Near Intents, the cross-chain swap service built on the Near protocol, has recovered the full $3.8 million stolen in an exploit of its platform, the company said, closing an episode that unfolded in under 48 hours from breach to full restitution.

Chief executive Alex Shevchenko announced the recovery on X, writing: "The funds from the NEAR Intents hack, amounting to $3.8 million, have been fully returned. We are ending the investigation." The statement followed an earlier, more pointed message from Shevchenko directed at the attacker: "We have identified you, sir."

According to Near Intents, the exploit stemmed from a flaw in the interaction between the Omni deposit and withdrawal layer and the platform's main contract. The company gave the attacker a 48-hour window to return the stolen funds after identifying them, an ultimatum that preceded the full recovery.

A hacker's apology

Shevchenko also relayed an onchain message he attributed to the author of the exploit, who wrote: "We have returned all the funds, we were in the wrong." Near Intents has since closed its internal investigation, though the episode leaves open questions about any separate processes that may follow.

Part of the stolen funds was traced by independent onchain investigator ZachXBT, who followed the money through KuCoin before it was converted and moved onto the Bitcoin network.

A tense backdrop

The exploit landed just two days after Near Intents had blocked $50 million in transactions linked to the hack of exchange Bitget, an incident estimated at $387.5 million in total losses. Both Bitget and blockchain analytics firm Elliptic have attributed that hack to North Korean actors, adding a layer of tension to the week's events even though no link has been established between the two incidents.

Near Intents enables swaps across 35 blockchains, including Ethereum, BNB Chain and Solana, and has processed more than $30 billion in volume since launch, underscoring the scale of infrastructure that was briefly compromised.

Not the first reversal

Full or near-full restitution after a major exploit has precedent in crypto. In 2021, the attacker behind the $611 million Poly Network hack returned most of the stolen funds. In 2023, the Euler Finance attacker likewise returned almost all of what had been taken. The Near Intents case now joins that list, though the speed of the reversal — under two days from attack to full recovery — stands out even against those episodes.