Home Cybersecurity SKN | NEAR Intents Recovers Entire $3.8M Stolen in Security Breach
Cybersecurity

SKN | NEAR Intents Recovers Entire $3.8M Stolen in Security Breach

Share
Share

Key Points

  • NEAR Intents recovered the full approximately $3.8 million stolen during a security breach involving its Omni deposit and withdrawal infrastructure.
  • The exploiter returned the funds after NEAR Intents identified the individual and issued a 48-hour ultimatum under a responsible-disclosure process.
  • NEAR Intents had paused services after discovering the vulnerability and previously committed to fully compensating affected users.

NEAR Intents has recovered the entire approximately $3.8 million stolen during a security breach after identifying the individual behind the exploit and giving the attacker 48 hours to return the funds.

NEAR Intents general manager Alex Shevchenko announced the full recovery on Friday, saying the stolen assets had been returned in their entirety. He also urged security researchers and potential attackers to use bug bounty programs rather than disrupting live services.

The recovery ends the immediate financial impact of the incident, although the breach has raised further questions about the security of cross-chain deposit and withdrawal infrastructure.

Exploiter Returns Entire Amount

NEAR Intents said on Friday that it had identified the individual responsible for the breach and provided a 48-hour window for the funds to be returned under a responsible-disclosure process.

The full amount was subsequently sent back to NEAR Intents.

Shevchenko confirmed that the approximately $3.8 million had been returned in full and said the investigation was being stopped following the recovery.

The return means affected users can be compensated without the protocol absorbing the entire loss, consistent with NEAR Intents’ earlier commitment to make users whole.

Vulnerability Involved Omni Infrastructure

NEAR Intents paused its services after detecting what it described as a bug involving the interaction between its Omni deposit and withdrawal infrastructure and its smart contract.

A preliminary investigation determined that approximately $3.8 million in user funds had been stolen.

The incident did not result in a permanent loss of those funds, but the temporary compromise prompted the platform to suspend affected services while the vulnerability was investigated.

Stolen Funds Moved Across Networks

Blockchain investigator ZachXBT previously reported that funds associated with the incident were transferred to the KuCoin exchange and subsequently bridged to the Bitcoin network.

The cross-chain movement illustrates the challenges faced by protocols operating infrastructure that connects assets across multiple blockchain networks.

NEAR Intents’ ability to identify the exploiter and establish a direct recovery process ultimately resulted in the full return of the funds.

NEAR Calls for Responsible Disclosure

Following the recovery, Shevchenko encouraged researchers and security specialists to use bug bounty programs rather than exploiting vulnerabilities in production systems.

The incident highlights the distinction between responsible vulnerability disclosure and attacks that directly expose user funds. For cross-chain protocols, where multiple smart contracts and infrastructure components interact, vulnerabilities can potentially affect assets across several networks.

The full recovery also provides NEAR Intents with an opportunity to address the underlying infrastructure weakness without the additional pressure of permanently lost user funds.

Outlook

NEAR Intents’ recovery of the full $3.8 million significantly limits the financial consequences of the breach, but the incident underscores the security challenges associated with cross-chain deposit and withdrawal systems.

The immediate investigation has been halted following the return of the funds, while the broader focus will likely shift toward strengthening the affected infrastructure and preventing similar vulnerabilities from being exploited again. The episode also reinforces the importance of responsible disclosure and security testing for protocols handling substantial user balances.

 

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | China Flags Crypto Espionage Risks as Singapore’s Crypto Activity Surges 55%

    Key Takeaways China’s Ministry of State Security has warned that cryptocurrencies can facilitate espionage, money laundering and cyberattacks, emphasizing that public blockchain transactions...

    SKN | Ethereum zkAPI Launches on Mainnet, Bringing Privacy-Preserving Payments to AI and APIs

    Key Takeaways Ethereum’s zkAPI is live on mainnet, allowing users to pay for AI services and other metered APIs without directly linking their...

    Related Articles

    SKN | Zano Exploiter Created 36.9M Unauthorized ZANO Before Blockchain Rollback

    Key Points The attacker exploited Zano’s Gateway Address vulnerability twice, creating approximately...

    SKN | Core Lightning Warns Attackers Are Targeting Unpatched Bitcoin Nodes

    Key Points Core Lightning urged operators running version 26.06.7 or earlier to...

    SKN | Bitget Says $388M Hack Exploited Third-Party Security Vulnerability

    Key Points: Bitget CEO Gracy Chen said the exchange’s $388 million exploit...

    SKN | Sequans Exits Bitcoin Treasury Strategy After Selling Remaining 314 BTC

    Key Points Sequans Communications sold its remaining 314 BTC, completing its exit...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY