Who benefits? Who pays? Who comes back?

Low Hype Unit
KOLs coming home after another successful airdrop season.
7
4,290
NRR from @Bitwise held 7.20M near:native after day one. As of Oct 1, it holds 11.54M. So another 4.3M NEAR went into the ETF after launch day. For scale, the @near_intents buyback wallet has accumulated about 1.34M NEAR since February. I don't know if this means institutions are flipping bullish, because there's no way to know who the buyers are yet. The one thing I do know is that none of them had to use @NEARProtocol or NEAR Intents to get into NRR. 🫡
3
7
82
7,952
THORChain didn't launch zcash:native for the @bitget hacker. it was targeting April, sorry to break it to ya. what launched today is a native ZEC pool on @THORChain . right now it holds 0.14 ZEC and 237 $RUNE. about $355 total. 8 actions so far. 5 swaps. one BTC -> ZEC swap has already settled to a transparent Zcash address. that's the product: native asset in, native ZEC out. no account, and most definately no desk approving the trade. the pool is microscopic for now. the biggest swap put in about $48 of ZEC and got about $38 of RUNE back. the ZEC side is transparent and shielding is a second step in your own wallet. THORChain isn't the privacy layer - it's the permissionless route to it. the route is live, and the pool is $355 deep. Live ZEC pool state gateway.liquify.com/chain/th… Full ZEC pool action history gateway.liquify.com/chain/th… Current inbound/vault addresses - search ZEC gateway.liquify.com/chain/th…
6
3
65
7,756
SHIELD, in English. @near_intents NEAR Intents has a risk screen. On a 1Click swap, before Intents fills your order, SHIELD checks it against known incidents and risk signals. Think KYT, not KYC. It looks at the money, not your passport. The signals come from both machines and people. The docs describe a rule-based anomaly engine. Incidents can also be raised by partners, on-call operators and internal tooling. @AlexAuroraDev says SHIELD also takes signals from analytics providers, researchers and large institutions. If a flow is flagged: before execution: no quote. during execution: abort the swap and hold the funds. That's what happened with the @bitget hacker. $50M+ in attempted swaps flagged; most never got a quote. ~$503K stopped mid-swap. ~$166K got through. Alex's figures, ±10%. What SHIELD isn't: @NEARProtocol consensus. It doesn't freeze your wallet or stop the chain. It's policy inside the Intents app deciding whether Intents will process the trade. What isn't documented yet: where the rules end and human discretion begins, who can release a held swap, and what happens if SHIELD is wrong. The chain can stay permissionless, and the order desk can still say no. NEAR is the rail. Intents is the order desk. SHIELD is the screen at the desk. Alex Shevchenko's Bitget report: x.com/AlexAuroraDev/article/… Illia on permissionless vs policy: x.lingyaoai.com/ilblackdragon/status/2… SHIELD docs (Proactive Intents Security): docs.near-intents.org/securi… SHIELD Incident API: docs.near-intents.org/securi…
NEAR is permissionless programmable money. Permissionless means nobody needs permission to own and transfer assets, or deploy contracts on NEAR. It does not mean every application or liquidity provider must process every transaction. SHIELD is how NEAR Intents applies this in practice: shared, real-time risk intelligence that lets participants identify hacks and other incidents and choose not to facilitate stolen funds. Partners can both consume and contribute incident data. In the Bitget hack, SHIELD identified $50M+ in attempted flows through NEAR Intents and helped stop funds during execution. Open financial infrastructure does not require us to make theft easy. Instead of hiding behind "it's permissionless, what can we do" while sitting on pause button, we should be creative in solutions that are addressing underlying problem. We can have permissionless protocols that have intelligent defense. This is what we are building with SHIELD and invite everyone to join to make SHIELD industry-wide.
2
2
24
4,263
Oct 1: ~$3.8M stolen from @near_intents later that day: “we have identified you, sir.” Oct 2: $3.8M returned in full. investigation closed. yeah, I know the purists were like "OMG NEAR Intents has too much control!" and yet the pause button capped it, and attribution helped get it back. and : neither one was code. you can dislike the model, but it worked. kudos to @AlexAuroraDev and team 🫡
5
1
35
7,271
NEAR Intents, in English. You have ETH on Arbitrum. You want $SOL on Solana. Normally that's your problem: bridge, DEX, gas, routes, wallets @near_intents flips it: You say what you have and what you want. Market makers called solvers compete to fill the order. Best quote wins. A contract on @NEARProtocol checks the trade and settles it. That's the product: you post the outcome, pros figure out the route. try it: near.com You may have used it without seeing the NEAR name. It sits under the swap button in Trust Wallet, Ledger Live, Rabby, Brave, LI[.]FI, ZODL and Zashi It's also a big part of the @Zcash story: start with BTC, ETH, SOL or USDC and end up with $ZEC without doing the cross-chain plumbing yourself. $32B+ routed so far. And the user never needs to own near:native. Intents charges fees, NEAR keeps a piece, and that piece buys near:native . You can use the product without caring about the token and still create demand for it. Then there's the part everyone learned this week. To use Intents, you deposit first. Your ETH leaves Arbitrum through bridge infrastructure and shows up as a balance inside Intents. Solvers compete to fill your order against that balance. When you want the SOL on Solana, the withdrawal infrastructure gets it there. The user doesn't pick or manage any of that. HOT, Omni and PoA are bridge implementations under the hood. This week, a bug where that deposit/withdrawal infrastructure meets the Intents contract caused about $3.8M in losses. Intents says users will be compensated in full. So the plumbing didn't disappear, your assets still have to get in and out. You just don't manage it. That's chain abstraction in one sentence: the complexity is still there, it just became someone else's job.
5
6
62
7,697
Crypto: "Code is Law" @AlexAuroraDev just posted three return addresses and a 48-hour deadline.
We have identified you, sir. Please return the funds to the following addresses: Bitcoin: bc1qjhv3hu8rfteh5e8exfmalvx2z3pzlmjlgnzxey BNB / Ethereum: 0xB18a1aEDfde8B70FD67012C9E9c7a088B4d0C0e7 Solana: AHTfKaeRcaK1sbSG8MFJS2uPxLBChfenigNtvbWEkhKD You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes.
5
5,195
one of these is not like the other: @THORChain : "permissionless like Bitcoin" when the losses were Bybit's and Bitget's. halt when its own vault gets drained. @near_intents : intervene when Bitget's stolen funds hit the rail. halt when its own infrastructure breaks. promise to refund users. one says Bitcoin when the loss is somebody else's. you can dislike the control model, but the model didn't change when the losses did.
17
7
56
8,938
Osmosis is coming out of maintenance mode and looking elsewhere for growth. At its peak, @osmosis turned Cosmos infra into a retail product. IBC-connected chains were cool, but Osmosis gave people a reason to use them. In April, $OSMO holders voted to merge into the @cosmoshub. cosmos:native holders said no. Now Osmosis is back with a plan: ▫️Lower inflation ▫️ Burn most of the community pool ▫️ Concentrate treasury liquidity in a few core pools ▫️ Cut the validator set from 70 to 30 ▫️ Explore products "beyond the current chain" And I know the last line will get the attention, but the list is the story. The chain that turned IBC into a retail economy is cutting what it costs to run down to what it earns, and looking somewhere else for the next customer. And while semantically Osmosis isn’t leaving Cosmos, the retail side of the eco is mostly gone. What's left to swap?
9
1
63
11,572
MetaMask has now posted two updates on its security incident. ~1,300 characters. Sep 30: "no immediate threat to MetaMask wallets." Oct 1: "no indication that MetaMask wallets or customer funds have been affected." negative assurance without incident disclosure. what was compromised? not disclosed. what could the attacker reach? not disclosed. what the chain disclosed, per @0xKaden: ~17,000 validators exiting. 18 blocks paid ~0.36 ETH in fees to a wallet funded through Tornado Cash.
We’re continuing to actively investigate and respond to the security incident affecting part of our infrastructure. Our focus remains on working closely with affected partners and taking appropriate steps to protect users. As part of this, we worked with our partners to take the precautionary step of exiting affected validators. Based on our investigation to date, there is no indication that MetaMask wallets or customer funds have been affected. Our teams continue to work through containment and verification, and we’ll share further verified information as appropriate. As always, please remain vigilant: be cautious of unsolicited messages, never share your Secret Recovery Phrase or private keys, and rely on official MetaMask channels for updates. MetaMask will never ask you for your Secret Recovery Phrase. We’ll continue to share updates here as our investigation progresses: metamask.io/news/user-update
3
5
31
13,948
after some onchain sleuthing, i think this is what happened: 19 metamask validators had won block rewards, and 18 of the rewards were not paid to the correct fee recipient but instead to this tornado funded account: 0x98B9231de84334c1d48BA0b72CF13f92484924A3 ~17k validators proactively exited, ~523k eth total, unknown whether the attacker had the ability to change all fee recipients it appears that 3 of the exploited validators have not yet been exited, and that 821 potentially impacted validators in total have yet to exit, unclear why attacker only stole ~0.36 eth in rewards and likely never had the ability to withdraw any staked eth. however, depending on how the attacker managed to get signing access, they could potentially cause the validators to be intentionally slashed
2
1,048
NEAR Intents halted today after a bug in its deposit/withdrawal infrastructure. preliminary loss: ~$3.8M. Unchained traced ~$3.87M USDT out of a contract @near_intents 's own docs list as the HOT Bridge treasury on BNB Chain. Intents supports withdrawals through three bridge implementations: HOT, Omni and PoA, and the user never has to pick one. services stopped. the contract-side flaw was patched. 11 chains stayed offline while the infrastructure fix continued. "compensated in full." who pays? that's not in the NEAR statement. chain abstraction didn't remove the bridge, but it removed the bridge from the user.
3
2
16
6,294
MetaMask Staking doesn't control the withdrawal keys. an operator compromise can't redirect the staked ETH. it can redirect the block fees. Sep 30, 12:12–16:46 UTC: 18 blocks from @MetaMask -run validators paid their fees to a wallet funded through Tornado Cash at 10:27. total: 0.36 ETH. whoever set that address had access somewhere inside the validator operation. that's enough to treat the signing environment as potentially compromised. bad signatures can get validators slashed. Ethereum can't rotate a validator signing key in place. you exit, withdraw and restake with fresh keys. so they're rotating the validator. btw, we've seen the containment playbook before. Sep 9, 2025: Kiln disclosed a security incident and exited its Lido validators. 28 days later, the cause: compromised GitHub token -> CI workflows -> cloud credentials. 104 days later, the bill: 207.312 ETH in missed rewards across 5,726 validators. MetaMask hasn't disclosed the root cause or the validator count. one thing is already different. Kiln found no evidence its Ethereum validators were touched. here, someone was already collecting the fees. etherscan.io/address/0x98B92…
Security Update: We are responding to a security incident affecting part of our infrastructure. At this time, we have identified no immediate threat to MetaMask wallets. As a precaution, we are proactively exiting affected validators within our non-custodial staking operations, in coordination with clients, partners and security advisors. We’ll share further updates as appropriate. metamask.io/news/user-update…
5
11
82
22,671
A Nasdaq-listed company holding 55M+ $NEAR, most of it staked, just proposed cutting NEAR issuance from 2.5% to 1.6%. That costs SVRN roughly 970K NEAR a year in staking income, or about $5M at today's price. The CEO of SVRN disclosed the trade himself: less revenue recognition, more value in the NEAR already on the balance sheet. At 55M NEAR, a 10% move in the token is ~$29M. Six years of the income he's giving up. One of NEAR's biggest holders is asking the network to pay it less NEAR. Because it already owns a lot of NEAR. Nothing personal, just incentives. Forum link: gov.near.org/t/near-governan…
8
12
128
15,710
$35.5M into the NEAR ETF on day one, via @Bitwise, or 7.2M $NEAR tokens. About 0.55% of the supply, in one session. $NEAR found new customers without the product finding any new users. For comparison: @NEARProtocol buyback wallet, funded by protocol revenue since February 2026: ~1.34M NEAR. vs. NRR held 7.2M after one day. NYSE Arca has pretty good distribution. 🫡
2
4
41
5,900
bitwise @Bitwise launched a NEAR ETF today. the pitch: AI x crypto. @near_intents intents has routed $32.58B. that threw off $51.78M in fees. @NEARProtocol kept $8.20M of it - about 2.5 bps of the volume. and that $8M is now buying ethereum:0x85f17cf997934a597031b2e18a9ab6ebd4b9f6a4 on the open market. ~$5M of NEAR bought since February 2026, that's not burned. it sits in a wallet literally named buybacks.multisignature.near. 1.31M NEAR as of today. and ...here's the weird part: NEAR's own dashboard says buybacks "permanently remove NEAR from circulation." in August, @ilblackdragon proposed putting that revenue into a sovereign fund. on aug 20 he pulled it - partly because, his words, the mechanism "doesn't guarantee" the bought NEAR never comes back. so we're here: $32.58B activity -> $51.78M fees -> $8.20M to NEAR -> buybacks -> ? the first four are real. the fifth is still a forum thread. the "AI story" is PR and i'm more interested in what happens to the NEAR after they buy it. Links: ▫️Rev Dashboard: revenue.near.org/ ▫️NEAR governance forum - Sovereign Fund thread, page 1 (proposal and objections) gov.near.org/t/near-governan… ▫️NEAR governance forum - Sovereign Fund thread, page 2 (Illia withdrawal, Aug 20) gov.near.org/t/near-governan… ▫️buybacks.multisignature.near on NearBlocks nearblocks.io/es/address/buy…
4
24
5,547
This week, @THORChain and @near_intents showed the fork in the road: CT rewards ideological purity. it pays in likes. institutions pay for controlled openness.
Crypto space really has a choice - grow the f up or get sidelined with random regulations. Saying we can not do anything when we are programming decentralized system is just untrue. Banks run AI for fraud detection but are inherently centralized and require KYC. At the same time KYC doesn't solve any of real problems as we know. We have better data and talent to create systems that don't require KYC and actually deter criminals while giving full freedom to real users. By working together we can totally weed out crypto of criminal activity. Criminal TAM is way smaller than all of economy moving onchain we are targeting. Decentralization != disorganization
10
5,720
Stride is winding down. Your stATOM is not disappearing. The machine that creates it is. What that means if you hold stATOM or any @stride_zone stToken: ▫️ Until Oct 12: redeem normally on Stride ▫️ Oct 12: redemptions pause while the backing assets unbond ▫️ ~Nov 20: fixed-rate redemption pools open on Osmosis ▫️ Your stTokens do not expire ▫️ After migration, staking rewards stop and the rate freezes The @osmosis pools are an exit, not a replacement. Stride took ATOM, issued a liquid version, and could even convert already-staked ATOM without the 21-day wait. What stays behind on Osmosis only lets existing holders swap back into the ATOM that was unbonded to back them. No new yield. No new stATOM. Stride has ~$6M in TVL and, at current burn, runs out of money in February 2027. It is shutting down while it can still afford to do it properly. Stride was one of the better teams Cosmos produced, with a product people actually used. This is a real loss for the ecosystem, or what is left of the retail side of it. 🫡
4
11
56
9,138