NEAR Intents says it’s identified the hacker, gives 48-hour ultimatum
NEAR Intents said it has identified the person behind a security breach that allowed the theft of $3.8 million in user funds and gave that individual 48 hours to return the assets under "responsible disclosure." The protocol paused services after detecting a bug in the Omni deposit-and-withdrawal interaction with the NEAR Intents smart contract and said it will fully compensate affected users.

Why It Matters
A $3.8 million loss and a public identification of a suspected attacker are material events for a crypto protocol's security posture and user trust. How the situation is resolved — whether funds are returned and users are made whole — could affect NEAR Intents' reputation and broader discussions about protocol security and disclosure practices.
Key Facts
- Amount stolen: $3.8 million
- Timeframe of theft announcement: Thursday (protocol paused services)
- Public ultimatum: 48 hours to return funds under 'responsible disclosure'
- Person making the statement: Alex Shevchenko, NEAR Intents general manager
- Bug identified: Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract
NEAR Intents said on Friday it has identified the individual it believes is responsible for a security breach that resulted in the loss of $3.8 million in user funds. General manager Alex Shevchenko posted on X that the team has identified the actor and shared three wallet addresses intended to receive Bitcoin, BNB and Solana, framing a 48-hour deadline for a return of funds under a "responsible disclosure" process.
The protocol paused services on Thursday after detecting what it described as a bug in the interaction between the Omni deposit-and-withdrawal infrastructure and the NEAR Intents smart contract. NEAR Intents' preliminary investigation concluded that $3.8 million was taken and the firm pledged to compensate affected users in full.
Blockchain investigator ZachXBT reported that proceeds from the incident were moved to the KuCoin exchange and then bridged into Bitcoin. NEAR Intents' public message gives the suspected attacker a final window to return the assets before the protocol says the responsible disclosure option will close.
The incident adds to a series of recent security events involving protocols assisting or interacting with other platforms. NEAR Intents did not provide further technical detail in the post about the exploit vector beyond the stated Omni interaction, nor did it outline the specific steps for compensating users beyond the pledge to make them whole.
Keep Reading

SEC moves to clear custody hurdle for advisers offering crypto

Ethereum’s zkAPI brings privacy-preserving API payments to mainnet

Core Lightning warns attackers are targeting unpatched nodes
