'We Have Identified You, Sir': Near Intents Recovers $3.8 Million After 48-Hour Ultimatum

Near Intents said the roughly $3.8 million drained in an exploit on Thursday was returned in full, a day after the team said it had identified the attacker and gave them 48 hours to return the funds.

By Decrypt Staff

2 min read

Near Intents got its money back.

The cross-chain swap service said Friday that the roughly $3.8 million drained in an exploit on Thursday has been returned in full. The return came a day after the team publicly told the attacker it knew who they were.

Myriad: Where does Ethereum go next? Click to make your prediction.

"The funds from the $3.8M NEAR Intents hack were sent back in full," Alex Shevchenko, general manager of Near Intents, wrote on X. "We are stopping the investigation."

The turnaround was fast. On Thursday, Shevchenko posted Bitcoin, BNB/Ethereum and Solana addresses for returning the funds and addressed the attacker directly: "We have identified you, sir."

He framed the return as a last chance at responsible disclosure, the practice of reporting a vulnerability to developers instead of exploiting it, and warned that the window would close after 48 hours.

An on-chain message attached to a transaction, which Shevchenko shared and which appears to come from the exploiter, struck a contrite tone. "We've returned all the funds, we were in the wrong," it read. The message also thanked the Near team for being cordial during the process and urged others to use bug bounties.

Near Intents had halted service Thursday after a bug in how its Omni deposit and withdrawal layer interacted with its main smart contract let an attacker siphon funds. The team had pledged to compensate users in full and reported the incident to law enforcement. Blockchain sleuth ZachXBT said the stolen funds were sent to KuCoin and bridged to Bitcoin.

Near Intents lets users swap tokens across 35 blockchains by stating what they want and letting market makers compete to fill the order. It has processed more than $30 billion in swaps, according to data from the service.

The exploit capped a turbulent week. Two days earlier, Near Intents blocked a $50 million swap attempt by the hacker behind the roughly $387.5 million Bitget breach, which Bitget and blockchain analytics firm Elliptic have pinned on North Korea. The hack also came days after Bitwise's spot NEAR ETF began trading.

"Please use bug bounties instead of disrupting the services," Shevchenko wrote.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News