NEAR Intents has given the attacker behind its Oct. 1 exploit 48 hours to return the stolen funds, with Shevchenko publicly claiming the hacker has been identified. The protocol says all losses will be fully compensated and law enforcement has been notified, but the wallet addresses he posted showed almost no activity when checked on-chain.
NEAR Intents attacker receives 48-hour warning
Shevchenko’s public message gave the alleged attacker two days to return the stolen assets under a responsible-disclosure framework. He did not announce a separate bounty alongside the deadline, although NEAR Intents operates two security programs whose maximum rewards reach $300,000.
“We have identified you, sir,” Shevchenko wrote on X at 8:18 p.m. ET on Oct. 1. He then listed addresses associated with Bitcoin, BNB Chain and Ethereum, as well as Solana.
“You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes,” Shevchenko added.
The message did not name the individual allegedly responsible for the exploit. NEAR Intents also has not publicly released the exploit transactions or provided a token-by-token accounting of the preliminary loss.
The addresses highlighted by Shevchenko showed little evidence of holding the stolen assets when blockchain data was checked at 1:15 a.m. UTC on Oct. 2. The Bitcoin address had no recorded transaction history, according to Blockstream data.
The address identified for BNB Chain and Ethereum contained no ETH, BNB, USDT or USDC on either network and had not sent a transaction. On Solana, the listed address received 0.005 SOL at 12:04 a.m. UTC on Oct. 2, about 13 minutes before Shevchenko’s post. It subsequently sent 0.001 SOL and retained 0.004 SOL, with no token accounts recorded.
NEAR Intents security programs offer up to $300,000
The deadline comes as NEAR Intents points to its existing security-disclosure framework. The protocol operates two bug bounty programs through HackenProof, with both programs covering areas relevant to the reported vulnerability.
Its bridges program includes the Omni Bridge contract and NEAR’s multi-party computation network. Critical findings under that program can qualify for rewards between $10,000 and $300,000.
The smart-contracts program covers the near/intents repository and offers between $100,000 and $300,000 for qualifying findings. Both programs limit high- and critical-severity rewards to 10% of the funds practically affected by a vulnerability.
Researchers are also instructed to “perform testing on a private testnet wherever possible.”
According to the incident explanation supplied by NEAR Intents, the vulnerability involved the interaction between its Omni deposit and withdrawal infrastructure and its smart contract. That places the affected code within the scope of both security programs.
The existence of the programs provides context for Shevchenko’s appeal to responsible disclosure, although the Oct. 1 message did not specify that the attacker would receive a particular bounty if the funds were returned.
NEAR Intents had recently detailed Bitget recovery efforts
The latest incident came only four days after Shevchenko published a report concerning NEAR Intents’ handling of funds associated with the Bitget breach.
Bitget has put the value of that breach at $387.5 million. In his Sept. 28 report, Shevchenko said the protocol’s SHIELD risk layer detected more than $50 million in attempted laundering flows connected to the incident.
According to his account, approximately $166,000 passed through the system, while another $503,000 was frozen during execution. Shevchenko cautioned that the figures were indicative and rounded, with an estimated margin of up to 10% from the actual values.
He also said NEAR Intents would waive its claim to the recovery bounty announced by Bitget, allowing the exchange to potentially recover a larger share of the affected funds.
“NEAR Intents is not a place for laundering stolen assets,” Shevchenko wrote.
The statement highlights the protocol’s stated efforts to monitor suspicious transactions and cooperate with broader efforts to trace potentially illicit crypto flows. Those efforts now form part of the response to the separate Oct. 1 exploit.
NEAR Intents restores services as NEAR token falls
NEAR Intents temporarily halted its services following the exploit and said affected losses would be compensated in full. Shevchenko later cited a post from near.com stating that the product had returned online 57 minutes after the interruption.
The protocol had previously indicated that deposits and withdrawals across 11 networks would remain disabled for approximately another 12 hours while security measures were implemented. That period had elapsed by the time of the supplied report.
Market data also reflected pressure on the NEAR token following the incident. NEAR was down 8.7% over 24 hours at 1:19 a.m. UTC on Oct. 2, according to CoinGecko data cited in the report. Despite the short-term decline, the token remained up 5.1% over seven days and ranked 21st by market capitalization at that point.
Data from DefiLlama showed that total value locked in NEAR Intents stood at approximately $222.3 million, compared with $248.1 million at the beginning of Oct. 1. The protocol had processed roughly $4.7 billion in swap volume during the preceding 30 days.
The protocol has not yet publicly identified the attacker or released a complete accounting of the assets involved. It has, however, said that law enforcement was notified and that it is working with blockchain analytics partners to trace the movement of funds.
For now, the 48-hour deadline issued by Shevchenko places the focus on whether the allegedly stolen assets can be recovered through voluntary return or continued blockchain tracing. The addresses publicly identified by Shevchenko had not held the reported funds when the supplied blockchain data was reviewed, leaving the location and movement of the allegedly stolen assets unresolved.
The incident also leaves several details pending, including a complete exploit analysis, the exact composition of the loss and the identity of the alleged attacker. NEAR Intents said a detailed report on the incident would follow “in the following days.”
As the investigation continues, NEAR Intents remains operational, while the protocol’s security response, law-enforcement cooperation and efforts to trace the funds are expected to determine the next stage of the recovery process.