NEAR Intents Hacker Returns Full $3.8M After Opening Negotiations

fiverr
Coinmama



All news is rigorously fact-checked and reviewed by leading blockchain experts and seasoned industry insiders.
  • The attacker returned the full $3.8 million taken from NEAR Intents.
  • Contact began through a 1 BNB transaction carrying a Signal request.
  • A published recovery wallet received about 34.59 BTC.
  • NEAR Intents says it has stopped the investigation.

NEAR Intents has recovered the full $3.8 million taken in its Oct. 1 exploit, less than a day after the team said it had identified the person responsible and gave them 48 hours to return the assets.

General Manager Alex Shevchenko confirmed on Oct. 2 in X that the funds had been returned in full and that the investigation was being stopped. He also urged security researchers to use bug-bounty programs rather than disrupt live services.

The resolution followed several hours of onchain negotiations. Before returning the bulk of the assets, an address labeled by BscScan as “Near Intents Exploiter 1” transferred 1 BNB to the recovery address and embedded a request to continue discussions privately:

“Willing to cooperate, reply with your Signal so contact is possible.”

The message marked the first visible sign that the incident could end in recovery rather than another attempt to move the stolen assets beyond the team’s reach.

Tokenmetrics

From Ultimatum to Full Return in Hours

NEAR Intents detected the exploit on Oct. 1 and initially estimated losses at approximately $3.8 million. The problem involved an interaction between its Omni deposit and withdrawal infrastructure and a NEAR Intents smart contract. The core NEAR blockchain and its native token were not compromised. CointelegraphBy the following day, Shevchenko said the team had identified the attacker and published addresses for returning assets across Bitcoin, BNB Chain/Ethereum and Solana.

The attacker was given 48 hours to cooperate.

Blockchain investigator ZachXBT had separately traced funds from the incident through KuCoin and into Bitcoin, providing an early view of how the stolen assets were being moved.

The response came well before the deadline.

After the initial 1 BNB message requesting Signal contact, the Bitcoin address published by Shevchenko received approximately 34.59 BTC between 14:31 and 15:05 UTC on Oct. 2, worth about $2.95 million using a Bitcoin price near $85,200 at the time.

A later BNB Chain transaction, confirmed at 16:15:28 UTC, carried another message from the address associated with the exploit. This time, the sender said the funds had been returned and acknowledged being “in the wrong.”

The message also thanked the NEAR team for its handling of the negotiations and recommended the use of bug bounties.

The transaction is permanently visible onchain.

NEAR Intents has not published a complete asset-by-asset reconciliation of every return transaction. The visible Bitcoin and BNB Chain activity therefore provides only part of the recovery trail, while Shevchenko’s confirmation establishes that the full amount was ultimately restored.

Recovery Does Not Erase the Security Failure

The outcome separates two parts of the incident that can easily be conflated.

The first is asset recovery. On that measure, NEAR Intents achieved a complete result: the stolen funds came back and the team ended its investigation.

The second is the vulnerability itself.

The assets were removed before any agreement existed between the attacker and NEAR Intents. Cooperation began only after the exploit, tracing work and the team’s public claim that it had identified the person responsible.

That makes the episode different from a conventional white-hat disclosure, where a researcher reports a vulnerability through an agreed process rather than first using it to remove user funds.

NEAR Intents had already committed to compensating affected users before the recovery. The return therefore changes the financial outcome of the incident, but not the need to explain how the vulnerable interaction reached production in the first place.

It also illustrates a limit of blockchain tracing. Investigators can follow assets between addresses, exchanges and chains, but identifying their route does not itself return them. In this case, the decisive step came when the person controlling the funds chose to communicate and cooperate after the team applied public pressure.

With the money restored, the next important disclosure is now technical rather than financial. NEAR Intents has yet to publish a full post-mortem explaining the Omni interaction that enabled the exploit and the safeguards introduced after the incident.





Source link

Bitbuy

Be the first to comment

Leave a Reply

Your email address will not be published.


*