NEAR Intents Issues Ultimatum to Attacker After $3.8M Exploit
TREE NEWS reports: NEAR Intents has confirmed the identity of the hacker behind a security breach that drained approximately $3.8 million in user funds, the protocol’s general manager. The team has issued a 48-hour ultimatum demanding the return of stolen assets through a “responsible disclosure” process.
The exploit stemmed from a vulnerability in the interaction between Omni’s deposit and withdrawal infrastructure and NEAR Intents’ smart contracts, prompting the protocol to pause services while investigators traced the flow of funds.
On-Chain Trail Leads to KuCoin and Bitcoin
Blockchain sleuth ZachXBT reported that the stolen funds were subsequently moved to KuCoin and cross-chain swapped into Bitcoin — a common laundering pattern designed to break the transaction trail and obscure the origin of the assets. The conversion into BTC complicates recovery efforts, as Bitcoin’s UTXO model and lack of native smart contract functionality make on-chain clawbacks significantly harder than on Ethereum-compatible networks.
Full Compensation Promised to Affected Users
NEAR Intents has committed to fully reimbursing affected users, a move that protects its reputation but raises questions about the long-term sustainability of such guarantees for a protocol still building its market position. The decision mirrors a broader industry trend in which DeFi projects absorb losses to preserve user trust — a strategy that can be effective in bull markets but becomes increasingly difficult to maintain as exploits grow more frequent and costly.
Industry Implications: Cross-Chain Bridges Remain the Weakest Link
This incident underscores a persistent vulnerability in the DeFi ecosystem: cross-chain infrastructure. Bridges and intent-based settlement layers have become prime targets because they concentrate liquidity and often rely on complex, multi-contract interactions that expand the attack surface.
- Security audits are not enough: Even audited contracts can harbor interaction-level vulnerabilities between third-party infrastructure and core protocol logic.
- Identity attribution as leverage: Confirming a hacker’s identity gives protocols a negotiation tool, but it rarely guarantees recovery — especially when funds have already been swapped into Bitcoin.
- Exchange cooperation is critical: KuCoin’s response will be closely watched. If the exchange freezes related accounts, it could set a precedent for faster intervention in future exploits.
Forward Outlook
NEAR Intents’ handling of this breach will serve as a case study for how intent-based architectures manage security crises. If the attacker ignores the 48-hour deadline, the protocol may escalate to law enforcement and on-chain tracking, though the Bitcoin conversion suggests the hacker is already preparing for a prolonged standoff. For the broader DeFi sector, the incident reinforces that cross-chain composability — however innovative — remains the industry’s most dangerous frontier.




