Cross-chain protocol NEAR Intents General Manager Alex Shevchenko has publicly identified the attacker responsible for a $3.8 million exploit, issuing a strict 48-hour deadline for the return of stolen funds across Bitcoin, BNB/Ethereum, and Solana deposit addresses.
In a post on X directly addressing the perpetrator, Shevchenko stated, "We have identified you, sir," warning that the window for responsible disclosure will close permanently after the ultimatum expires.
Key Takeaways:
- Exploit Cause: A flaw in the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract caused a $3.8 million loss, isolated to USDT on BSC.
- Ultimatum Issued: Alex Shevchenko gave the attacker 48 hours to return funds to designated addresses before the team pursues full legal action.
- User Protection: NEAR Intents confirmed all affected users will be compensated in full, and the primary NEAR Protocol was unaffected.
Incident Details and Platform Response
The exploit occurred when a bug in how the Omni deposit and withdrawal infrastructure interacts with the NEAR Intents smart contract allowed the attacker to drain funds. NEAR co-founder Illia Polosukhin confirmed the breach was restricted to USDT on BSC, noting that the platform's AI security layer, SHIELD, flagged outlier behavior and triggered an immediate pause.
Engineers patched the contract vulnerability within one hour of detection, restoring NEAR Intents and near.com. However, deposit and withdrawal services across BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll, and Plasma remained paused for an additional 12 hours to complete Omni infrastructure fixes. Despite the incident, NEAR Protocol reported its network operated without disruption, as its native NEAR token was not directly involved in the breach. Following recent security breaches across DeFi platforms where hackers exploited third-party adapters, protocol teams are moving rapidly to contain smart contract vulnerabilities.
According to CoinGecko, NEAR fell over 5% in 24 hours, though it remains up 166% over the past 30 days. The platform, which processes more than $4 billion in monthly volume, confirmed that this was its first major security exploit.
AI Threats and Industry Vigilance
Polosukhin highlighted that decentralized finance is entering a new threat environment characterized by sophisticated, AI-driven attacks. He referenced recent security incidents involving major entities like Bitget, which suffered a $387 million hack on September 24, as well as infrastructure incidents affecting MetaMask on October 1 and Lido.
To strengthen defenses, NEAR Intents plans to integrate formal verification into its smart contract deployment process and expand information sharing through new SHIELD security partnerships. The incident has been reported to law enforcement while blockchain analytics firms work to track the stolen assets.
Why It Matters
This incident highlights how critical real-time monitoring and rapid incident response are as DeFi protocols scale to multi-billion-dollar transaction volumes. By using an AI security layer to detect anomalous execution and deploying a patch within one hour, NEAR Intents prevented broader systemic contagion across its multi-chain bridge network. Moving forward, the industry's shift toward formal verification and proactive AI defense will determine whether cross-chain intent frameworks can maintain institutional trust amid increasingly automated exploit tools.



