NEAR Intents Hacker Returns $3.8 Million After 48 Hour Deadline

Blockonomics


Set as Google Preferred SourceFollow on Google News

TLDR

  • NEAR Intents GM Alex Shevchenko confirmed the full return of roughly $3.8 million taken in an October 1 exploit.
  • The bug was found in how NEAR Intents’ Omni deposit and withdrawal system interacted with its smart contract.
  • Services were paused across 11 networks including BNB Chain, Polygon, TON, and Avalanche during the response.
  • The stolen funds were traced through a BNB Chain hot wallet, KuCoin, and a Bitcoin bridge.
  • The core NEAR blockchain and its native token were not affected by the exploit.

NEAR Intents has confirmed that roughly $3.8 million taken in an exploit on October 1 has been fully returned. GM Alex Shevchenko shared the update after a tense 48 hour period following the incident.

The protocol had already promised to repay affected users in full before the funds came back. That means the return mostly affects NEAR Intents’ own balance sheet rather than what it owed its users.

How The Exploit Happened

The issue stemmed from a bug connecting NEAR Intents’ Omni deposit and withdrawal infrastructure with its smart contract. The flaw was found on the contract side.

NEAR co-founder Illia Polosukhin said the exploit was isolated to USDT on BSC. He added that the platform’s AI security layer, called SHIELD, flagged the unusual activity and triggered a pause.

The contract vulnerability was patched within about an hour of being found. Despite the quick fix, deposits and withdrawals across several networks stayed paused for close to 12 more hours while additional fixes were completed.


Betpanda


Networks affected included BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, Scroll, and Plasma. NEAR Protocol confirmed that its core blockchain and native token were not involved in the incident at any point.

Tracing The Stolen Funds

Blockchain investigators traced the abnormal activity to infrastructure tied to the HOT Bridge treasury on BNB Chain. Investigator ZachXBT also flagged unusual outflows from a BNB Chain wallet linked to NEAR Intents.

According to that tracing, the funds moved through KuCoin before being bridged into Bitcoin. Nothing in the available reporting suggests the base NEAR chain itself was breached.

During the response, the wallet responsible for moving the funds sent small amounts of ETH and BNB to a recovery address. Each transfer included a message asking for contact details on Signal.

Shevchenko later posted three recovery addresses, one each for Bitcoin, BNB Chain, and Solana. He gave the suspected attacker a 48 hour deadline to return the funds voluntarily.

In his message, Shevchenko wrote, “We have identified you, sir,” and called it a closing window for responsible disclosure. He has not publicly named the person responsible or shared evidence backing the identification.

By October 2, the Bitcoin recovery address had received about 34.59 BTC. The full return across all three addresses was confirmed shortly after.

NEAR Intents reported the incident to law enforcement and worked with security firms to trace the stolen assets. A full post mortem has been promised but has not yet been published.

Polosukhin pointed to a wider pattern of attacks using AI tools, naming Bitget, MetaMask, and Lido as other recent targets. MetaMask confirmed a separate infrastructure incident on October 1, and Lido also confirmed a compromise tied to its Ethereum validators.

Bitget is still dealing with the aftermath of a $387 million hack from September 24, with funds laundered through CoW Protocol and Chainflip. NEAR Intents said this was its first major exploit since launch, with the platform now processing more than $4 billion a month.

As of the latest update, NEAR Intents confirmed the full $3.8 million has been returned and most services remain restored across all affected networks.





Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*