NEAR Intents Recovers $3.8 Million After Hackers Return Stolen Crypto Funds
NEAR Intents suffered a $3.8 million cyberattack, but the CEO identified the attacker, leading to a full refund within 48 hours. Meanwhile, a new crypto ETF launched and NEAR prices recovered.
On October 1, NEAR Intents, a cross-chain bridge platform, suffered a cyberattack resulting in the theft of approximately $3.8 million. According to the project, the failure stemmed from a vulnerability in how the Omni system, which handles deposits and withdrawals, interacted with the service's smart contract. Most of the funds withdrawn were USDT, and the activity was limited to the BNB Chain network. After detecting the unusual activity, the service was temporarily suspended and the vulnerability was fixed.
Then came the twist. Within about 24 hours, Alex Shevchenko, CEO of NEAR Intents, announced that the team had managed to identify the person behind the system access and gave them a 48-hour window to return the funds. Dedicated addresses for returning the money were published, and the move succeeded: according to reports, the full amount was returned and the investigation was dropped. However, independent reports noted that a full breakdown of the return by individual asset was not published.
The project manager used the incident to send a message to the cybersecurity community: instead of exploiting vulnerabilities and harming services, security researchers should report them through Bug Bounty programs, pathways where companies offer rewards to those who identify security weaknesses and report them responsibly. Illia Polosukhin, co-founder of NEAR Protocol, also urged researchers to use these programs.
The incident comes at an interesting time for NEAR. On September 29, the first-of-its-kind NEAR crypto ETF by Bitwise was launched in the US under the ticker NRR. Meanwhile, the NEAR price recovered following the attack, reaching approximately $5.23 on October 6, an increase of 7.8% in 24 hours and 14.4% in a week, according to CoinGecko data.
The incident concludes with an unusual outcome in the crypto market: $3.8 million was stolen, the attacker was identified, and the funds were returned within 48 hours. The question now remains what will happen next time, and whether other attackers will also prefer to return the money or if this case is an anomaly.