NEAR Intents exploit results in $3.8M theft; platform identifies hacker and issues 48-hour ultimatum for fund return while restoring services.
Security & Exploits ·
NEAR Intents GM Alex Shevchenko identified an attacker who exploited a bug in the platform's deposit and withdrawal infrastructure to steal $3.8 million and issued a 48-hour deadline for the funds to be returned, warning that the window for responsible disclosure would then close. The vulnerability, isolated to USDT on the Binance Smart Chain, was patched within an hour and most services were restored, though some blockchain networks remained temporarily offline for additional fixes. NEAR Intents plans to fully reimburse affected users and is working with law enforcement and security partners to recover the assets, while the core NEAR blockchain and its token were unaffected by the incident.