In a dramatic turn of events, NEAR Intents has successfully recovered $3.8 million following an exploit that occurred on October 1, 2026. General Manager Alex Shevchenko confirmed the full return of the funds after a tense 48-hour deadline was set for the hacker to return the stolen assets.
The exploit was traced back to a bug within NEAR Intents’ Omni deposit and withdrawal system, specifically how it interacted with its smart contract. This vulnerability posed significant risks, leading the protocol to temporarily pause operations across 11 different networks, including BNB Chain, Polygon, and Avalanche.
Following the incident, the NEAR Intents team identified the exploit and promptly communicated with the suspected hacker, giving them a 48-hour window to return the funds. Remarkably, within less than a day, the hacker complied, sending back the entire $3.8 million. Shevchenko expressed relief at the outcome, stating, “The funds from the $3.8M NEAR Intents hack were sent back in full. We are stopping the investigation. Please use bug bounties instead of disrupting the services.”
The return of the funds primarily affects NEAR Intents’ balance sheet rather than the compensation owed to its users, as the protocol had already assured that affected users would be repaid in full.
Understanding the Exploit
The vulnerability was specifically linked to the connection between NEAR Intents’ Omni system and its smart contract. Illia Polosukhin, co-founder of NEAR, confirmed that the exploit was isolated to USDT on the Binance Smart Chain (BSC). The platform’s AI security layer, known as SHIELD, detected unusual activity and prompted a service pause to mitigate further risks.
The vulnerability was patched swiftly, within about an hour of detection, but the fallout led to a prolonged pause of services across various networks for nearly 12 additional hours while further measures were implemented. Networks affected included BNB Chain, Polygon, TON, and others, while NEAR Protocol confirmed that its core blockchain and native token remained unaffected.
Tracing the Stolen Assets
Blockchain investigators were quick to trace the stolen funds, tracking abnormal activity linked to the HOT Bridge treasury on BNB Chain. The investigations revealed that the funds flowed through KuCoin before being bridged into Bitcoin, with no evidence suggesting that the NEAR chain was compromised.
During the investigation, the hacker made minimal transactions of ETH and BNB to a recovery address, each accompanied by messages asking for contact details via Signal. In response, Shevchenko published three recovery addresses for the hacker to send the funds back, which included options for Bitcoin, BNB Chain, and Solana.
By October 2, the Bitcoin recovery address had successfully received about 34.59 BTC, confirming the hacker’s compliance with the ultimatum. NEAR Intents has since reported the incident to law enforcement and is collaborating with security firms to ensure the integrity of its platform moving forward.
Polosukhin pointed out a broader trend of attacks leveraging AI tools within the crypto space, citing other recent incidents involving prominent platforms like Bitget, MetaMask, and Lido. As NEAR Intents recovers from its first major exploit since its launch, the platform continues to process over $4 billion monthly.
As of the latest updates, NEAR Intents has confirmed the full return of the $3.8 million, and most services have been restored across all affected networks.
