Summary

  • Near Intents has successfully retrieved the entire $3.8 million that was stolen during an exploit on Thursday, as confirmed by general manager Alex Shevchenko on Friday, signaling the end of their investigation.
  • The recovery was prompted by Shevchenko's public statement to the hacker declaring, "We have identified you, sir," and granting them a 48-hour deadline to return the stolen assets.
  • An on-chain communication, apparently from the perpetrator, acknowledged wrongdoing, urging others to utilize bug bounty programs.

Near Intents has regained its funds.

The cross-chain token swapping service announced on Friday that it has fully recovered about $3.8 million taken in an exploit that occurred on Thursday. This resolution came just a day after the team publicly confronted the attacker, indicating they knew their identity.

Myriad: Predict Ethereum's next move! Click to share your opinion.

Alex Shevchenko, general manager of Near Intents, announced on X, "The funds from the $3.8M NEAR Intents hack were sent back in full. We are stopping the investigation now."

The recovery process was swift. On Thursday, Shevchenko shared Bitcoin, BNB/Ethereum, and Solana addresses for returning the funds while directly addressing the hacker with, "We have identified you, sir."

He framed this return as a final opportunity for responsible disclosure, which is the practice of notifying developers about vulnerabilities instead of exploiting them, warning that the chance would expire after 48 hours.

An on-chain message associated with the transaction, which Shevchenko shared and that seems to be from the hacker, expressed remorse: "We've returned all the funds, we were in the wrong." The message also expressed gratitude to the Near team for their professionalism throughout the process and encouraged others to adopt bug bounty practices.

Near Intents had temporarily suspended its services on Thursday after discovering a vulnerability in its Omni deposit and withdrawal system that allowed the attacker to drain funds. The team had committed to fully compensating users and notified law enforcement about the incident. Blockchain investigator ZachXBT noted that the stolen assets were transferred to KuCoin and converted to Bitcoin.

Near Intents facilitates token swaps across 35 different blockchains, allowing users to specify their desired tokens while market makers compete to fulfill their orders. The platform has handled over $30 billion in swaps, based on its own data.

This incident capped off a tumultuous week for the platform. Just two days prior, Near Intents blocked a $50 million swap attempt by the hacker linked to the approximately $387.5 million breach at Bitget, which has been attributed to North Korean actors by Bitget and blockchain analytics firm Elliptic. This exploit also followed closely on the heels of the launch of Bitwise's spot NEAR ETF.

"Please use bug bounties instead of disrupting the services," Shevchenko urged.

Daily Debrief Newsletter

Stay updated with the latest news, original features, podcasts, videos, and more by subscribing to our daily newsletter.