Near Intents Recovers $3.8 Million After Security Incident
UpGatePositiveSecurity & hacks

Near Intents Recovers $3.8 Million After Security Incident

Reading time: 2 min

Near Intents has recovered approximately $3.8 million in cryptocurrency following a security incident that disrupted its services earlier this week. The cross-chain swap service announced that the full amount was returned within a 48-hour period.

Incident and Service Disruption
The incident occurred on Thursday, stemming from a bug in Near Intents’ Omni deposit and withdrawal layer that interacted with its main smart contract. This vulnerability allowed an unauthorized party to drain funds, prompting Near Intents to halt its operations.

Direct Response and Fund Recovery
In response, the Near Intents team publicly stated they identified the party responsible and issued a 48-hour ultimatum for the return of the funds, threatening further action. The funds were returned in full on Friday, leading Near Intents to cease its investigation. Near Intents has stated that it reported the incident to law enforcement.

Attacker’s Message and Context
An on-chain message, shared by Near Intents CEO Alex Shevchenko on X, indicated that the individual responsible expressed remorse, stating, “We’ve returned all the funds, we were in the wrong.” The message also included a plea for the use of bug bounties instead of disrupting services.

Blockchain sleuth ZachXBT reported that the funds were initially sent to KuCoin and subsequently bridged to Bitcoin. This incident follows a turbulent week for Near Intents, which also blocked a swap attempt valued at $50 million by a known attacker and saw the Bitwise spot NEAR ETF begin trading days after the incident. Near Intents has processed over $30 billion in swaps across 35 blockchains.

Remaining Uncertainties
While the incident was resolved quickly, uncertainties remain regarding the specific technical details of the bug and the precise methods of fund recovery beyond the ultimatum and the attacker’s on-chain communication. The identity of the attacker also remains unconfirmed by third parties.

Near Intents has pledged to compensate users in full for any losses incurred during the service disruption.

Why This Matters

This update details a security incident where a bug in Near Intents’ Omni deposit and withdrawal layer interacting with its main smart contract allowed an unauthorized party to siphon approximately $3.8 million. The specific bug that was associated with the incident.

Broader Context

Near Intents is a cross-chain swap service.

Tags:UpGatePositiveSecurity & hacks
Copied