NEAR Intents Recovers $3.8 Million in Stolen Funds After Giving Hacker 48-Hour Deadline
NEAR Intents secures return of all stolen funds
NEAR Intents has recovered approximately $3.8 million that was stolen during a security breach on Thursday. The recovery followed an ultimatum issued to the person responsible for the exploit, giving them 48 hours to return the assets.
The company confirmed that the entire sum was returned in full. Following the recovery, the team announced it would stop its investigation into the incident.
Important details of the recovery
- The exploiter returned the full $3.8 million after being identified by the project.
- The breach was caused by a bug in how the NEAR Intents smart contract—a self-executing digital agreement—interacted with its deposit and withdrawal infrastructure.
- NEAR Intents had initially promised to compensate all affected users before the funds were sent back.
- The company has urged security researchers to use bug bounties, which are rewards for finding flaws, rather than disrupting services.
Statement from NEAR Intents leadership
Alex Shevchenko, the general manager of NEAR Intents, confirmed the return of the funds on the social media platform X. Shevchenko stated that because the money was returned, the investigation has been closed. He also encouraged developers to follow responsible disclosure practices in the future.
What the investigation revealed
The security breach was first detected on Thursday, leading NEAR Intents to pause its services. A preliminary investigation found that a bug in the Omni deposit and withdrawal infrastructure allowed the theft to occur. Blockchain investigator ZachXBT tracked the stolen funds as they were moved to the KuCoin exchange and then converted to Bitcoin, a well-known digital currency.
Why this recovery matters
While crypto hacks are common, recovering the full amount of stolen assets is less frequent. By identifying the person responsible and offering a deadline for the return of funds, the project was able to protect user assets without a permanent loss. This event also highlights the importance of bug bounty programs in maintaining blockchain security.