crypto for all
Join
A
A

NEAR Intents Fixes Flaw After $3.8M Crypto Hack

8h05 ▪ 5 min read ▪ by Luc Jose A.
Getting informed ▪ Cybersecurity
Summarize this article with:

NEAR Intents suffered a hack estimated at 3.8 million dollars on October 1st, caused by a bug between its smart contract and a deposit and withdrawal infrastructure. The protocol promises to fully reimburse users and now claims to have identified the attacker, granting them 48 hours to return the funds.

Inside an immense blockchain vault, a security manager bearing the NEAR symbol has just closed a gigantic armored door with satisfaction. Behind the door, a massive glowing reserve displays only M, protected by multiple locks and chains. A visual element associated with Bitget appears on part of the mechanism, serving as a reminder of the origin of the locked funds. But behind the character's back, in the right foreground, a small maintenance hatch has just been forced open. A hooded hacker silhouette quietly escapes through it carrying a glowing briefcase displaying .8M. The NEAR manager is only just turning around, his expression shifting from satisfaction to shock.

In brief

  • NEAR Intents suffered a hack estimated at 3.8 million dollars on October 1st.
  • The protocol attributes the incident to a bug between Omni and its smart contract
  • NEAR Intents promises to fully reimburse affected users.
  • The team claims to have identified the alleged attacker and gives them 48 hours to return the funds.
  • Some of the stolen assets apparently transited through KuCoin before being moved to Bitcoin.

The NEAR Intents hack in four points

NEAR Intents detected a flaw in the interaction between its smart contract and Omni, its infrastructure responsible for managing certain deposits and withdrawals. The incident resulted in the loss of 3.8 million dollars belonging to users.

The protocol suspended its services during its initial investigations. It claims to have fixed the vulnerability on the contract side to prevent it from being exploited again.

Here are the main elements communicated since the incident :

  • The provisional loss amounts to 3.8 million dollars ;
  • NEAR Intents promises to fully reimburse affected users ;
  • The contract flaw has been fixed, according to the protocol ;
  • Authorities and several blockchain analysis firms have been involved ;
  • A detailed report is expected to be published in the coming days ;
  • The protocol claims to have identified the attacker, without revealing their identity.

“We have identified who you are, sir”, declared Alex Shevchenko, CEO of NEAR Intents. He gave the alleged attacker 48 hours to return the assets as part of responsible disclosure. “After 48 hours, this possibility will disappear”, he warned.

This statement comes directly from NEAR Intents. It does not yet constitute a confirmed attribution by a judicial authority.

How was the NEAR Intents hack possible?

NEAR Intents is a cross-chain protocol that allows exchanging assets across multiple blockchains. Instead of manually executing each step, the user expresses the desired outcome, for example converting a token on Solana to bitcoins. Specialized actors then find the best path to fulfill this intent.

This model simplifies operations but multiplies interactions between contracts, networks, and external infrastructures. In this case, NEAR Intents attributes the incident to a bug in the communication between Omni and its smart contract. The flaw did not necessarily come from an isolated error in each component, but from their joint operation.

The protocol has not yet explained precisely how the hacker triggered the withdrawals nor published the announced technical audit. It also remains to be verified whether the deployed fix covers all possible variants of the attack.

The funds reportedly transited through KuCoin before Bitcoin

According to blockchain investigator ZachXBT, the stolen assets were transferred to the KuCoin platform, then converted or moved to the Bitcoin network. This passage complicates their tracking, as investigators must link operations carried out across several blockchains.

NEAR Intents claims to work with on-chain analysis specialists to trace the funds and try to recover them. Alex Shevchenko also published three addresses allowing restitution in bitcoin, BNB, or Solana.

No effective reimbursement has yet been confirmed publicly. At this stage, full loss coverage remains a commitment from the protocol, not an operation already completed.

The NEAR Intents hack follows that of Bitget

The incident occurs a few days after the Bitget hack, which caused about 387.5 million dollars in losses. Before itself being attacked, NEAR Intents claimed to have blocked more than 50 million dollars of transfers associated with the pirate’s Bitget addresses.

Its SHIELD system reportedly detected these operations and froze 503000 dollars during their execution. About 166000 dollars of suspicious funds nonetheless passed through the protocol. NEAR Intents then announced it would forgo the bounty offered by Bitget so that a larger sum could be returned.

This connection proves no link between the two attacks. In particular, nothing indicates attributing the NEAR Intents hack to the group suspected of targeting Bitget.

The third quarter was however particularly heavy for the sector. CertiK estimates losses related to security incidents at 1.26 billion dollars over 247 events, compared to 819.4 million dollars in the previous quarter. The month of September alone concentrates about 769 million dollars in losses. The publication of the technical report and expiration of the 48-hour ultimatum will now allow assessing the chances of recovering the 3.8 million dollars.

Maximize your Cointribune experience with our "Read to Earn" program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.



Join the program
A
A
Luc Jose A. avatar
Luc Jose A.

Diplômé de Sciences Po Toulouse et titulaire d'une certification consultant blockchain délivrée par Alyra, j'ai rejoint l'aventure Cointribune en 2019. Convaincu du potentiel de la blockchain pour transformer de nombreux secteurs de l'économie, j'ai pris l'engagement de sensibiliser et d'informer le grand public sur cet écosystème en constante évolution. Mon objectif est de permettre à chacun de mieux comprendre la blockchain et de saisir les opportunités qu'elle offre. Je m'efforce chaque jour de fournir une analyse objective de l'actualité, de décrypter les tendances du marché, de relayer les dernières innovations technologiques et de mettre en perspective les enjeux économiques et sociétaux de cette révolution en marche.

DISCLAIMER

The views, thoughts, and opinions expressed in this article belong solely to the author, and should not be taken as investment advice. Do your own research before taking any investment decisions.