FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
    Filters
      Symbols
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      $3.8M Stolen from NEAR Intents Fully Recovered Following Omni Contract Exploit

      TLDR

      • GM Alex Shevchenko of NEAR Intents announced the complete recovery of approximately $3.8 million stolen during an October 1 security breach.
      • The vulnerability originated from a flaw in the interaction between NEAR Intents’ Omni deposit/withdrawal infrastructure and its smart contract architecture.
      • Emergency protocols suspended operations across 11 blockchain networks, including BNB Chain, Polygon, TON, and Avalanche, while the team responded.
      • On-chain investigators tracked the stolen assets through multiple channels: a BNB Chain hot wallet, exchanges including KuCoin, and ultimately a Bitcoin bridge.
      • NEAR’s main blockchain infrastructure and its native cryptocurrency remained completely unaffected throughout the incident.

      NEAR Intents has successfully recovered the entire sum of approximately $3.8 million that was stolen during a security exploit on October 1. General Manager Alex Shevchenko announced the recovery following an intense two-day period after issuing an ultimatum to the attacker.

      Before the stolen funds were recovered, the protocol had already committed to fully reimbursing all affected users. Consequently, the return of assets primarily impacts NEAR Intents’ internal finances rather than changing its obligation to compensate users.

      Breakdown of the Security Breach

      The exploit originated from a critical bug in how NEAR Intents’ Omni deposit and withdrawal system communicated with its underlying smart contract. Security teams determined the vulnerability existed within the contract layer itself.

      NEAR co-founder Illia Polosukhin clarified that the breach was limited to USDT on the Binance Smart Chain. He noted that the platform’s AI-powered security system, SHIELD, detected the suspicious transactions and automatically initiated emergency shutdown procedures.

      Engineers successfully patched the contract vulnerability approximately one hour after identification. However, as a precautionary measure, deposit and withdrawal functionality across multiple networks remained disabled for nearly 12 additional hours while comprehensive security audits and additional fixes were implemented.

      The affected blockchain networks included BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, Scroll, and Plasma. NEAR Protocol emphasized that its primary blockchain infrastructure and native cryptocurrency remained completely secure and were never compromised during the incident.

      Following the Money Trail

      Blockchain forensics experts identified suspicious activity connected to infrastructure associated with the HOT Bridge treasury on BNB Chain. Security researcher ZachXBT independently detected anomalous fund movements from a BNB Chain wallet connected to NEAR Intents.

      The tracking analysis revealed that stolen assets were routed through the KuCoin exchange before being converted and transferred via a Bitcoin bridge. Importantly, all available evidence indicates the NEAR blockchain itself was never directly compromised.

      Throughout the incident response, the wallet controlling the stolen funds transmitted small quantities of ETH and BNB to a designated recovery address. Each transaction contained an embedded message requesting secure communication via the Signal messaging platform.

      In response, Shevchenko published three distinct recovery wallet addresses—one each for Bitcoin, BNB Chain, and Solana networks. He issued a firm 48-hour deadline for the attacker to voluntarily return the stolen assets.

      In his public statement, Shevchenko declared, “We have identified you, sir,” framing it as a narrowing opportunity for responsible disclosure. However, he has not publicly revealed the suspected individual’s identity or shared the investigative evidence supporting the identification claim.

      By October 2, the Bitcoin recovery wallet had received approximately 34.59 BTC. Shortly thereafter, the team confirmed the complete return of funds across all three designated addresses.

      NEAR Intents formally reported the security breach to law enforcement authorities and collaborated with specialized cybersecurity firms to track the movement of stolen assets. While a comprehensive post-mortem report has been announced, it has not yet been made public.

      Polosukhin highlighted what he described as an emerging trend of cyberattacks leveraging AI-powered tools, citing recent incidents affecting Bitget, MetaMask, and Lido as examples. MetaMask acknowledged a separate infrastructure security event on October 1, while Lido also confirmed a breach involving its Ethereum validator infrastructure.

      Bitget continues managing the fallout from a massive $387 million hack that occurred on September 24, with stolen funds being laundered through protocols including CoW Protocol and Chainflip. NEAR Intents characterized this as its first significant security exploit since its launch, noting the platform now processes over $4 billion in monthly transaction volume.

      According to the most recent update, NEAR Intents has confirmed the full $3.8 million recovery and restored normal operations across the majority of affected blockchain networks.


      Source: Parameter
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud