return of funds later on Friday, writing on X, "The funds from the $3.8M NEAR Intents hack were sent back in full." NEAR Intents said it stopped the investigation and told users, "Please use bug bounties instead of disrupting the services."

Image from @coindesk
@coindesk@coindesk

What broke, what paused

NEAR Intents said it paused services after detecting a "bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract." NEAR Intents attributed the exploit to a bug in how its Omni deposit-and-withdrawal infrastructure interacted with the NEAR Intents smart contract, and it said the contract-side vulnerability had been patched. ZachXBT said the funds were transferred to the KuCoin exchange and bridged to Bitcoin after the exploit began with irregular withdrawals from a BNB Chain hot wallet linked to NEAR Intents.

NEAR Intents said it would fully reimburse losses caused by the incident, and it also pledged to compensate affected users in full. NEAR Intents and near.com resumed operations after the temporary suspension, while deposits and withdrawals on 11 networks remained unavailable for roughly 12 more hours.

Image from bitcoin.es
bitcoin.esbitcoin.es

Aftermath and next steps

NEAR Intents said it reported the incident to law enforcement and enlisted security and blockchain analytics firms to trace the funds. NEAR Intents said it would review its internal protocols and collaborate with third parties to strengthen the security of its smart contracts. NEAR Intents also planned to launch a series of educational workshops for NEAR developers, aiming to reduce the incidence of similar vulnerabilities in the future.

“The crypto space is entering a new era of far more sophisticated cyber attacks.”

Wall Street arrived in NEAR just as a $4 billion-a-month app got hacked

Illia Polosukhin said the exploit was isolated to USDT on BSC and that NEAR Intents’ SHIELD security system detected unusual activity before pausing services. Polosukhin argued that "The crypto space is entering a new era of far more sophisticated cyber attacks" and said the ecosystem needs to raise the bar on both onchain contract standards and offchain monitoring and proactive prevention.

Sourcesbitcoin.esbitcoin.es