Press Enter to search · ESC to close

DeFi

NEAR Intents Identifies Hacker, Demands $3.8M Return Within 48 Hours

NEAR Intents has identified the hacker responsible for a $3.8 million exploit and issued a 48-hour deadline for the return of stolen funds. The breach involved Omni's deposit infrastructure and NEAR Intents smart contracts, with stolen assets moved to KuCoin and converted to Bitcoin. The protocol has pledged full compensation to affected users.

NEAR Intents Issues Ultimatum to Attacker After $3.8M Exploit

NEAR Intents has confirmed the identity of the hacker behind a security breach that drained approximately $3.8 million in user funds, the protocol’s general manager. The team has issued a 48-hour ultimatum demanding the return of stolen assets through a “responsible disclosure” process.

The exploit stemmed from a vulnerability in the interaction between Omni’s deposit and withdrawal infrastructure and NEAR Intents’ smart contracts, prompting the protocol to pause services while investigators traced the flow of funds.

On-Chain Trail Leads to KuCoin and Bitcoin

Blockchain sleuth ZachXBT reported that the stolen funds were subsequently moved to KuCoin and cross-chain swapped into Bitcoin — a common laundering pattern designed to break the transaction trail and obscure the origin of the assets. The conversion into BTC complicates recovery efforts, as Bitcoin’s UTXO model and lack of native smart contract functionality make on-chain clawbacks significantly harder than on Ethereum-compatible networks.

Full Compensation Promised to Affected Users

NEAR Intents has committed to fully reimbursing affected users, a move that protects its reputation but raises questions about the long-term sustainability of such guarantees for a protocol still building its market position. The decision mirrors a broader industry trend in which DeFi projects absorb losses to preserve user trust — a strategy that can be effective in bull markets but becomes increasingly difficult to maintain as exploits grow more frequent and costly.

Industry Implications: Cross-Chain Bridges Remain the Weakest Link

This incident underscores a persistent vulnerability in the DeFi ecosystem: cross-chain infrastructure. Bridges and intent-based settlement layers have become prime targets because they concentrate liquidity and often rely on complex, multi-contract interactions that expand the attack surface.

  • Security audits are not enough: Even audited contracts can harbor interaction-level vulnerabilities between third-party infrastructure and core protocol logic.
  • Identity attribution as leverage: Confirming a hacker’s identity gives protocols a negotiation tool, but it rarely guarantees recovery — especially when funds have already been swapped into Bitcoin.
  • Exchange cooperation is critical: KuCoin’s response will be closely watched. If the exchange freezes related accounts, it could set a precedent for faster intervention in future exploits.

Forward Outlook

NEAR Intents’ handling of this breach will serve as a case study for how intent-based architectures manage security crises. If the attacker ignores the 48-hour deadline, the protocol may escalate to law enforcement and on-chain tracking, though the Bitcoin conversion suggests the hacker is already preparing for a prolonged standoff. For the broader DeFi sector, the incident reinforces that cross-chain composability — however innovative — remains the industry’s most dangerous frontier.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback