BLOCKCHAIN AI.NEWS

Security

'We Have Identified You, Sir': NEAR Intents' $3.8 Million Came Back Within a Day of the Ultimatum

A bug in how NEAR Intents' Omni deposit and withdrawal layer talked to its settlement contract let someone pull $3.8 million in USDT out of a BNB Chain hot wallet on October 1. Services on eleven networks paused, the contract was patched within an hour, and the general manager posted a 48-hour deadline addressed to a person he said the team had identified. The money was back by 14:30 UTC on October 2. The team says it has stopped investigating and will not say how it knew.

Editorial illustration: a frosted-glass vault door stands open at the end of a mirrored chrome corridor, and two neat stacks of glass coins sit on the threshold lit by a single warm gold glow, with a thin electric blue line tracing the floor
✓ CoinDesk had the exploit first, citing ZachXBT · The Crypto Times on the return · crypto.news, Finwire, Crypto Briefing, TechFlow, PANews · NEAR Intents Verifier contract documentation and the Omni Bridge repository read by this desk

On Thursday morning the on-chain investigator ZachXBT flagged unusual outflows from a BNB Chain hot wallet belonging to NEAR Intents, and traced the money to KuCoin and across a bridge to Bitcoin, more than $3.8 million in all. CoinDesk had it at 10:18 Eastern. By then NEAR Intents had paused deposits and withdrawals on eleven networks: BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. Its explanation was that "the incident was caused by a bug in the way its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract," that "the contract-side vulnerability has since been patched," and that affected funds would be reimbursed in full.

Friday afternoon the same team said it was done. "The funds from the $3.8M NEAR Intents hack were sent back in full," general manager Alex Shevchenko posted. "We are stopping the investigation. Please use bug bounties instead of disrupting the services." The Crypto Times puts the recovery at 14:30 UTC on October 2 and reports that about $2.95 million of it came back as 34.59 bitcoin, with the remaining $850,000 or so arriving by other routes. A transaction on BNB Chain from an address the explorer labels "Near Intents Exploiter 1" carried a message thanking the team for being "respectful, constructive, and cordial."

Two layers, one bug

NEAR Intents is not a single contract. Its documentation describes a settlement layer, the Verifier contract at intents.near, where "deposited tokens are credited to accounts in the contract's ledger" and "tokens leave the contract only on withdrawal through token bridges." Below that sit the bridges that actually hold assets on other chains and move them. When a user withdraws to another network, "the Verifier settles the withdrawal through the appropriate token bridge, delivering tokens to the destination address." The documentation adds that "Intents Technology does not custody these balances — control stays with the keys that can sign for each account."

Omni is one of those bridges, and it is NEAR's own. The Omni Bridge repository, maintained by the Near-One organization, describes a multi-chain bridge built on NEAR's Chain Signatures and a multi-party computation service; transfers out of NEAR are signed that way, and transfers in from BNB Chain and several EVM networks are verified through Wormhole. Its security policy points to a bug bounty on HackenProof for "NEAR intents bridges," which is the program Shevchenko's parting line refers to.

What the two statements together describe is a disagreement between the layers. The ledger said one thing about a balance and the bridge released another, and the gap was paid out of the bridge's BNB Chain hot wallet in USDT. NEAR co-founder Illia Polosukhin, posting on X Thursday, said the impact was limited to USDT on BNB Chain, that the core NEAR protocol and token were unaffected, and that the fix went in within an hour of detection. "All of the affected users will be compensated in full," he wrote, and: "At this scale, we have to hold ourselves to a higher security standard." The Desk has not seen a technical post-mortem, and nothing published so far says what the bug was in code terms, which contract was patched, or which side of the ledger-bridge seam was wrong.

The ultimatum

The part of this that will be remembered is Friday's post. "We have identified you, sir," Shevchenko wrote, publishing return addresses on Bitcoin, EVM chains and Solana and giving the person 48 hours. "You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes." Crypto Briefing and TechFlow both report that the incident had been referred to law enforcement. No bounty was offered in the post, and none has been announced since.

Asked afterward how the team had identified the person, Shevchenko replied: "No. We dropped the investigation already." He credited the work to the internal team, and Polosukhin said SHIELD, the screening layer NEAR Intents described two days earlier in the context of the Bitget theft, had assisted. The person was identified, by the team's account, in under 24 hours. ZachXBT's early trace through KuCoin, an exchange with account identification, is one obvious route to a name; the Desk is noting it as an inference, not reporting it as the method.

From outflow to return, as reported (UTC where given)

WhenWhatSource
Oct 1, morningZachXBT flags abnormal outflows from the BNB Chain hot wallet; funds to KuCoin and bridged to BitcoinTechFlow, CoinDesk
Oct 1, 14:18CoinDesk reports $3.8M loss and the pause on eleven networksCoinDesk
Oct 1Contract-side bug patched "within an hour" of detection; Polosukhin: impact limited to USDT on BNB Chain; services resume, some networks restrictedcrypto.news
Oct 2Shevchenko: "We have identified you, sir." 48-hour deadline, return addresses postedFinwire, Crypto Briefing
Oct 2, 14:30Funds returned in full, ≈34.59 BTC plus other routes; investigation stoppedThe Crypto Times, PANews
Sources as listed. The 14:18 UTC time is CoinDesk's 10:18 a.m. EDT publication stamp. NEAR Intents has not published its own timeline.

Three days, two postures

This is the second NEAR Intents story on this desk in three days, and the two sit oddly together. On Tuesday the team was explaining how SHIELD had declined to quote more than $50 million of swaps linked to the Bitget theft, holding $503,000 of it mid-swap. On Thursday its own bridge paid out $3.8 million it should not have, and the screening layer's contribution, by the team's account, was to the manhunt rather than the prevention. That is not a contradiction. SHIELD watches what comes in from other people's hacks; a ledger-bridge mismatch is a flaw in the house. But a protocol that has spent a week describing itself as the place stolen money cannot pass through has now had to ask for its own back, and got it, on terms it will not describe.

The posture on the money is clear and creditable: users made whole regardless, by Polosukhin's commitment on day one. The posture on the facts is not. There is no post-mortem, no statement of what was patched, and a flat refusal to say how the person was found. "We dropped the investigation already" closes the question of attribution, and the request to "use bug bounties instead of disrupting the services" reframes a theft as a disclosure that took the wrong door. Whether the person who took $3.8 million and gave it back after being named is a researcher or a thief who ran out of road is not something the public record can settle, because the people who could settle it have said they will not.

The Take

Getting the money back in a day is a good outcome, and a team that patches in an hour, promises full compensation before it knows where the funds went, and then recovers them deserves the credit for all three. But the last sentence of the story is "we are stopping the investigation," and a protocol that handles other people's money should read that sentence the way its users will. A bug in the seam between a settlement ledger and a bridge is the kind of flaw that recurs, across bridges, across chains, and in other people's code built the same way. The bounty program Shevchenko is pointing at exists so that the next person who finds one is paid to describe it. That only works if the protocol also describes the last one. Right now the only account of what went wrong at NEAR Intents is a transaction memo from the person who exploited it, thanking the team for being cordial.

More on the subject