NEAR Intents recovers entire stolen $3.8M after ultimatum to exploiter
NEAR Intents said it recovered roughly $3.8 million that was taken during a security breach after identifying the individual responsible and issuing a 48-hour ultimatum. The platform paused services during its probe and pledged to fully reimburse affected users.

Why It Matters
A full recovery of stolen funds is a notable outcome in blockchain security incidents, where asset retrieval is often difficult; the case also highlights the use of deadlines and responsible-disclosure demands as part of incident response. The episode involved cross-chain movements, with investigators saying the funds were routed through KuCoin and bridged to Bitcoin, underscoring typical evasive tactics used in exploits.
Key Facts
- Amount recovered: $3.8 million
- Timeframe given to exploiter: 48 hours
- Platform: NEAR Intents
- NEAR Intents GM: Alex Shevchenko
- Where funds were moved: Transferred to KuCoin and bridged to Bitcoin (per investigator ZachXBT)
NEAR Intents said it has recovered about $3.8 million taken in a security breach that was detected earlier in the week. The project temporarily halted services after discovering a vulnerability in the interaction between its Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract.
Cointelegraph reported that NEAR Intents identified the individual it said was behind the breach and gave that person 48 hours to return the funds under what the project described as a "responsible disclosure" process. Later on Friday, NEAR Intents general manager Alex Shevchenko announced on X that the full amount had been returned and that the investigation was being stopped.
NEAR’s preliminary probe had concluded that $3.8 million in user funds were taken, and the platform committed to compensating users affected by the incident. Blockchain investigator ZachXBT said on-chain analysis showed the stolen funds were transferred to the KuCoin exchange and then bridged into Bitcoin, a pattern often seen in attempts to obfuscate the origin of illicit transfers.
Shevchenko urged researchers to use bug-bounty channels rather than disrupting services, framing the return as the end of the incident response. NEAR Intents has not published a detailed post-mortem of the vulnerability in the excerpted reporting, and further updates may follow as the team completes its internal review and user restitution procedures.
Keep Reading

Community banks sue OCC over trust bank charters of crypto firms

Trump Is Hosting Yet Another Meme Coin Dinner: Here Are the Details

Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea
