NEAR Intents Recovers Full $3.8M in Stolen Crypto After 48-Hour Ultimatum
NEAR Intents has recovered the entire $3.8 million stolen during a Thursday security breach after identifying the individual responsible and issuing a 48-hour ultimatum under a "responsible disclosure" framework. General manager Alex Shevchenko confirmed the complete return of funds on Friday in a post on X, stating: "The funds from the $3.8M NEAR Intents hack were sent back in full." Shevchenko added that NEAR Intents is halting its investigation and urged the exploiter to "use bug bounties instead of disrupting the services."
The breach stemmed from a bug in the Omni deposit and withdrawal infrastructure's interaction with the NEAR Intents smart contract, prompting the platform to pause services after detecting the vulnerability. NEAR's preliminary investigation determined that approximately $3.8 million in user funds had been stolen, with the protocol pledging to compensate affected users in full. Blockchain investigator ZachXBT traced the stolen funds to the KuCoin exchange, where they were bridged to Bitcoin.
This successful recovery highlights the growing use of responsible disclosure timelines in the crypto industry, where projects grant identified hackers a set window to return funds in exchange for halting legal action. The incident adds to ongoing debates around on-chain security practices and the effectiveness of bug bounty programs as an alternative to exploiting protocol vulnerabilities, echoing recent community friction between THORChain and NEAR supporters over differing philosophies on how protocols should handle adversarial actors.
Following the resolution, NEAR Intents is expected to resume full operations while continuing its broader review of smart contract interactions with cross-chain infrastructure to prevent similar exploits.
Read Full Article at CoinTelegraph →