NEAR Intents Hacked for $3.8M: Inside the Protocol’s Swift Response

Share

The NEAR Intents protocol suffered a $3.8 million theft on Thursday, but the team’s exemplary crisis management — a fix within one hour, full reimbursement announced, and cooperation with authorities — has turned this hack into a resilience test for the cross-chain DeFi ecosystem.

🔑 Key Takeaways

  • The attacker exploited a flaw in the software layer handling fund inputs and outputs.
  • $3.8M stolen and laundered through KuCoin in bitcoin according to ZachXBT.
  • NEAR Intents has processed over $30 billion in swaps across 35 networks.
  • NEAR token drops ~9% to $4.86, Bitwise NEAR ETF loses more than 7%.
  • All affected users will be fully reimbursed by the team.

1. Anatomy of the Hack

The attack targeted the software layer responsible for managing fund flows within NEAR Intents, as well as its interaction with the main contract holding user funds. NEAR Intents is a cross-chain cryptocurrency swap service that emphasizes transaction privacy by masking counterparties and amounts. The tool has established itself as a major player in the sector: the platform reports a cumulative volume exceeding $30 billion in swaps spread across 35 blockchain networks.

The attacker’s modus operandi has not yet been fully detailed, but early analysis points to an orchestration vulnerability between the protocol’s modules. Blockchain research team ZachXBT quickly traced the stolen funds: converted to bitcoin then deposited on the KuCoin exchange, a platform often used as an exit point by hackers due to its deep liquidity and variable regulatory tolerance depending on jurisdiction.

2. Crisis Management in Under One Hour

The NEAR Intents team’s response has been praised by several industry observers. The sequence of actions taken since the vulnerability was detected illustrates an operational discipline now expected in professional DeFi (decentralized finance).

Detailed timeline

EventTiming
Vulnerability detectionT0
Service shutdownT+several minutes
Faulty contract patched< 1 hour
Core services restored~1 hour
Full recovery (11 networks)T+13 hours

Deposits and withdrawals on 11 blockchain networks — including BNB Chain, Polygon, and Optimism — remained suspended for an additional 12 hours after core services resumed, time needed to deploy a complete fix and audit the entire infrastructure. The company confirmed that all affected users will be fully reimbursed.

3. Impact on NEAR Token and Bitwise ETF

The market reacted instantly to the news. The NEAR token fell nearly 9%, sliding to $4.86 according to available data. Even more revealing: the Bitwise NEAR ETF, launched just two days before the incident, lost more than 7% of its value. This unfortunate timing placed Bitwise in a delicate situation, as the ETF had been presented by the company as “proof of NEAR network growth.”

The combined drop in the underlying asset and the derivative product illustrates the sensitivity of crypto financial instruments to security incidents, even when the scale of the damage remains contained. For asset managers launching crypto ETFs, the message is clear: security monitoring has become as crucial as the technical performance of the underlying protocol.

4. Comparison with Other Recent Incidents

The NEAR Intents incident fits into a series of security events that have marked the crypto ecosystem in recent weeks. This perspective helps relativize the scale of the hack and assess the maturity of each player’s response.

ProtocolAmount lost / impactDowntime
NEAR Intents$3.8M~13 hours
Kelp DAOSeveral hundred M$Under analysis
Bitget (exchange)$387.5M4 days of withdrawal freezes
MetaMaskValidator withdrawalMinimal communication

The gap between $3.8 million and several hundred million dollars highlights both the maturity of detection mechanisms and the importance of a segmented architecture to limit the propagation of vulnerabilities. By that yardstick, NEAR Intents’ response ranks among the most structured in the sector.

5. A “Bullish Hack”?

The handling of the incident has led several analysts to use a provocative term: “bullish hack.” The parallel is drawn with the self-exploitation discovered by the ZCash team, a case where the rapid disclosure of a vulnerability had paradoxically strengthened confidence in the project. Tyler Warner, author of Decrypt’s Morning Minute newsletter, summarizes this perception:

“This is pretty much the best-case scenario for such a bad event.”

Tyler Warner, Author of Morning Minute (Decrypt)

Six ingredients of a bullish hack

  • Rapid bug identification and immediate service shutdown.
  • Patch applied in under one hour.
  • Transparent public communication.
  • Direct contact with law enforcement.
  • Commitment to full user compensation.
  • Refusal to downplay the incident or sweep it under the rug.

The incident also occurs a few days after NEAR Intents publicly denied any link to a hacker suspected of being affiliated with North Korea and considered responsible for the Bitget exchange hack. This stance reinforces the team’s credibility in its willingness to cooperate with authorities.


Conclusion

The NEAR Intents episode illustrates the new standard of crisis management in DeFi: rapid detection, transparent communication, and full reimbursement commitment. While the hack remains a warning signal about the growing complexity of cross-chain protocols, the team’s response could paradoxically strengthen institutional confidence in the medium term, provided the post-mortem audit is made public.

The scenario to watch remains the following: if the full reopening proceeds without new incident and reimbursements are effectively executed within 30 days, the NEAR token could recover its pre-hack level. Conversely, the discovery of a second flaw or a delay in compensation would shift the narrative from “bullish hack” to lasting distrust, mirroring what other protocols have experienced after reimbursement announcements that never materialized.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Disclaimer: this content is for information purposes only and is not financial advice. Cryptocurrencies are highly volatile: you may lose all of your capital. Always do your own research. Legal notice
Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Read More

Items