NEAR Intents Hack Puts Crypto's Responsible Disclosure Culture on Trial

After a $3.8 million exploit, NEAR Intents identified the attacker and offered a 48-hour window to return funds before escalating consequences.

7 min read

Crypto security incidents usually end one of two ways: a postmortem written in passive voice, or a viral thread naming wallets and demanding justice. On October 2, 2026, NEAR Intents chose a third path—public identification paired with a timed ultimatum.

The protocol paused services after detecting a bug in the interaction between Omni deposit and withdrawal infrastructure and NEAR Intents smart contracts. Preliminary analysis found $3.8 million in user funds stolen. NEAR Intents pledged full compensation for affected users. Then general manager Alex Shevchenko posted on X: “We have identified you, sir,” giving the attacker 48 hours to return funds under “responsible disclosure” before, as he put it, “that window closes.”

Blockchain investigator ZachXBT reported that stolen funds were transferred to KuCoin and bridged to Bitcoin—classic laundering choreography that complicates recovery but does not eliminate leverage if exchanges cooperate.

What broke

Early statements pointed to a bug at the boundary of bridging and intent execution—exactly the kind of seam that accumulates risk as protocols stack abstractions. “Intents” systems promise users outcomes rather than transaction paths, routing across liquidity and chains behind the scenes. That convenience multiplies attack surface: deposit wrappers, withdrawal handlers, signature verification, and cross-domain state synchronization must all be correct.

The NEAR incident is a reminder that composability is not free. Every integration with external bridge infrastructure imports that partner’s threat model.

The responsible disclosure debate

Traditional cybersecurity has mature frameworks for vulnerability reporting: coordinated disclosure timelines, bug bounties, and legal safe harbors for good-faith researchers. On-chain finance adds pseudonymity, irreversible transfers, and communities that sometimes celebrate exploits as “white hat” if funds are returned.

Shevchenko’s message attempts to import off-chain norms into on-chain adversarial dynamics. Naming the attacker—while stopping short of a full dox in public posts—signals confidence in attribution. The 48-hour clock creates urgency. The subtext is clear: return the money or face escalation that may include law enforcement involvement, exchange freezes, and public pressure.

Critics will argue this approach blurs lines between security response and vigilante justice. Supporters will counter that $3.8 million thefts demand speed, and that protocols compensating users need leverage against attackers who treat exploits as arbitrage.

User protection and treasury policy

NEAR Intents’ pledge to make users whole is ethically strong and financially costly. It also sets expectations across DeFi: if protocols routinely socialize losses through inflationary token prints, user trust erodes; if they compensate from treasuries, treasuries must be sized for tail risk.

Venture-backed teams sometimes underreserve for black swan bridge failures. Incidents like this should push governance forums to stress-test insurance, emergency multisigs, and transparent communication templates before crises hit.

Broader market context

October 2026 has been active for crypto security headlines. The same week brought news of Blast shutting down its Ethereum L2 after operating costs exceeded revenue—a different failure mode, but equally instructive. Not every protocol death is a hack; some are unit economics failures.

Meanwhile, institutional rails continue expanding: the SEC proposed easing custody requirements for advisers holding crypto, and Mastercard integrated Open USD stablecoin access through BVNK. Security incidents do not pause maturation; they shape which protocols survive scrutiny.

Lessons for builders

Treat bridge boundaries as Tier-0 critical. Fuzz test deposit and withdrawal paths independently and composed.

Pre-write incident comms. Users deserve timestamps, scope, and compensation policy early—even while forensics continue.

Assume stolen funds will hit exchanges quickly. Pre-negotiate escalation contacts with major venues if you operate at scale.

Do not confuse intents UX with simplified security. Abstraction for users often means complexity for engineers.

What happens after 48 hours

If funds return, NEAR Intents will likely frame the outcome as a win for community norms. If not, expect legal processes, on-chain bounty campaigns, and intense debate about whether public identification helps or endangers unrelated parties.

Regardless of outcome, the incident reinforces a uncomfortable truth: as crypto finance becomes more automated, the human drama of attribution, negotiation, and reputation still determines who pays the bill.

For users, the practical takeaway is unchanged but worth repeating: bridge only what you can afford to lose, diversify custody, and treat shiny new intent routers as unaudited until proven otherwise.

Anatomy of intent-based architectures

Intent systems translate user goals—“swap token A for token B at best price”—into execution paths across liquidity venues and bridges. Users sign intents; solvers compete to fulfill them. The UX improvement is real: fewer manual transactions, less slippage hunting. The security cost is opaque execution graphs that cross trust boundaries.

NEAR’s Omni integration created a dependency chain: user deposits, bridge state, intent settlement contracts, and solver networks each assumed the others behaved correctly. Attackers hunt the weakest link, often deposit or withdrawal adapters that were audited separately but not composed.

Exchange cooperation and recovery odds

ZachXBT’s observation that funds moved to KuCoin and bridged to Bitcoin outlines a familiar laundering path. Recovery depends on exchange compliance teams freezing accounts quickly, jurisdictional cooperation, and whether the attacker cashed out before alerts propagated. Public ultimatums sometimes pressure thieves to negotiate; sometimes they accelerate exits.

Protocols should pre-establish contacts with major exchanges’ financial crime units. Minutes matter.

Insurance, auditing, and governance gaps

DeFi insurance products rarely cover bridge composition failures at scale. Governance tokens may vote to compensate users, but voter fatigue and treasury politics slow payouts. NEAR Intents’ upfront compensation pledge sets a high bar—other protocols should clarify user protection policies before incidents, not during Twitter threads.

Builder checklist after NEAR

  • Model composed threat scenarios in threat matrices, not single-contract audits.
  • Cap per-route liquidity during beta phases.
  • Publish pause mechanisms and multisig roles before launch.
  • Run chaos tests that simulate bridge delays and partial withdrawals.

Comparative incident timeline

Within 48 hours of detection, NEAR Intents paused services, published preliminary loss estimates, pledged user compensation, and publicly addressed the attacker. Compare that cadence to protocols that vanish for weeks. Communication discipline preserves community trust even when code fails.

Retail investor psychology

Headline hacks move token prices and social sentiment faster than technical postmortems. Traders should distinguish protocol insolvency risk from temporary operational pauses with compensation commitments. Long-term holders watch governance execution, not only Telegram outrage.

Cross-chain security collaboration

Bridges and intent routers should share attack signatures through industry groups like SEAL or similar ISAC-style efforts. Siloed responses help attackers reuse exploits across protocols that do not talk to each other.

Intent protocols will not disappear because one bridge integration failed. Users want simpler cross-chain experiences, and capital will continue funding UX improvements. The survivors will be teams that treat composition risk as first-class, publish incident runbooks before launch, and maintain treasuries sized for user protection pledges. NEAR Intents' public stance on compensation sets a benchmark competitors will be measured against in future incidents.

For developers integrating NEAR or similar intent layers, treat incident response contacts and pause switches as part of the API surface—not emergency-only trivia. Document which multisig can halt withdrawals and expected communication channels during outages. Users forgive hacks less when silence fills the gap between detection and disclosure.

Watching this story unfold is a reminder that crypto's social layer—public statements, ultimatums, and community pressure—remains as important as smart contract code. Whether the funds return or not, NEAR Intents has shown that transparency and user compensation pledges can coexist with aggressive attribution tactics.

More in cryptocurrency

Cubed

Write about the technologies shaping the future.

For developers, founders, and curious minds exploring AI, crypto, Web3, and emerging tech—signal over noise.

One free account across In Plain English, Stackademic, Venture, and Cubed.

How it works
  • AI, crypto & Web3
  • Software & emerging technologies
  • Analysis & practical resources
  • Thoughtful voices, not hype
1

Sign in

Google or GitHub

2

Complete profile

Takes a few minutes

3

Get approved & publish

Start sharing

Why write for Cubed?

The future deserves thoughtful voices, not just louder headlines.

Comments

Loading comments…

Posts Across the Network