NEAR Intents announced on Friday that it has identified the individual behind a security exploit that resulted in the loss of $3.8 million in user funds earlier in the week. General Manager Alex Shevchenko publicly addressed the suspect via X, stating "We have identified you, sir," and provided three wallet addresses to receive Bitcoin, BNB, and Solana as part of a "responsible disclosure" framework. The company gave the individual 48 hours to return the stolen assets.
The incident occurred on Thursday when NEAR Intents paused services after detecting a bug in the interaction between its Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. Preliminary investigations confirmed the theft of $3.8 million, with the company pledging full compensation to affected users. Blockchain investigator ZachXBT reported that the stolen funds were transferred to the KuCoin exchange and subsequently bridged to Bitcoin. This breach follows recent assistance provided by NEAR Intents regarding a separate Bitget security issue.
The public identification of an attacker and the imposition of a strict 48-hour ultimatum represent a significant escalation in how decentralized finance protocols handle post-exploit recovery. By leveraging social pressure through direct communication on X and providing specific cryptocurrency wallets for restitution, NEAR Intents is attempting to bypass traditional legal timelines which are often too slow for immediate asset recovery in crypto markets. This strategy relies heavily on the assumption that the attacker may be motivated by leniency or fear of exposure rather than purely financial gain, a gamble that carries reputational risk if unsuccessful.
From an operational risk perspective, the involvement of centralized exchanges like KuCoin and cross-chain bridges highlights the complex jurisdictional challenges inherent in recovering digital assets. While the protocol promises full compensation, the actual movement of funds across different blockchains and into centralized platforms creates friction for law enforcement and complicates the technical feasibility of reversing transactions. The case underscores the critical need for robust smart contract auditing, particularly concerning infrastructure interactions like those between Omni and NEAR Intents, as these integration points remain vulnerable vectors for institutional-grade exploits.


