Exploiter Opens Channel After $3.8M Drain
TREE NEWS reports: The attacker behind the NEAR Intents exploit has made an unexpected move: transferring 1 BNB into a designated recovery wallet along with an on-chain message stating a willingness to cooperate and requesting a Signal contact handle. General manager of NEAR Intents, the transfer originated from the same address previously linked to roughly $3.8 million in diverted funds.
Roughly an hour before the BNB transfer, the same address moved 0.295 ETH on the Ethereum network carrying an identical message. SlowMist’s chief information security officer, known as 23pds, flagged the activity, noting the attacker appears to be probing for direct negotiations.
Why This Matters for DeFi Security
On-chain messaging has become a standard tool in post-exploit negotiations. Attackers often use transaction memos to open dialogue, either to negotiate a bounty or to demonstrate that funds remain recoverable. The decision to send a small test amount — rather than returning principal — suggests a cautious, incremental approach typical of actors weighing legal exposure against the practical difficulty of laundering large sums.
- Signaling over substance: A 1 BNB transfer is a gesture, not a restitution. It establishes a channel without committing to a return of funds.
- Cross-chain behavior: Activity on both BNB Chain and Ethereum indicates the attacker is managing assets across multiple networks, complicating tracing and recovery.
- Precedent: Similar patterns have appeared in past incidents where exploiters eventually returned a portion of stolen assets in exchange for bounty payments and public assurances.
The Broader Intents Landscape
NEAR Intents sits at the intersection of cross-chain routing and intent-based execution — a fast-growing sector that lets users express desired outcomes rather than manually route transactions. That design concentrates risk in solver and settlement layers, making audits and real-time monitoring critical. The incident underscores that intent architectures, while improving user experience, introduce novel attack surfaces that are still being mapped.
What Comes Next
Whether the attacker follows through will depend on the terms offered. Recovery negotiations typically hinge on bounty size, immunity from prosecution, and the practical ability to move funds without triggering exchange compliance systems. For NEAR Intents, the priority is securing remaining contracts, publishing a transparent post-mortem, and reassuring integrators. For the wider DeFi ecosystem, the episode is a reminder that exploit response is now as much a communications exercise as a technical one — and that on-chain dialogue is increasingly the first step toward recovery.




