NEAR Intents resumes service after $3.8M exploit, pledges full compensation

Bybit
fiverr



NEAR Intents has resumed service after a $3.8 million exploit affecting USDT on BSC, with co-founder Illia Polosukhin promising full compensation for affected users.

Summary

  • The attacker exploited Omni’s deposit and withdrawal interaction with the NEAR Intents smart contract.
  • Polosukhin said the team fixed the vulnerability within an hour of detection.
  • NEAR Intents and near.com returned online, although some affected chains remained restricted.
  • The core NEAR Protocol, NEAR token, and other applications were unaffected, according to Polosukhin.

NEAR co-founder Illia Polosukhin said on Oct. 1 that the team had restored NEAR Intents and near.com after temporarily pausing the service when its SHIELD security system detected unusual activity.

itrust

In his account of the incident, Polosukhin placed the loss at $3.8 million and said the vulnerability involved the interaction between Omni’s deposit and withdrawal infrastructure and the NEAR Intents smart contract. He limited the affected asset and network to USDT on BSC.

“All of the affected users will be compensated in full.”

NEAR Intents fixes the vulnerability within an hour

According to Polosukhin, SHIELD detected behavior outside normal activity patterns, prompting the temporary pause. The Intents team then identified the exact vulnerability and fixed it within an hour of detection.

While announcing the restart, the co-founder said a few affected chains on Intents remained unavailable. His update described NEAR Intents and near.com as back online, with restrictions still applying to those connections.

Polosukhin also separated the affected infrastructure from the underlying blockchain, saying the core NEAR Protocol, its native token and other applications running on NEAR were unaffected.

For the service’s operating scale, he put NEAR Intents’ monthly trading and payments volume above $4 billion. He described the incident as the first major exploit on Intents and said the team would conduct a full review and postmortem.

“At this scale, we have to hold ourselves to a higher security standard.”

In outlining the response, Polosukhin said findings from the incident would feed into additional security measures, alongside work already underway on a formal verification system for NEAR contracts.

SHIELD previously blocked Bitget-linked transfers

Earlier coverage of the same security system focused on attempts to move suspected stolen funds through NEAR Intents. On Sep. 29, crypto.news reported that the platform had blocked Bitget-linked transfers worth more than $50 million, citing NEAR Intents general manager Alex Shevchenko. Shevchenko attributed the intervention to SHIELD’s screening of activity passing through the service.

During execution, the system froze approximately $503,000, while about $166,000 in suspected stolen funds passed through before the activity was stopped, according to his account. He said rejected transfers subsequently moved toward other providers.

The earlier report cited Bitget’s confirmation that attackers had transferred approximately $387.5 million to addresses under their control during the exchange’s Sep. 24 security breach.

For the frozen funds, Shevchenko said NEAR Intents would return the money through an appropriate legal process and forgo Bitget’s recovery bounty. His description concerned transactions attempting to use NEAR Intents, rather than an ability to freeze assets across entire blockchains.

In the Oct. 1 statement, Polosukhin described SHIELD as an AI-based monitoring and outlier-detection system. He also invited additional partners to share information and help identify and contain criminal activity.

U.S. investors recently gained NEAR exposure through NRR

For American investors, the incident follows the Bitwise NEAR ETF launch on Sep. 29, when the product began trading on NYSE Arca under the ticker NRR. According to Bitwise, the fund charges a 0.75% management fee and holds NEAR directly, giving investors access through traditional brokerage accounts.

Bitwise said it intends to stake the fund’s NEAR through its institutional staking operation, with rewards accruing to shareholders through net asset value. At launch, the asset manager cited an annualized network staking reward rate of around 5% as of Sep. 25, while stressing that rewards can change and are not guaranteed.

In its launch announcement, Bitwise said the value of the fund’s shares is correlated with the NEAR it holds. Its risk disclosures also state that those holdings may face loss, theft, damage, or restrictions on access.

Polosukhin’s account of the Oct. 1 exploit specifically identified USDT on BSC as affected and said the NEAR token was untouched. His compensation commitment covered users affected by the exploit.

NEAR Intents also routes eligible users into Ondo products

The restored infrastructure also supports an integration announced in September. In Sep. 22 coverage of NEAR’s Ondo tokenized asset integration, Ondo Finance said eligible near.com users could exchange supported crypto assets for 20 tokenized U.S. stocks, ETFs and commodity-linked products. The initial selection included Tesla, Nvidia, Apple, Microsoft and Amazon, alongside QQQ, SLV and IAU.

According to the company’s description, NEAR Intents connects more than 30 blockchains and uses independent solvers to execute users’ requested transactions. Supported funding assets for the Ondo integration included Bitcoin and USDC.

Ondo’s disclosures restrict access by U.S. persons, despite the products tracking American-listed securities. The company stated that Ondo Stocks were not registered under the Securities Act of 1933 and could not be offered or sold in the United States or to U.S. persons without registration or an applicable exemption.

On security, Polosukhin called for stronger contract standards, monitoring and preventive measures, citing recent attacks targeting Bitget, MetaMask and Lido. He said criminals were using AI systems to probe infrastructure.

As part of the planned contract release process, Polosukhin said the NEAR ecosystem would shortly implement formal verification, which he described as a tool for preventing a class of vulnerabilities. Additional security measures will come from the incident postmortem, according to his statement.



Source link

Binance

Be the first to comment

Leave a Reply

Your email address will not be published.


*