Key Highlights:
- NEAR Intents has fully recovered the $3.8 million drained during a recent security exploit.
- General Manager Alex Shevchenko confirmed that the attacker returned all stolen assets following a 48-hour grace period and identification.
- The vulnerability originated from an interaction flaw between the Omni deposit and withdrawal system and the NEAR Intents smart contract.
NEAR Intents Recovers $3.8 Million Following Protocol Exploit
NEAR Intents, a cross-chain transaction infrastructure operating within the NEAR ecosystem, has announced the complete recovery of approximately $3.8 million compromised during a recent security breach. The resolution follows an intense effort by the protocol’s leadership to track down the exploit and identify the individual responsible, culminating in the complete return of the stolen assets.
According to an official statement by NEAR Intents General Manager Alex Shevchenko, the individual associated with the exploit agreed to return the funds after their identity was determined. The resolution materialized following a 48-hour grace period extended to the perpetrator by the project’s security and leadership teams, ultimately leading to the full restitution of the missing capital.
Root Cause and Response: Flaws in Omni Infrastructure
The security incident stemmed from an underlying flaw in the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. This architectural mismatch allowed the attacker to bypass standard controls and extract roughly $3.8 million across connected chains.
Upon detecting the unusual activity, platform administrators moved swiftly to temporarily suspend specific services to isolate the vulnerability and prevent further exploitation. From the outset, the NEAR Intents team assured the community that any affected users would be fully compensated, regardless of the immediate outcome of the fund recovery process.
On-Chain Tracing and Asset Laundering Efforts
During the incident, independent on-chain researcher ZachXBT traced the attacker’s transaction flow as they attempted to move the proceeds. The investigation revealed that portions of the stolen capital were routed through the KuCoin cryptocurrency exchange before being bridged and transferred to the Bitcoin network.
Despite the attacker’s attempts to obscure the trail across different blockchains and centralized platforms, on-chain tracking alongside ecosystem investigations successfully pinned down the attacker’s identity. Facing exposure, the perpetrator opted to return all the taken funds rather than risk further legal or enforcement actions.
Why This Matters
Cross-chain transaction architectures and intent-based protocols continue to face complex attack vectors due to the interactions between different smart contracts and external deposit/withdrawal pipelines. The rapid identification of the perpetrator highlights the expanding capabilities of on-chain forensics and centralized exchange coordination in tracking cross-network exploits. Furthermore, the total recovery safeguards user confidence in the NEAR ecosystem’s infrastructure without forcing the protocol to absorb a multi-million-dollar loss.
Frequently Asked Questions
How much money was involved in the NEAR Intents security incident?
The security exploit involved approximately $3.8 million, all of which has been recovered in full following negotiations with the identified attacker.
What caused the exploit on NEAR Intents?
The incident was caused by a technical vulnerability in how the Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract.
Were the stolen funds moved to other networks?
Yes. According to findings published by on-chain investigator ZachXBT, a portion of the stolen funds was transferred to KuCoin and subsequently bridged over to the Bitcoin network before being successfully returned.




