Alex Shevchenko, general manager of NEAR Intents, said on October 2 that the team has identified the person responsible for the roughly $3.8 million loss the cross-chain protocol disclosed a day earlier. He gave that person 48 hours to return the funds, describing the deadline as the final chance to settle the matter under responsible disclosure.
NEAR Intents is a cross-chain protocol in the NEAR Protocol ecosystem that lets users swap assets across different blockchains by stating the outcome they want, which a network of market participants then fills.
What Shevchenko Posted
Shevchenko published the demand at 00:18 Coordinated Universal Time (UTC) on October 2 in a post on X from his personal account, @AlexAuroraDev. “We have identified you, sir,” he wrote.
He asked that the funds be sent to the following addresses:
- Bitcoin (BTC): bc1qjhv3hu8rfteh5e8exfmalvx2z3pzlmjlgnzxey
- BNB Chain and Ethereum (ETH): 0xB18a1aEDfde8B70FD67012C9E9c7a088B4d0C0e7
- Solana (SOL): AHTfKaeRcaK1sbSG8MFJS2uPxLBChfenigNtvbWEkhKD
A single address covers both BNB Chain and Ethereum because both networks use the Ethereum Virtual Machine (EVM) address format.
Shevchenko closed the message by telling the recipient, “You know better than most how responsible disclosure works,” before adding, “this is the last window to use it. After 48 hours, that window closes.” Counted from the post’s timestamp, the deadline runs to about 00:18 UTC on October 4.
The message came from Shevchenko’s own account, not the project’s. His profile identifies him as general manager of NEAR Intents and states that the views posted there are his own. The official @near_intents account had not published a matching statement on the identification claim or the deadline when Shevchenko’s post went live.
What NEAR Intents Disclosed on October 1
NEAR Intents paused services on October 1 after detecting a security incident. In a statement posted at 12:53 UTC on October 1, the project attributed the cause to “a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.” Omni is the infrastructure that handles deposits into and withdrawals out of NEAR Intents across supported blockchains.
The project put the preliminary loss at approximately $3.8 million and said, “These funds will be compensated in full.” The Crypto Times reported the swap halt and the $3.8 million outflow on the same day.
According to the October 1 statement, the vulnerability on the smart contract side had been patched, and NEAR Intents and near.com were expected to resume within about one hour. Deposits and withdrawals were expected to remain unavailable for roughly 12 more hours on BNB Smart Chain (BSC), Polygon, The Open Network (TON), Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll, and Plasma while fixes to the Omni infrastructure were completed.
Users holding assets from those chains inside NEAR Intents, including through the HOT wallet or on near.com, were told they could swap them into other assets once the service came back online.
The project also said it had reported the incident to law enforcement and was working with security and blockchain analytics partners to trace the funds and pursue recovery. It added that a detailed report would be shared publicly in the following days.
What the Deadline Post Adds and Leaves Out
The October 2 post is the first public claim from Shevchenko that the person behind the exploit has been identified. It adds three return addresses and a 48-hour limit.
It does not name the individual, publish any evidence supporting the identification, or state that any funds have been returned. It also does not offer a bounty or reward figure; the wording points to responsible disclosure rather than a new payout.
The post does not alter the compensation commitment. The October 1 statement remains the project’s public pledge that the approximately $3.8 million will be covered in full. Neither post includes a repayment schedule for affected users.
Separate From the Bitget Hack Flows
The deadline is unrelated to NEAR Intents’ late September account of funds linked to the Bitget hack. On September 29, The Crypto Times reported that attackers attempted to route more than $50 million in Bitget hack funds through NEAR Intents, with about $503,000 frozen mid-swap and about $166,000 completed, according to figures Shevchenko shared at the time.
That episode involved attempted use of the protocol to move proceeds from a theft on another platform. The October 1 incident stemmed from a bug in how the Omni infrastructure interacts with the NEAR Intents smart contract.
What Remains Open
NEAR Intents has said a detailed report on the October 1 incident will follow. Until that report or a further statement from the official project account is published, the identification claim rests solely on Shevchenko’s October 2 post. Whether any of the listed addresses receive the funds before the 48-hour window closes has not been established in any statement published so far.
Also Read: FlashLoopAdapter Exploit Drains $305K From Two Aave-Linked Safes
