{"id":2130,"date":"2026-10-03T14:23:11","date_gmt":"2026-10-03T14:23:11","guid":{"rendered":"https:\/\/xesi.net\/?p=2130"},"modified":"2026-10-03T14:23:11","modified_gmt":"2026-10-03T14:23:11","slug":"near-intents-recovers-3-8-million-stolen-in-security-breach-following-ultimatum","status":"publish","type":"post","link":"https:\/\/xesi.net\/?p=2130","title":{"rendered":"NEAR Intents Recovers $3.8 Million Stolen in Security Breach Following Ultimatum"},"content":{"rendered":"<p>NEAR Intents has successfully recovered approximately $3.8 million in digital assets that were stolen earlier this week during a security breach. The swift recovery came after the protocol&#8217;s development team identified the individual responsible for the exploit and issued a strict 48-hour ultimatum, urging the perpetrator to return the funds under the framework of responsible disclosure or face aggressive legal and on-chain tracking measures.<\/p>\n<p>The incident first came to light when NEAR Intents detected suspicious activity impacting its infrastructure. According to subsequent technical disclosures from the project, the exploit was traced back to a specific vulnerability involving the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. As a result of this infrastructure flaw, unauthorized actors were able to siphon off user funds amounting to approximately $3.8 million. <\/p>\n<p>In the immediate aftermath of the breach, the platform acted quickly to mitigate further damage. NEAR Intents announced that it was pausing its core services to isolate the vulnerability and prevent any additional assets from being compromised. At the time, preliminary internal investigations confirmed the total financial loss and the team publicly pledged that, regardless of the outcome of recovery efforts, all affected users would be fully compensated for their losses out of the project&#8217;s reserves.<\/p>\n<p>As the crypto community mobilized to analyze the exploit, prominent independent blockchain investigator ZachXBT provided crucial tracking details regarding the movement of the stolen capital. According to insights shared by ZachXBT, the exploiter rapidly attempted to obscure the trail of the stolen cryptocurrency by transferring portions of the funds to the KuCoin centralized cryptocurrency exchange and subsequently bridging assets across to the Bitcoin network, a common tactic used by malicious actors seeking to launder illicitly obtained funds across different blockchain ecosystems.<\/p>\n<p>Despite these laundering attempts, the technical and investigative team behind NEAR Intents continued their forensic analysis at a rapid pace. By Friday, reports surfaced confirming that the protocol had successfully pinpointed the identity of the individual behind the security breach. Armed with this critical information, NEAR Intents opted to pursue a diplomatic yet firm resolution before escalating the matter to international law enforcement agencies. The project issued a public 48-hour ultimatum to the hacker, giving them a narrow window of opportunity to return the stolen $3.8 million voluntarily under the principles of responsible disclosure.<\/p>\n<p>The strategy proved successful later that same day. Alex Shevchenko, the general manager of NEAR Intents, took to social media to announce that the stolen capital had been fully restored to the protocol. Writing on the X platform, Shevchenko confirmed the complete resolution of the crisis, stating that the funds from the $3.8 million NEAR Intents hack had been sent back in full. He added that the internal and external investigations were officially being called off, while taking the opportunity to urge developers and security researchers to utilize legitimate bug bounty programs in the future rather than disrupting live production services and compromising user funds.<\/p>\n<p>The swift resolution highlights both the vulnerabilities inherent in complex cross-chain and smart contract interactions within the decentralized finance sector and the evolving tactics used by protocols to recover stolen funds. By combining rapid infrastructure pauses, transparent communication with the user base, on-chain tracking collaboration with independent investigators like ZachXBT, and decisive direct engagement with exploiters, NEAR Intents was able to avert what could have been a permanent financial loss for its user community. With services secured and user funds returned in full, the protocol is expected to conduct a comprehensive security audit of its Omni deposit and withdrawal infrastructure before resuming normal operations, ensuring that similar contract interaction bugs are thoroughly addressed moving forward.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NEAR Intents has successfully recovered approximately $3.8 million in digital assets that were stolen earlier this week during a security breach. The swift recovery came after the protocol&#8217;s development team identified the individual responsible for the exploit and issued a strict 48-hour ultimatum, urging the perpetrator to return the funds under the framework of responsible [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2129,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[933],"tags":[935,139,934,1121,3242,136,346,3925,2608,3926,3927,936],"class_list":["post-2130","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency-and-web3","tag-blockchain","tag-breach","tag-crypto","tag-following","tag-intents","tag-million","tag-near","tag-recovers","tag-security","tag-stolen","tag-ultimatum","tag-web3"],"_links":{"self":[{"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/posts\/2130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2130"}],"version-history":[{"count":0,"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/posts\/2130\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=\/wp\/v2\/media\/2129"}],"wp:attachment":[{"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2130"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2130"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xesi.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}