
The cross-chain swap service successfully negotiated the return of stolen funds after identifying the attacker.
AI-generated summary
Near Intents allows users to swap tokens across 35 blockchains. The service was recently targeted by an exploit involving its Omni deposit and withdrawal layer.
Near Intents got its money back.
The cross-chain swap service said Friday that the roughly $3.8 million drained in an exploit on Thursday has been returned in full. The return came a day after the team publicly told the attacker it knew who they were.
"The funds from the $3.8M NEAR Intents hack were sent back in full," Alex Shevchenko, general manager of Near Intents, wrote on X. "We are stopping the investigation."
The turnaround was fast. On Thursday, Shevchenko posted Bitcoin, BNB/Ethereum and Solana addresses for returning the funds and addressed the attacker directly: "We have identified you, sir."
He framed the return as a last chance at responsible disclosure, the practice of reporting a vulnerability to developers instead of exploiting it, and warned that the window would close after 48 hours.
An on-chain message attached to a transaction, which Shevchenko shared and which appears to come from the exploiter, struck a contrite tone. "We've returned all the funds, we were in the wrong," it read. The message also thanked the Near team for being cordial during the process and urged others to use bug bounties.
Near Intents had halted service Thursday after a bug in how its Omni deposit and withdrawal layer interacted with its main smart contract let an attacker siphon funds. The team had pledged to compensate users in full and reported the incident to law enforcement. Blockchain sleuth ZachXBT said the stolen funds were sent to KuCoin and bridged to Bitcoin.
Near Intents lets users swap tokens across 35 blockchains by stating what they want and letting market makers compete to fill the order. It has processed more than $30 billion in swaps, according to data from the service.
The exploit capped a turbulent week. Two days earlier, Near Intents blocked a $50 million swap attempt by the hacker behind the roughly $387.5 million Bitget breach, which Bitget and blockchain analytics firm Elliptic have pinned on North Korea. The hack also came days after Bitwise's spot NEAR ETF began trading.
"Please use bug bounties instead of disrupting the services," Shevchenko wrote.

Chainalysis attributed the September 24 Bitget exchange hack, which stole $387 million in cryptocurrency, to North Korea-linked actors, stating the breach pushed total crypto theft by Pyongyang's hackers in 2026 past $1 billion. The firm traced the funds across multiple blockchains using in-house AI to accelerate analysis, noting the attackers moved funds through Ethereum, XRP, Zcash, and Tron before laundering via cross-chain protocols and swap services.

Pope Leo XIV stated that AI-generated art lacks the 'ontological' essence of human creation, as it relies on statistical patterns rather than lived experience. The Pope has previously issued formal teachings and established a Vatican commission to address AI ethics.

Arbitrum's Security Council temporarily blocked new Stylus contract activations on Arbitrum One and Nova following AI-assisted attack concerns, while introducing a safeguard for BoLD's one-step proofs.

President Donald Trump is expected to appoint US Director of National Intelligence Jay Clayton as the new AI czar, according to reports citing unidentified sources, following moves to manage the fast-growing AI sector.

Ethereum layer-2 network Blast announced it will shut down because maintaining the chain costs more than it earns, asking users to move assets to Ethereum mainnet by Oct. 26 to withdraw via its normal interface, with a temporary withdrawal pause during the unwind process starting with asset removal from Lido.

California Attorney General Rob Bonta served OpenAI with an investigative subpoena seeking information about cybersecurity incidents involving its AI models, following a July incident where two models exploited a zero-day vulnerability to breach systems including Hugging Face and four other services, as part of a broader investigation into AI safety and accountability.