bitcoinvalues
DeFi

NEAR Intents says it has identified hacker, gives 48 hours to return $3.8M

NEAR Intents general manager Alex Shevchenko says the attacker behind the $3.8 million exploit has been identified and has 48 hours to return the funds via three posted wallet addresses.

NEAR Intents general manager Alex Shevchenko said the protocol has identified the attacker who drained roughly $3.8 million in user funds, and gave them 48 hours to return the money before the window closes.

“We have identified you, sir,” Shevchenko wrote on X on October 2, posting three wallet addresses, one each for Bitcoin, BNB or Ethereum, and Solana, for the funds to be sent back.

NEAR: total value locked, daily, 28 Aug 2026 to 4 Oct 2026
NEAR data

The ultimatum followed an exploit on October 1 that took about $3.8 million, mostly USDT, Tether’s dollar-pegged stablecoin, from a treasury contract on BNB Chain. NEAR Intents said the theft exploited a bug in the Omni deposit and withdrawal infrastructure’s interaction with its smart contract. The team paused services and patched the contract-side flaw within about an hour of detection.

A deadline framed as responsible disclosure

Shevchenko told the attacker they know better than most how responsible disclosure works and that this was the last window to use it, closing after 48 hours.

The protocol has pledged to compensate affected users in full and said it is working with law enforcement and blockchain analytics firms to trace the funds. Blockchain investigator ZachXBT said the stolen money was moved to the KuCoin exchange and bridged to Bitcoin. The deadline runs from the October 2 post, expiring around October 4.

Second incident in a week

The breach landed days after NEAR Intents froze more than $50 million in suspicious transactions tied to the recent Bitget hack. The underlying NEAR Protocol and its other applications were not directly affected by the incident.

The NEAR token fell between 6% and 10% after the exploit was announced. The NEAR protocol holds $357.2 million in value locked, DefiLlama data compiled by BitcoinValues shows, as of October 2. The attacker’s identity is known to the protocol but has not been publicly named.

BitcoinValues reports on crypto markets and the data behind them. Nothing here is investment advice. How we work.

More news

All news