NEAR Intents Exploit Exposes Cross-Chain Risks After $3.8M Theft

Add as a preferred source on Google

NEAR Intents has identified the suspected individual behind its $3.8 million exploit and issued a 48-hour deadline for returning funds. Bitquery traced most of the stolen assets across multiple blockchain networks, while the protocol works to restore services and fully compensate affected users.

The NEAR Intents Exploit has entered a new phase after the protocol said it identified the individual behind the $3.8 million security breach. On Friday, Oct. 2, General Manager Alex Shevchenko gave the suspected attacker 48 hours to return the stolen funds, while the protocol continues its recovery efforts.

Shevchenko said NEAR Intents had identified the person responsible and published separate wallet addresses for returning Bitcoin, BNB, and Solana. The protocol is offering a final responsible-disclosure window before the deadline expires. NEAR Intents has also pledged to fully reimburse users affected by the incident.

Also Read | AAVE Whale Activity Puts AAVE Price in Focus as Momentum Builds

NEAR Intents Exploit Triggers 48-Hour Deadline

The 48-hour ultimatum represents an important step in the handling of the NEAR Intents exploit. According to Shevchenko, the attacker still had the chance to refund the stolen funds via the published addresses. The protocol didn’t reveal the identity of the person responsible for the attack, and there were no reports of the return of any of the stolen funds at the time of writing.

The exploit was first reported on Thursday following the discovery of the vulnerability in the NEAR Intents Omni deposit and withdrawal mechanism and NEAR Intents smart contract. It was noted that the smart contract vulnerability had already been fixed while other issues needed to be sorted out before full resumption of services.

Blockchain investigator ZachXBT previously reported that the stolen assets moved through KuCoin before being bridged into Bitcoin. That tracking provided an early view of the fund movement after the exploit, while the NEAR Intents exploit continued working with analytics firms and authorities to trace the assets.

Bitquery Tracks $3.87M Across Multiple Chains

Furthermore, separate on-chain research carried out by Bitquery offers some more information regarding the stolen funds’ movement. The blockchain intelligence company claims an attacker withdrew about $3.865 million in USDT from the BNB Chain Vault through five major withdrawals within six hours, following two preliminary test transactions. Bitquery believes that they can track around 99% of those funds.

According to the Bitquery research, 34.69 BTC (which is about 76% of the stolen funds) was kept in four different Bitcoin wallets by Oct. 1. About $802,000 reached the KuCoin exchange via two different channels. There was also about $822,000 worth of stolen money that passed through the NEAR Intents exploit during the theft itself.

Share of the stolen USDT 
Source: Bitquery

The fund movements began with USDT being converted into BNB and distributed across multiple newly created wallets. Then these funds moved via various cross-chain exchanges. According to Bitquery, three Chainflip swaps were refused before the attacker used the THORChain exchange. A smaller part was also converted into Monero-related cryptocurrency using the Hyperliquid exchange.

NEAR Intents Exploit Raises Infrastructure Security Concerns

NEAR Intents Exploit sheds light on the vulnerabilities inherent in systems that orchestrate transactions through multiple blockchain platforms. Through NEAR Intents, users can define the tokens they wish to exchange while the underlying technology manages the transaction execution and route.

This particular attack did not breach the security of the NEAR Protocol blockchain. However, the revealed vulnerability is linked to the infrastructure used for deposits and withdrawals on NEAR Intents. The importance of highlighting the difference stems from the fact that while the compromised system was infrastructure running across multiple blockchain networks, the NEAR Protocol blockchain did not suffer any vulnerabilities.

Additionally, this breach happened just days after NEAR Intents had provided help in handling the Bitget security breach. Prior to this, the protocol mentioned that it had blocked about $50 million worth of funds related to this security breach and frozen more than $500,000.

NEAR Price Falls After Security Breach

Additionally, the NEAR Intents Exploit took place against the backdrop of pressure on the NEAR token. Although the value of NEAR decreased due to news of the exploit, the security vulnerability was only related to the infrastructure of NEAR Intents and not to NEAR Protocol itself.

For now, the major concerns for affected users are getting compensated and restoring deposits and withdrawals in blocked networks. The organization promises to compensate everyone fully but still hasn’t set any dates for the process of compensations.

Further steps will be decided based on the outcome of returning funds by the potential attacker within 48 hours and the total amount of funds investigators will be able to track down and return. Also, a post-mortem report from NEAR Intents is due to be released soon, which will give more insight into the process of discovering the vulnerability and preventing future exploits.

Thus, NEAR Intents Exploit remains an ongoing case of security investigations, in which the protocol tries to not only return the funds but also repair its infrastructure. The newly set deadline adds a new timeframe target, while on-chain investigations help track the majority of stolen funds.

Also Read | Sui Price Stays at $1.14 as the OpenAssets Collaboration Delivers a New Catalyst

Bena Ilyas

Bena Ilyas

Bena Ilyas is a Global News Correspondent and Market Analyst at Tronweekly with over four years of experience covering global cryptocurrency, blockchain, and Web3 developments. She has written 1,000+ articles for leading crypto news platforms, reporting on Bitcoin, Ethereum, altcoins, DeFi, and global crypto regulation, alongside Web3 trends, Layer 2 ecosystems, and AI-driven crypto use cases. Her work is based on verified sources and fact-based reporting for global market participants.

Articles: 2019