
NEAR Intents identified the individual responsible for a $3.8 million security breach involving user funds and gave them 48 hours to return the assets under responsible disclosure, pausing services and pledging full compensation while blockchain investigator ZachXBT traced funds to KuCoin and Bitcoin.
AI-generated summary
NEAR Intents detected a bug in its Omni deposit and withdrawal infrastructure interaction with its smart contract, leading to a security breach resulting in the loss of $3.8 million in user funds on Thursday.
NEAR Intents said it has identified the individual behind a security breach that resulted in the loss of $3.8 million in user funds on Thursday, giving them 48 hours to return the funds under “responsible disclosure.”
“We have identified you, sir,” NEAR Intents general manager Alex Shevchenko said in an X post on Friday, as he shared three different wallet addresses to receive Bitcoin, BNB and Solana.
“You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes.”
On Thursday, NEAR Intent paused services after detecting a “bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.”
Its preliminary investigation found that $3.8 million in user funds was stolen, and it pledged to compensate affected users in full.
Blockchain investigator ZachXBT said the funds from the incident were transferred to the KuCoin exchange and bridged to Bitcoin.
AI outlook — possibilities, not facts
The individual will return the stolen funds within the 48-hour window to avoid public exposure and potential legal consequences
Possible · Within days
NEAR Intents will fully compensate affected users regardless of whether the funds are returned
Very likely · Within days

Crypto firms and users lost nearly $2.7 billion to security incidents in 2026 through September, with North Korea-linked thefts surpassing $1 billion. CertiK recorded 658 incidents, $420.4 million in recovered assets, and September alone accounted for $766.5 million in losses driven by major breaches at Bitget and Liquid Network. The concentration of losses in a few mega-hacks highlights systemic vulnerability, while physical 'wrench attacks' increased significantly in frequency and value.

OpenAI disrupted a coordinated extraction campaign aimed at copying its AI models' internal reasoning. The company attributed a core cluster of the activity to individuals associated with Chinese startup Moonshot AI.

Meta says its Muse AI agent cannot access iMessages on Mac without explicit user permission, requiring both Full Disk Access and its internal Messages connector to be enabled, countering a journalist's report that the app synced his texts despite denied access.

MetaMask is exiting approximately 17,000 Ethereum validators after a security breach diverted transaction-fee rewards. The mass exit has caused a significant spike in Ethereum's withdrawal backlog, reaching a nine-month high of over 773,000 ETH.

Ethereum validators face a crucial configuration choice ahead of the Glamsterdam upgrade on the Sepolia testnet on Oct. 6, where they must manually override default software settings to test an aggressive 200 million gas limit.

MetaMask is exiting its Ethereum validators from the Lido protocol due to an ongoing security incident affecting its infrastructure. The non-custodial move impacts thousands of validators while users' funds remain safe.