NEAR Intents Recovers All $3.8M Stolen in Separate Hack
The investigation is closed, turning a reported $3.8 million theft into a full recovery for NEAR Intents.
Crypto hacks turn technical failures into immediate financial losses. This beat covers breaches of exchanges, bridges and onchain protocols in which attackers steal or redirect user and treasury funds. The failure may begin with a compromised hot wallet, leaked private key, faulty access control, manipulated oracle, flash-loan transaction or bridge validation flaw. For crypto readers, the important questions extend beyond the headline loss: which assets and networks are affected, whether deposits or withdrawals have stopped, who controls the stolen funds, and whether users face a shortfall. Incidents involving ETH, BTC, SOL and stablecoins such as USDT and USDC can also create liquidity pressure across multiple venues.
Zipp follows incidents from the first credible alert through the post-mortem. Day-to-day coverage examines onchain transfers, attacker swaps and bridging activity; statements from project teams, exchanges and security researchers; contract pauses and withdrawal restrictions; recovery negotiations; and proposals to reimburse users. Recent reporting has tracked drained AscendEX hot wallets and subsequent withdrawal concerns, Ostium funds converted from USDC into ETH, a flash-loan exploit affecting Summer Finance, and the bridge breach that prompted Taiko to halt its Ethereum L2. We distinguish confirmed theft from suspicious outflows or operational disruption, update loss estimates as wallets are traced, and scrutinize whether audits, multisignature controls and incident-response procedures worked as intended.
The investigation is closed, turning a reported $3.8 million theft into a full recovery for NEAR Intents.
Bybit kept withdrawals open without further issues, underscoring the trade-off between precaution and uninterrupted access.
Lubin says investigators have found no indication that MetaMask wallets or customer funds were affected, and clients' withdrawal keys are held separately.
The attack puts maritime cyber risk in focus for oil traders, with the supply implications hinging on whether the tanker's journey is affected.
Users can redeem recovery tokens now, but larger reimbursements depend on future funding and the recovery of stolen assets.
The theft pushes DPRK-linked crypto losses above $1B in 2026, while rapid cross-chain transfers show how quickly stolen funds can be dispersed.
A single exchange hack accounted for nearly a third of the damage, putting the concentration of crypto security risk in focus.
The $388M draw on Bitget's self-managed backstop is one of the larger disclosed exchange losses, and the real test is whether the 131% reserve snapshot holds through the Oct 2 withdrawal restart.
A handful of mega-breaches now define the industry's annual security tally, and a state-sponsored adversary sits behind 37% of the bill, raising the stakes for every exchange and protocol custody…
A precautionary validator withdrawal has widened Ethereum’s exit queue, while the extent of the attacker’s access remains unresolved.
ETF inflows have outweighed direct security losses, but repeated exploits threaten to raise the cost and scrutiny of institutional adoption.
The reported diversion of block rewards was small, but potentially compromised signing keys leave a separate slashing risk for validators still active.
The reported diversion is small, but affected validators could miss staking income for weeks while they exit and re-enter Ethereum's staking system.
The precautionary move puts staking infrastructure risk in focus as MetaMask Staking works to protect client assets.
The precaution affects non-custodial staking operations; MetaMask says it does not hold clients' withdrawal keys.
MetaMask says wallets face no immediate threat, but it is taking precautions in its staking operations.
The move follows failed attempts to route more than $50M through NEAR Intents, underscoring how tighter screening can push stolen funds toward privacy tools and permissionless venues.
The transfer represents part of the 18,900 ZEC stolen from Bitget, while Zcash’s shielded pool is designed to increase transaction privacy.
The timeline places malicious activity more than three weeks before Bitget's hot wallets were drained, making the lead-up central to the investigation.
The deposits cover about 15% of the stolen ZEC, adding a privacy layer that complicates tracing but does not erase every potential clue.
A crypto protocol hack is an unauthorized theft or diversion of digital assets caused by compromised credentials, flawed smart-contract logic, broken access controls or another security weakness. Not every outage or suspicious transfer is a confirmed hack.
Start with wallet addresses confirmed by the affected project or reputable security researchers, then use a block explorer to follow transfers, swaps and bridge deposits. Labels are useful but can be incomplete, so an address association should not automatically be treated as proof of identity.
Attackers may swap stablecoins because issuers can freeze certain tokens or because ETH provides deeper onchain liquidity and is needed for network fees. A swap does not make the funds untraceable; subsequent transactions remain visible on public blockchains.
An audit can identify known coding and design risks, but it cannot guarantee that a protocol is secure. Private-key theft, faulty upgrades, governance abuse, configuration errors and newly discovered attack paths can still lead to losses.