The NEAR Intents exploit began on Thursday, when an attacker drained $3.8 million from the crypto protocol's cross-chain trading infrastructure. The service paused deposits and withdrawals the same day, and a preliminary investigation found that user funds had been taken. On Friday the story took a turn almost nobody sees in crypto hacks: the money came back, all of it. General manager Alex Shevchenko said the exploiter returned the funds in full, the investigation was over, and the team wanted future researchers to use bug bounties instead of raiding live services.
The ultimatum is what made the NEAR Intents exploit stand out. A day after the attack, Shevchenko posted that the team had identified the person behind the breach and gave them a 48-hour window to return the assets under what he called "responsible disclosure." The post included three return addresses for Bitcoin, BNB and Solana, plus a warning that the disclosure window was the last one available. According to CoinDesk, NEAR Intents said the incident was caused by a bug in how its Omni deposit and withdrawal infrastructure interacted with the Intents smart contract. The vulnerability has since been patched, and the company pledged to reimburse affected users in full even before the money returned.
How the money came back
Blockchain investigator ZachXBT traced the funds taken in the NEAR Intents exploit through a hot wallet on BNB Chain to the KuCoin exchange, where they were bridged into Bitcoin. NEAR Intents co-founder Illia Polosukhin confirmed the return on Friday, saying the exploiter sent everything back after the team identified the attacker and opened communication. NEAR Intents said it reported the incident to law enforcement and is working with security and blockchain analytics firms to trace the funds. The native NEAR token slipped about six percent over the day, though the underlying NEAR Protocol blockchain was never affected by the breach.
The platform is built to simplify cross-chain trading. Instead of asking users to pick a bridge, an exchange or a route themselves, traders specify the swap they want and independent market makers, known as solvers, compete to complete it behind the scenes. The company says it has processed more than $30 billion in volume across 35 blockchains, which makes the episode a reminder that even mature infrastructure can carry a quiet bug in one integration. That scale is also why the NEAR Intents exploit drew so much attention: it happened to a system a lot of traders rely on daily.
A rare happy ending in a brutal year
Full recoveries like the one after the NEAR Intents exploit are the exception. Just last week, the Bitget exchange suffered an exploit that drained more than $350 million in assets, and the incident list for the year includes several breaches worth hundreds of millions each, according to DefiLlama data cited by CoinDesk. Most of those stories end with frozen wallets, long investigations and users waiting for compensation that takes months. The NEAR Intents exploit stands out because it skipped that part: the compensation promise barely mattered, since the returned funds covered the losses and the reimbursement pledge now affects the company's own books rather than leaving customers out of pocket.
The mechanics of the recovery after the NEAR Intents exploit also say something about where crypto security is headed. Exchanges now cooperate with tracing, on-chain investigators publish fund routes within hours, and an identified exploiter faces a choice between returning the money quietly or being pursued publicly and through law enforcement. In this case the attacker chose the first option, and NEAR Intents chose to close its investigation rather than escalate. The outcome is pragmatic. The protocol still has to explain how the bug survived testing, and users still lived through a day of frozen funds while the team patched the contract.
For now the service is back online and the contract-side vulnerability is patched. The bigger test is whether the industry's security posture improves before the next nine-figure exploit, because the year has shown that attackers only need one overlooked interaction between two systems to walk away with millions. Most of them do not give it back. Read the original reporting at CoinDesk and Cointelegraph.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.