en
Back to the list

Shevchenko Gives NEAR Intents Attacker 48 Hours

source-logo  thedefiant.io 4 h
image

Alex Shevchenko, general manager of $NEAR Intents, told the attacker who drained a preliminary $3.8 million from the cross-chain protocol that he has been identified and has 48 hours to send the money back.

“We have identified you, sir,” Shevchenko wrote on X at 8:18 p.m. ET on Oct. 1, listing a Bitcoin address, one for $BNB Chain and Ethereum, and one for Solana. “You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes.”

The post sets a deadline and names no bounty. $NEAR Intents runs two disclosure programs covering the code involved, and each pays at most $300,000.

app-logo

Know when your
coins move

Alerts, real-time prices, and market news — all in one app
4.8 based on 40K reviews in the App Store and Google Play

Three Fresh Addresses

None of the three addresses held the funds as of 1:15 a.m. UTC on Oct. 2. The Bitcoin address has never recorded a transaction, Blockstream data shows. The address given for $BNB Chain and Ethereum holds no ether, no $BNB and no USDT or USDC on either network, and has never sent a transaction.

The Solana address was funded with 0.005 $SOL at 12:04 a.m. UTC on Oct. 2, 13 minutes before the post. It sent 0.001 $SOL out five minutes later, holds 0.004 $SOL and owns no token accounts.

Shevchenko posted the message from his personal account. The $NEAR Intents account has not posted since its incident statement on Oct. 1, which said a detailed report would follow “in the following days.”

A $300,000 Ceiling

$NEAR Intents runs two bug bounty programs on HackenProof. The bridges program lists the Omni Bridge contract and $NEAR's multi-party computation network among its targets and pays $10,000 to $300,000 for a critical finding. The smart-contracts program covers the near/intents repository and pays $100,000 to $300,000. Both cap high and critical rewards at 10% of the funds a vulnerability practically affects, and both tell researchers to “perform testing on a private testnet wherever possible.”

$NEAR Intents attributed the incident to a bug in how the Omni deposit and withdrawal infrastructure interacted with its smart contract, code that sits across both programs.

Four Days Earlier

Shevchenko published a report on Sept. 28 on how $NEAR Intents handled funds from the Bitget breach, which the exchange puts at $387.5 million. He said the protocol's SHIELD risk layer detected more than $50 million in attempted laundering flows, that $166,000 passed through and that it froze $503,000 mid-execution. He described the figures as indicative and rounded, within 10% of the true values.

Shevchenko said $NEAR Intents was waiving its claim on the 5%-plus-5% recovery bounty Bitget announced, so the exchange could recover more.

“$NEAR Intents is not a place for laundering stolen assets,” he wrote.

Services Back, Token Down

$NEAR Intents halted services on Oct. 1 and said losses would be compensated in full. Shevchenko quoted a near.com post saying the product was back up 57 minutes later. The protocol had said deposits and withdrawals on 11 networks would stay off for roughly 12 more hours; that window has elapsed.

$NEAR fell 8.7% in 24 hours, CoinGecko data showed at 1:19 a.m. UTC on Oct. 2. The token is up 5.1% over seven days and ranks 21st by market value.

Total value locked in $NEAR Intents is $222.3 million, down from $248.1 million at the start of Oct. 1, DefiLlama data shows. The protocol handled $4.7 billion of swap volume over the past 30 days.

$NEAR Intents has not named the attacker, published the exploit transactions or given a token-by-token breakdown of the loss. It said it reported the incident to law enforcement and is working with analytics partners to trace the funds.

thedefiant.io