$3.8M Returned vs. $900M Lost: Inside 2026’s Widening DeFi Security Divide

Ledger
Coinmama


Most hackers leave a trail of laundered coins. This one left an apology.

Less than two days after a $3.8 million exploit, a transaction landed on-chain carrying a short message admitting fault, thanking the victim’s team and urging everyone to use bug bounties. It is not the usual ending to a DeFi theft.

NEAR Intents Funds Return Is Confirmed Onchain

A transaction recorded on-chain shows the exploiter returning the money, and its status reads “Success”. NEAR Intents general manager Alex Shevchenko said the same on X: the $3.8 million is fully back and the team is closing its investigation.

okex

$3.8M Returned vs. $900M Lost: Inside 2026’s Widening DeFi Security Divide

What I like about this case is that two independent records agree. A team announcement could be spin, but a confirmed transaction with the exploiter’s own message attached is much harder to argue with.

The Onchain Message Reads Like a Confession and a Thank-You

The transaction page shows an Input Data Message, a note the sender embeds directly in the transaction. It opens with “We’ve returned all the funds, we were in the wrong,” a plain admission of fault from the party that took the money. It then thanks the NEAR team for staying respectful, constructive and cordial during the return process, and ends with a nudge to “always use bug bounties!”

$3.8M Returned vs. $900M Lost: Inside 2026’s Widening DeFi Security Divide

I’d call that a notable choice. The sender is not claiming white-hat status or demanding a reward. It reads as an apology with a lesson attached. The page also shows two chat messages linked to the transaction, which suggests the conversation did not stop at one note. The message says “we,” so it likely comes from more than one person, but nothing on the page names anyone.

Other 2026 Hacks Where the Funds Came Back

NEAR Intents is in decent company this year. The Liquid Network lost about 4,000 BTC, roughly $319 million, on September 6, and Blockstream’s own incident assessment covers the recovery. About 3,400 BTC, around 85%, came back the next day, though roughly $47 million is still outstanding and the attackers’ white-hat claim is unverified.

In May, the Verus-Ethereum bridge lost about $11.58 million, and after Verus’s official announcement of the attack, the hacker returned 4,052 ETH, about $8.5 million, keeping a 1,350 ETH bounty.

In April, Rhea Finance, another NEAR-ecosystem protocol, lost $18.4 million according to its official account. The attacker returned millions in USDC, NEAR and Zcash, leaving a shortfall of about $400,000 that the team committed to cover. The pattern is consistent: returns follow a patch, a bounty offer and a deadline.

Major 2026 Hacks Where the Money Never Came Back

The other side of the ledger is far bigger. On April 1, attackers drained about $285 million from Drift Protocol after a six-month social engineering campaign, and the project has since published a recovery update on rebuilding. A wallet linked to the exploit moved 23,095 ETH, about $44.4 million, into Tornado Cash in late July. On April 18, KelpDAO lost 116,500 rsETH, about $292 million, in a bridge attack that LayerZero Labs’ incident report attributes to North Korea’s TraderTraitor group. Arbitrum’s Security Council froze 30,766 ETH, about $100 million, but I found no reports of the attackers returning anything.

The newest example is the Bitget breach of about $387.5 million on September 24. ZachXBT reported that suspected North Korean attackers were moving the stolen funds into Zcash. State-backed groups rarely negotiate, so bounty offers carry little weight with them.

Disclosure: This is not trading or investment advice. Always do your research before buying any cryptocurrency or investing in any services. Follow us on X @nulltxnews



Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*