The NEAR Intents protocol has seen a potential shift in its recent security incident as the exploiter reached out to the project team. On October 2, 2026, reports emerged indicating that the individual or group responsible for the exploit initiated contact by sending a small amount of cryptocurrency to a recovery address, accompanied by a message suggesting a desire to cooperate. This development follows a significant breach that resulted in the loss of hundreds of thousands of dollars in digital assets.
Communication via Blockchain Transactions
According to Alex Shevchenko, General Manager of NEAR Intents, the exploiter transferred 1 BNB to a designated recovery wallet. The transaction included an embedded message expressing a willingness to discuss the situation and requesting contact information through the encrypted messaging app Signal. This move is often seen in the decentralized finance (DeFi) space as a precursor to "white hat" negotiations or the potential return of stolen funds in exchange for a bug bounty.
The technical details of the communication include:
- A transfer of 1 BNB on the BNB Chain to the recovery wallet.
- A prior transfer of 0.295 ETH on the Ethereum network occurring roughly one hour earlier.
- The use of the same message across both networks to ensure the project team received the notification.
Context of the NEAR Intents Security Breach
Security experts, including 23pds, the Chief Information Security Officer at SlowMist, confirmed that the address used for these messages is the same one involved in the initial exploit. The attacker had previously moved approximately 0.8 million in assets during the main phase of the breach. SlowMist is a prominent blockchain security firm known for tracking illicit fund movements and providing forensic analysis during DeFi exploits.
NEAR Intents exploiters transferred 1 BNB to a recovery wallet with a message expressing willingness to cooperate and requesting contact information via Signal.
The identification of these transactions allows the NEAR Intents team to establish a formal line of communication. By using the same address that holds the majority of the stolen funds, the exploiter has verified their identity to the developers, which is a standard step in on-chain negotiations.
The situation remains fluid as the NEAR Intents team evaluates the exploiter's proposal. While the transfer of small amounts of BNB and ETH indicates a potential resolution, the recovery of the full $800,000 remains the primary objective for the protocol's stakeholders. The industry continues to monitor the recovery wallet for any further outgoing transactions that might signal the return of the remaining liquidity to the NEAR ecosystem.
Frequently Asked Questions
Quick answers to the most common questions about this topic.