NEAR Intents Tells ₿43.8 Hacker: Return the Funds in 48 Hours

Neon blockchain network illustrating the NEAR Intents exploit, Bitcoin fund movement and a 48-hour return deadline

NEAR Intents says it knows who drained roughly ₿43.8 ($3.8 million) from its cross-chain infrastructure—and it just put the alleged attacker on a 48-hour clock.

The figure is approximately ₿43.8 using a Bitcoin price near $86,700 and will move with BTC. The underlying exploit hit NEAR Intents’ Omni deposit-and-withdrawal infrastructure on October 1, forcing the service to pause operations while its team patched the contract-side vulnerability.

Then the story took a more unusual turn. NEAR Intents general manager Alex Shevchenko posted a direct message to the alleged attacker: “We have identified you, sir.” He supplied Bitcoin, BNB/Ethereum and Solana return addresses and said the responsible-disclosure window closes after 48 hours.

Alex Shevchenko gives the alleged NEAR Intents exploiter 48 hours to return the stolen assets.

What was actually hacked?

NEAR Intents is designed to let users specify the outcome they want—such as exchanging one asset on one network for another asset elsewhere—while competing solvers handle the route. That abstraction makes cross-chain movement easier for users, but it also creates infrastructure that must safely coordinate deposits, withdrawals and smart-contract state across multiple networks.

According to reporting on the initial incident, NEAR Intents attributed the loss to a bug in the interaction between its Omni deposit/withdrawal infrastructure and the NEAR Intents smart contract. The team said the contract-side flaw was patched and promised affected users full compensation.

The exploit follows an already brutal stretch for crypto security. BitcoinVersus recently tracked how funds from the Bitget hack moved into Zcash’s shielded pool, demonstrating how quickly stolen assets can jump between exchanges, chains and privacy systems once an attacker begins laundering them.

The stolen funds moved toward Bitcoin

Blockchain investigator ZachXBT said funds from the NEAR Intents incident moved through KuCoin and were bridged into Bitcoin. That does not imply any compromise of Bitcoin itself; it means the attacker allegedly converted proceeds into BTC after exploiting infrastructure elsewhere.

That distinction matters. A bridge, hot wallet or application contract can fail without the underlying destination blockchain being hacked. The same separation was important in BitcoinVersus’ earlier coverage of the ₿-denominated theft of a large Bitcoin fortune: possession-layer failures and protocol-layer failures are not the same event.

Market Mates discusses the NEAR Intents exploit alongside the day’s Bitcoin and altcoin market action.

“We have identified you, sir”

Shevchenko’s ultimatum is the most interesting part of the developing story because it implies the team believes the exploit is no longer anonymous. But the public post does not name the person or disclose the evidence behind that identification.

Reporting on the ultimatum confirms that the October 2 post provides three return destinations and frames the deadline as the final opportunity to use responsible disclosure. Until NEAR Intents publishes its promised post-mortem—or funds visibly return—the identification claim remains Shevchenko’s claim rather than independently demonstrated attribution.

Why 48 hours can matter onchain

Crypto theft creates a strange inversion of conventional crime. The public may be able to watch the money move in real time even when nobody knows who controls the keys. Exchanges, stablecoin issuers, analytics companies and bridges can sometimes freeze or flag assets, while conversion into permissionless assets changes the recovery problem again.

That makes the next two days measurable. Investigators can watch whether the listed return addresses receive funds, whether the stolen assets move again and whether exchanges identify accounts connected to the flow.

It also reinforces why operational security matters beyond the consensus layer. Our AxeOS failover guide deals with a different part of crypto infrastructure, but the same engineering principle applies: resilient systems assume components will fail and design explicit recovery paths before they do.

The deadline is now part of the blockchain record

The attacker now has public return addresses and a public deadline. NEAR Intents has promised compensation. The contract-side bug has been patched. What has not yet been demonstrated is whether the team’s attribution will produce recovery.

That makes this less a story about a finished hack than a live recovery attempt. The exploit already happened. The next event is visible onchain: either some of the approximately ₿43.8 ($3.8 million) comes back, or the 48-hour clock runs out.

BitcoinVersus.Tech

Advertisement

BitcoinVersus.Tech advertisement.

Editor’s Note

The Bitcoin equivalent in this story is approximate because BTC’s market price changes continuously. Shevchenko’s claim that the attacker has been identified is attributed to him; the alleged attacker has not been publicly named and the identification evidence has not yet been released.

Support independent BitcoinVersus.Tech reporting with Bitcoin donations at: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This media platform reports on financial subjects purely for informational purposes.

Leave a comment