Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Near Intents Recovers $3.8 Million by Threatening to Expose the People Behind Its Own Hack

Near Intents recovers $3.8 million after naming the attacker and giving them a 48-hour ultimatum.

By mitch·2 min read
A vault returns cryptocurrency funds to their original owners after an attack.

Friday brought news that Near Intents had recovered its funds. The cross-chain swap service reported that the roughly $3.8 million taken in an exploit on Thursday had been restored in full. That recovery followed a day in which the team openly disclosed to the attacker that they knew their identity.

The 48-Hour Ultimatum

On Thursday, Shevchenko posted Bitcoin, BNB/Ethereum and Solana addresses for returning the funds and confronted the attacker directly, saying “We have identified you, sir.” He presented the return as a final opportunity for responsible disclosure, the custom of reporting a weakness to developers rather than using it, and cautioned that the window would shut after 48 hours.

Shevchenko posted an on-chain message from the attacker, which seems to be a direct response from the person behind the exploit. The reply arrived quickly. It read: “We’ve returned all the funds, we were in the wrong,”.

Advertisement

“We’ve returned all the funds, we were in the wrong.”

The note also thanked the Near team for their courteous conduct throughout the procedure and encouraged everyone else to make use of bug bounties.

What Went Wrong

Thursday saw Near Intents halt service following a flaw in how its Omni deposit and withdrawal layer worked alongside its main smart contract, which allowed an attacker to drain funds. The team promised full compensation to users and reported the incident to law enforcement. ZachXBT, a blockchain investigator, said the stolen funds were transferred to KuCoin and then moved across to Bitcoin.

Near Intents allows people to move tokens between 35 blockchains simply by stating their intent, with market makers competing to fulfill the request. The service has handled over $30 billion in swaps, per data from the platform itself.

A Turbulent Week

The attack followed a chaotic week. Two days prior, Near Intents thwarted a $50 million swap effort by the hacker tied to the roughly $387.5 million Bitget breach, which Bitget and blockchain analytics firm Elliptic have linked to North Korea. The hack also arrived days after Bitwise’s spot NEAR ETF started trading.

The Return Note

His reply came in answer to the return, a note in which he wrote “Please use bug bounties instead of disrupting the services,”.

Aftermath

Now that the money has been returned, the investigation has ended, and Near Intents has ceased its examination of the situation.

Source material: “'We Have Identified You, Sir': Near Intents Recovers $3.8 Million After 48-Hour Ultimatum,” Decrypt.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.