Cross-Chain Protocol Near Intents Recovers $3.8 Million Following High-Stakes Exploit and Pressure From Team
Main Facts
Cross-chain swap service Near Intents has successfully recovered the entirety of the roughly $3.8 million drained during a security exploit on Thursday. The swift retrieval of funds occurred just a day after the project’s leadership publicly notified the attacker that their identity had been uncovered, issuing a strict 48-hour ultimatum.
The security incident was triggered by a vulnerability in how the protocol’s Omni deposit and withdrawal layer interacted with its core smart contract. This flaw allowed an unauthorized actor to siphon approximately $3.8 million in crypto assets. Immediate action was taken by the Near Intents team, which temporarily halted its cross-chain swap services, notified law enforcement, and vowed to reimburse affected users out of pocket if the funds were not recovered.
However, the situation resolved rapidly when the exploiter returned the full balance on Friday. Alex Shevchenko, the general manager of Near Intents, confirmed the development on social media platform X (formerly Twitter), stating, "The funds from the $3.8M NEAR Intents hack were sent back in full. We are stopping the investigation."
The successful recovery highlights an increasingly common dynamic in decentralized finance (DeFi), where targeted ultimatums, on-chain messaging, and the threat of law enforcement intervention sometimes prompt hackers to return stolen capital. In this instance, the exploiter returned the funds voluntarily via designated blockchain addresses, accompanied by an on-chain message expressing remorse and thanking the team for handling the situation cordially.
Chronology of Events
The unfolding of the Near Intents hack and subsequent recovery played out across a frantic 48-hour window, compounding an already turbulent week for the protocol and the broader ecosystem.
Tuesday: The Bitget Blockade
The week began with high tension for Near Intents. Two days prior to the exploit, the protocol successfully blocked a $50 million swap attempt. The transaction was tied to the hacker responsible for the massive $387.5 million Bitget breach—an incident that analytics firms, including Elliptic, as well as crypto exchanges have attributed to North Korean state-sponsored threat actors. The near-miss proved that Near Intents was actively being monitored or targeted by sophisticated malicious actors.
Thursday Morning: The Exploit and Protocol Halt
Despite dodging the Bitget-related threat earlier in the week, Near Intents fell victim to an internal smart contract vulnerability on Thursday. A bug in the interaction between the protocol’s Omni deposit/withdrawal layer and its main smart contract enabled an attacker to drain roughly $3.8 million.
In response, the Near Intents team acted swiftly:
- Service Suspension: The cross-chain swap service was immediately halted to prevent further draining.
- Incident Response: The team engaged blockchain security experts, including prominent on-chain sleuth ZachXBT—who tracked the stolen funds moving toward exchange KuCoin and subsequently being bridged to Bitcoin.
- Law Enforcement: The exploit was officially reported to relevant authorities.
Thursday Afternoon: The Ultimatum
Capitalizing on early intelligence, Alex Shevchenko took to X on Thursday afternoon. He published specific Bitcoin, BNB/Ethereum, and Solana addresses for returning the stolen capital and addressed the anonymous exploiter directly: "We have identified you, sir."
Shevchenko framed the communication as a final opportunity for responsible disclosure—a standard industry practice wherein security researchers report vulnerabilities to developers rather than weaponizing them. He warned the attacker that a 48-hour window had been opened, after which legal and investigative measures would aggressively ramp up.
Friday: Full Recovery and Closure
The strategy yielded immediate results. On-chain data revealed that the exploiter transferred the complete balance back to the protocol. An accompanying on-chain message from the hacker read: "We’ve returned all the funds, we were in the wrong." The message also commended the Near team for maintaining a professional and cordial demeanor throughout the tense negotiations, while echoing Shevchenko’s advice by urging other potential attackers to utilize formal bug bounty programs.
Following the verification of the returned funds, Shevchenko announced the official conclusion of the internal investigation, allowing Near Intents to resume normal operations planning.
Supporting Data and Technical Context
To understand the severity of the incident, it is essential to examine the mechanics of Near Intents, the nature of the vulnerability, and the broader macro-environment surrounding the Near ecosystem during the week of the attack.
How Near Intents Operates
Near Intents is a sophisticated cross-chain swap service that facilitates token exchanges across an expansive network of 35 distinct blockchains. Rather than relying on traditional automated market maker (AMM) liquidity pools for every swap, the platform operates on an "intent-centric" model:
- Users state the specific parameters of the trade they want to execute (their "intent").
- Independent market makers compete directly to fill these orders at the best available rates.
- The protocol has scaled rapidly, processing a cumulative total of more than $30 billion in swaps since its inception.
The Vulnerability Mechanics
The exploit did not stem from a compromise of the underlying Near protocol itself, but rather a specific edge case within Near Intents’ architecture. The vulnerability existed in the bridge mechanics governing how the Omni deposit and withdrawal layer interfaced with the primary smart contracts. By manipulating this communication channel, the attacker was able to trick the system into releasing funds without a valid corresponding counter-transaction.

The Stolen Funds Flow
According to blockchain investigator ZachXBT, the exploiter moved quickly to obscure the stolen assets following the theft:
- Assets were initially siphoned from the protocol smart contract.
- A portion of the funds was routed through centralized exchange KuCoin.
- The hacker subsequently bridged capital into the Bitcoin network to evade on-chain tracking across Ethereum-compatible chains.
Despite these obfuscation attempts, the Near Intents forensic team was able to map the attacker’s footprint quickly enough to establish positive identification before the funds could be fully laundered or mixed.
A Historic Week for NEAR
The incident coincided with a major milestone for the broader Near ecosystem. Just days prior to the hack, Bitwise officially launched the first spot NEAR ETF, bringing institutional-grade investment products to the token. This confluence of high-profile financial products, attempted hacks by state-sponsored actors, and the Near Intents exploit made for an exceptionally volatile week for community stakeholders and market observers alike.
Official Responses and Industry Reactions
The resolution of the Near Intents hack has sparked widespread discussion across the Web3 security and developer communities regarding ransom dynamics, ultimatum effectiveness, and the role of bug bounties.
The Near Intents Leadership Perspective
Alex Shevchenko’s public handling of the incident earned praise from various corners of the crypto industry for its directness and composure. By establishing immediate contact, providing clear avenues for restitution, and leveraging a firm deadline, the team avoided a protracted legal battle or permanent capital loss.
In his closing remarks on the matter, Shevchenko reiterated a plea that has become a mantra for ethical protocol development:
"Please use bug bounties instead of disrupting the services."
The Attacker’s Concession
The on-chain message left by the exploiter—acknowledging wrongdoing, thanking the team for their cordial approach, and pointing others toward bug bounties—underscores the psychological chess match inherent in modern crypto exploits. While critics argue that allowing hackers to return funds without legal consequence encourages copycat attacks, proponents maintain that recovering user funds safely and instantly remains the absolute highest priority for solvent protocols.
Web3 Security Community Insights
Security analysts pointed out that the Near Intents incident reflects a broader trend: protocols with strong on-chain monitoring capabilities and immediate forensic response teams are increasingly able to corner hackers, especially when assets are bridged through centralized choke points like exchanges or identifiable cross-chain bridges.
However, security firms continue to stress that reliance on ultimatums is no substitute for rigorous, multi-layered smart contract audits. The interaction layer between cross-chain messaging and main contract logic remains one of the most vulnerable attack vectors in the decentralized finance space, requiring heightened architectural scrutiny.
Implications for Decentralized Finance (DeFi)
The Near Intents exploit and its rapid resolution carry several vital implications for the future of cross-chain infrastructure, asset recovery, and protocol security standards.
1. The Rise of Cross-Chain Complexity Risks
As the DeFi ecosystem expands horizontally across dozens of interoperable chains, the complexity of cross-chain protocols grows exponentially. The vulnerability in Near Intents’ Omni deposit and withdrawal layer demonstrates that security audits must look beyond isolated smart contracts and focus heavily on the integration points—the bridges, layers, and messaging protocols that tie disparate blockchains together. As cross-chain volume scales into the hundreds of billions of dollars, securing these communication channels is paramount.
2. Evolving Incident Response Playbooks
The successful use of a public ultimatum backed by swift forensic tracking (with the help of independent sleuths like ZachXBT) adds a valuable case study to the DeFi incident response playbook. While protocols historically stayed silent or engaged in secretive negotiations, the "public doxing warning" model deployed by Shevchenko forces attackers into a binary choice: return the funds within a tight window or face coordinated global law enforcement and asset freezing.
3. The Centralization Choke Point Dilemma
The fact that stolen funds can often be tracked to centralized exchanges (such as KuCoin in this instance) highlights a complex reality of decentralized finance. True decentralization aims to remove gatekeepers, yet the ultimate recovery of tens of millions of dollars in exploit funds still frequently relies on centralized compliance desks, exchange cooperation, and KYC-gated off-ramps.
4. Institutional Confidence and the NEAR Ecosystem
Despite the drama surrounding the $50 million Bitget-related block and the subsequent $3.8 million internal exploit, the ability of Near Intents to make users whole and recover funds in less than 48 hours is a testament to operational resilience. With financial products like Bitwise’s spot NEAR ETF opening the ecosystem to institutional capital, maintaining rapid, transparent incident management is crucial for preserving market confidence and safeguarding the network’s long-term growth trajectory.
