Altcoins

NEAR Intents Hacker Returns All $3.8M in Stolen Funds

The exploit hit two days after Bitwise launched its NEAR ETF, and the token fell nearly 9% on the news.

⏱ 2 min read Altcoins
Quick Summary
  • The flaw was patched within about an hour, but deposits on 11 networks stayed paused for 12 more
  • NEAR Intents had processed more than $30bn in swaps across 35 networks before the exploit
  • No bounty was disclosed, and the GM told future attackers to use bug bounties instead

The $3.8 million taken from NEAR Intents has been sent back in full.

The exploiter returned the funds on Friday with a short message attached: “We’ve returned all the funds, we were in the wrong.” NEAR Intents general manager Alex Shevchenko confirmed the return and said the team was stopping its investigation.

What happened

The attacker found a flaw in the layer that moves funds in and out of NEAR Intents, specifically in how that layer communicated with the main contract holding user funds.

The team patched the contract vulnerability and restored core services within about an hour. Deposits and withdrawals on 11 networks, including BNB Chain, Polygon and Optimism, stayed offline for roughly 12 more hours while the remaining fixes went in. NEAR Intents committed to compensating users in full and reported the incident to law enforcement before the funds came back.

Why it mattered

NEAR Intents is not a side project. It had processed more than $30 billion in swaps across 35 networks before the exploit, which makes it one of the main pieces of infrastructure behind the NEAR ecosystem’s growth story.

The timing was also poor. Bitwise’s spot NEAR ETF had launched two days earlier. NEAR fell nearly 9% to $4.86 after the hack was disclosed, and the new ETF’s shares dropped more than 7%.

The return does not close every question

No bounty has been disclosed, and the team has not said how the funds were recovered beyond its public statements. Shevchenko’s message to future attackers was blunt: “Please use bug bounties instead of disrupting the services.”

The full incident report the team promised has not yet been published. Until it is, the exact nature of the flaw, and whether similar weaknesses exist elsewhere in the system, remains unexplained.

The token has not regained its losses. NEAR was trading around $4.62 on Friday, down about 5% on the day.

⚖️ Our Verdict ⚖️ Watch and Wait

Users lost nothing and the money is back, which is close to the best outcome an exploit can have. But the contract flaw was real, the full incident report is still to come, and the token has not recovered its losses.