NEAR Intents Identifies $3.8M Hacker, Gives Them 48 Hours to Return Funds
NEAR Intents GM Alex Shevchenko has identified the attacker behind a $3.8 million exploit and given the hacker 48 hours to return the stolen funds, after a bug in its Omni deposit and withdrawal infrastructure was exploited. The platform has restored most services and plans to compensate affected users in full while investigators trace the assets. Shevchenko’s post on X directly addressed the attacker: “We have identified you, sir.” He then asked the person responsible to return the funds to Bitcoin, BNB/Ethereum, and Solana addresses. “You know better than most how responsible disclosure works — this is the last window to use it,” he told the hacker. “After 48 hours, that window closes.” According to NEAR Intents’ own account, services were halted after a security incident was detected. A bug in how the Omni deposit and withdrawal infrastructure interacts with the NEAR Intents smart contract caused the loss, which a preliminary assessment put at approximately $3.8 million. Illia Polosukhin, a NEAR co-founder, added that the exploit was isolated to USDT on BSC, and that SHIELD, the platform’s AI security layer, flagged outlier behavior and triggered the pause. The contract vulnerability was patched within an hour of detection, and NEAR Intents and near.com are back online. Deposits and withdrawals on BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma remained unavailable for about 12 additional hours while Omni fixes were completed. Furthermore, the NEAR Protocol confirmed that it was fully operational, and that neither it nor its native NEAR token had been involved in the Intents incident. Data from CoinGecko at the time of writing shows the cryptocurrency down more than 5% in 24 hours, although other timeframes were all green, including a 166% jump in the last 30 days. Affected users will be compensated in full, while the incident has been reported to law enforcement. NEAR Intents is also working with other security and blockchain analytics partners to trace the stolen assets. Polosukhin argued that crypto is entering a period of more sophisticated attacks, naming Bitget, MetaMask and Lido as recent targets of criminals using AI systems. “As a space, we need to be far more vigilant and raise the bar on both onchain contract standards and offchain monitoring and proactive prevention,” he wrote. MetaMask confirmed an infrastructure se
AI Analysis:
Disclaimer: This information is from public sources for reference only. Traceless does not guarantee accuracy.