CryptoCoinArticle is online

“We Identified You, Sir”: Near Intents Recovers $3.8M After 48-Hour Ultimatum

Mr. W
“We Identified You, Sir”: Near Intents Recovers $3.8M After 48-Hour Ultimatum

Preface


Overview: Near Intents, a cross-chain swap service, successfully recovered the roughly $3.8 million that was taken in a recent exploit. This article summarizes the incident, the company’s public response, and the outcome after a 48-hour ultimatum directed at the attacker. The goal is to present a clear, factual account of events and to explain how prompt public communication and the offer of responsible disclosure contributed to a full return of funds.



Lazy bag


Key takeaway: Near Intents publicly identified the exploiter and gave a 48-hour window to return the stolen assets; the attacker complied, posting an on-chain message admitting fault and returning the entire $3.8M. The team then stopped its investigation.



Main Body


On Thursday, Near Intents announced that a vulnerability had been exploited, allowing an attacker to drain roughly $3.8 million from the platform. The company immediately halted service to prevent further losses and pledged to compensate affected users. The exploit originated from a bug in how the platform’s Omni deposit and withdrawal layer interacted with its main smart contract, which enabled unauthorized fund transfers.



In response, Alex Shevchenko, general manager of Near Intents, posted public instructions for returning the funds, including Bitcoin, BNB/Ethereum and Solana addresses. He directly addressed the exploiter in a public message: "We have identified you, sir." That message framed the forthcoming window as an opportunity for responsible disclosure—the accepted security practice of reporting vulnerabilities to developers rather than exploiting them—and set a strict 48-hour deadline for returning the assets.



Within the given timeframe, an on-chain transaction accompanied by a message—apparently from the exploiter—returned the full amount. The message read in part, "We've returned all the funds, we were in the wrong," and expressed appreciation for the Near team’s civility during the process. It also urged others to choose bug bounties over exploiting vulnerabilities, reinforcing the company’s appeal to ethical behavior in the security community.



Following the return, Shevchenko confirmed on social media that the full $3.8 million had been recovered and that the team would cease its investigation. He also reiterated the company’s intent to restore normal operations and to make users whole. Near Intents had already reported the incident to law enforcement and pledged compensation for affected customers, steps consistent with standard incident response procedures.



Blockchain analysts tracked the movement of the stolen funds prior to their return. Some traces suggested transfers to centralized exchange addresses and bridging to other chains—actions commonly used by attackers to obfuscate provenance. The company’s swift public stance, combined with on-chain transparency, likely contributed to the rapid resolution.



The exploit came amid a busy period for Near Intents. Two days earlier the platform had blocked a separate large swap attempt tied to a different major breach. That earlier event involved a $50 million swap attempt associated with the actor blamed for a separate high-profile attack. The wider context—multiple large incidents and the recent launch of a related spot NEAR ETF—made quick, decisive action especially important to preserve user trust and market stability.



Near Intents facilitates token swaps across 35 blockchains by accepting users’ desired trades and allowing market makers to compete to fill them. The platform has processed tens of billions in swap volume, underscoring the potential impact when implementation bugs are exploited. This incident highlights the persistent importance of secure smart contract design, careful integration of bridging layers, and robust incident response plans for cross-chain services.



Lessons from this case include the value of transparent communication, the deterrent effect of naming and confronting an attacker when evidence supports identification, and the usefulness of responsible disclosure incentives such as bug bounties. Near Intents explicitly encouraged the community to favor bug bounties and coordinated disclosure over disruptive exploits—an appeal echoed in the exploiter’s return message.



While the funds were fully returned and the immediate crisis resolved, the event will likely prompt further internal audits, security hardening, and possibly expanded cooperation with external security researchers. Companies that operate bridges or cross-chain infrastructure should consider enhanced testing, formal verification where feasible, and stronger monitoring to detect anomalous interactions between layers and contracts.



In summary, Near Intents recovered the full $3.8 million after publicly identifying the exploiter and offering a 48-hour window for responsible disclosure. The incident concluded with a returned balance and a message urging ethical behavior; nonetheless, it underscores ongoing security challenges for cross-chain services and the continuing need for proactive vulnerability management.



Key Insights Table



















Aspect Description
Key Fact 1 Near Intents recovered the full $3.8 million stolen in the exploit after publicly identifying the attacker and issuing a 48-hour ultimatum.
Key Fact 2 An on-chain message, apparently from the exploiter, admitted fault, returned the funds, and encouraged the use of bug bounties.

Last edited at:2026/10/4