mt logoMyToken
ETH Gas
عربى

NEAR Intents Security Incident: Approximately $3.86 Million in Stolen Funds Transferred to KuCoin, Attacker Suspected to Be Lazarus Group

يجمعcollect
شاركshare

NEAR Intents has suffered a security incident, with approximately $3.86 million in stolen funds transferred to KuCoin; the attacker is suspected to be North Korea's Lazarus Group.

On the latest developments, according to multiple sources, NEAR Intents has suffered a security incident, and approximately $3.86 million in stolen funds has been transferred to KuCoin. Reports also mention that the attacker is suspected to be North Korea's Lazarus Group. The incident involves a suspected Lazarus Group connection and the flow of funds to a centralized exchange, and is currently classified as an incident with high security and regulatory attention.

On the core facts, the currently confirmable information mainly includes: the entity involved is NEAR Intents; the amount of stolen funds is approximately $3.86 million; the funds flow points to KuCoin; and the attacker's identity is described as "suspected to be" North Korea's Lazarus Group. Beyond that, existing reports do not provide the specific time of the attack, the attack method, the types of affected assets, the number of affected users, or vulnerability details. Due to these information gaps, it is not yet possible to make a more complete judgment on the full picture of the incident, the attack path, and the scope of impact, nor is it appropriate to describe the incident's impact in exaggerated terms.

On multi-source reporting and information completeness, related reports state that the NEAR Intents security incident has been covered by multiple sources. Among similar reports, the existing information retains the Lazarus connection and the flow of funds, making it relatively more complete. However, multi-source reporting is not equivalent to an official final conclusion; in particular, attribution of the attacker and ownership of the funds still require further confirmation by the project team, trading platforms, security firms, or law enforcement. At this stage, the reports themselves can only serve as leads on the incident and cannot replace formal investigation results.

Regarding the Lazarus connection, North Korea's Lazarus Group has been alleged to be possibly related to this attack, but it is currently described as "suspected." If confirmed later, the characterization of the incident may change. Existing materials do not provide the basis for attribution, sources of evidence, or official confirmation. Therefore, before an authoritative conclusion is released, the suspected connection should not be directly treated as a confirmed fact, nor should it be used as the sole basis for judging the incident's subsequent impact. The final determination of the attacker's identity should still be based on formal disclosures by security agencies or law enforcement.

On the flow of funds, the transfer of stolen funds to KuCoin makes the centralized exchange a key part of incident handling. Whether the exchange promptly flags, freezes, or restricts the movement of funds from related addresses remains to be seen. Existing reports do not indicate whether KuCoin has taken risk control measures, nor do they show whether it has issued a formal response. Therefore, how the funds are handled after entering the exchange is an important observation point for judging the incident's direction, rather than a handling outcome that has already occurred. KuCoin's subsequent actions will directly affect whether the funds may continue to be transferred.

On NEAR Intents' subsequent response, as the entity involved, whether NEAR Intents later releases a security incident report, discloses the attack path, cooperates with security firms to trace the funds, or launches user asset handling or compensation plans all await further information. Existing reports do not provide these details. For the project team, transparency, response speed, and cross-platform collaboration capacity after a security incident are response dimensions to watch. Whether relevant announcements are issued and whether they include technical details and fund-tracing progress will help the outside world assess the status of incident handling.

On security and regulatory attention, existing information marks this incident as one with high security and regulatory attention. This is because the incident simultaneously involves stolen funds, a suspected Lazarus Group connection, and the inflow of funds to a centralized exchange. There is currently no information indicating that regulators have formally intervened, and whether regulatory statements emerge later should still be based on official releases. In the absence of clear regulatory action, this level of attention is not equivalent to regulatory consequences that have already occurred.

On industry observations, the focus for this incident may be whether it exposes a replicable attack path and whether relevant platforms can reduce the possibility of further fund transfers through risk control and collaboration. It should be noted that an attack on an individual project does not necessarily mean that similar projects share the same risk, and market judgment should be based on subsequently verifiable information. Based on existing information, the attack path, scope of impact, and fund transfer chain have not been disclosed, so it is impossible to determine whether the same protocol risks exist.

On information verification principles, in security incidents, attacker attribution, the amount stolen, and fund flows often update as investigations progress. The current information is still at an early stage, and subsequent updates may change the understanding of the incident's scope and attribution of responsibility. Relevant developments should be based on formal disclosures by the project team, trading platforms, security firms, or law enforcement, and judgments should not be made based on a single source or unverified claims. Existing reports do not provide technical details on attacker attribution, and readers should avoid citing the suspected connection as a definitive conclusion.

On what to watch next, five pieces of information can be tracked closely: first, NEAR Intents' official investigation conclusion; second, KuCoin's handling measures for the related funds; third, further attribution by security firms regarding the Lazarus connection; fourth, whether law enforcement intervenes; and fifth, whether the stolen funds continue to move on-chain. All of the above should be based on disclosures from official or authoritative channels, and excessive inferences about market impact should not be made when information is incomplete.

Based on currently available information, the core facts of the NEAR Intents security incident are that approximately $3.86 million in stolen funds flowed into KuCoin and that the attacker is suspected to be linked to North Korea's Lazarus Group. The incident is still developing, and subsequent handling and confirmation of attribution will determine its final scope of impact.

إخلاء المسؤولية: تعود حقوق نشر هذه المقالة إلى المؤلف الأصلي ولا تمثل MyToken(www.mytokencap.com)الآراء والمواقف ؛ يرجى الاتصال بنا إذا كانت لديك أسئلة حول المحتوى وحقوق التأليف والنشر وما إلى ذلك.
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
(https://t.me/mytokenGroup)
القراءة ذات الصلة