NEAR Intents gives hacker 48-hour ultimatum after $3.8 million breach

Protocol's general manager claims the attacker has been identified and demands return of funds

By LineZotpaper
Published
Read Time2 min
NEAR Intents, a service built on the NEAR blockchain, has issued a 48-hour ultimatum to an individual it says stole $3.8 million in user funds, warning that the window for a responsible disclosure resolution is closing.

The NEAR Intents protocol suffered a security breach on Thursday, resulting in the loss of $3.8 million in user funds. On Friday, the project's general manager, Alex Shevchenko, publicly claimed that the attacker has been identified.

"We have identified you, sir," Shevchenko wrote in a post on X, sharing three wallet addresses for Bitcoin, BNB and Solana where he said the funds could be returned. "You know better than most how responsible disclosure works. This is the last window to use it. After 48 hours, that window closes."

Shevchenko did not specify what consequences the attacker would face if the funds are not returned within the deadline. The project has not disclosed how the attack was carried out or the extent of user accounts affected beyond the total loss figure.

NEAR Intents is a protocol that facilitates cross-chain transactions on the NEAR blockchain. The incident adds to a pattern of security exploits affecting decentralized finance platforms, though the project appears to be attempting a direct resolution rather than pursuing legal or law enforcement channels immediately.

§

Analysis

Why This Matters

  • Affected users may face permanent loss of funds if the hacker does not comply with the ultimatum.
  • The incident highlights ongoing security vulnerabilities in blockchain protocols, particularly those handling cross-chain transactions.
  • The outcome could set a precedent for how projects handle on-chain thefts, especially when the attacker's identity is allegedly known.

Background

NEAR Intents is a protocol on the NEAR blockchain that enables intent-based, cross-chain operations. As with many decentralized finance projects, it holds user funds in smart contracts, making it a target for hackers. The $3.8 million stolen represents a significant portion of the protocol's total value locked, though exact figures are not confirmed. The project's response, offering a private ultimatum rather than immediately freezing contracts or engaging authorities, is an unusual approach.

Key Perspectives

NEAR Intents team: They believe they have identified the hacker and are giving a chance to return funds under responsible disclosure principles, potentially avoiding legal complications. Security critics: Some may question whether the claim of identification is verifiable or if the ultimatum is merely a bluff to pressure the attacker. Users of the protocol: They are left in uncertainty about the safety of their remaining funds and the timeline for a resolution.

What to Watch

  • Whether the funds are returned within the 48-hour window.
  • The project's next steps if the deadline passes, including possible legal action or on-chain countermeasures.
  • Further details about the vulnerability that allowed the breach, which could affect other NEAR-based projects.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.