BTC—ETH—SOL—XRP—BNB—ADA—DOGE—TRX—LINK—AVAX—DOT—LTC—
Live

NEAR Intents recovers full $3.8 million after exploit deadline

NEAR Intents clawed back all $3.8 million drained in an October 1 exploit after giving the attacker 48 hours to return it. The funds came back on October 2, and the protocol closed its investigation without naming who was behind the theft.

By Himanshu Sakre

Published · 4 min read

NEAR Intents said the full $3.8 million drained from the cross-chain protocol on October 1 has been returned. The attacker sent the funds back on October 2, inside a 48-hour window the team had set. The investigation is now closed.

Alex Shevchenko, general manager of NEAR Intents, confirmed the recovery in a public post. "The funds from the $3.8M NEAR Intents hack were sent back in full," he wrote, adding that the team was dropping its probe. The protocol had already promised to repay affected users whether or not it clawed back the money.

What was taken on October 1

Trouble began with irregular outflows from a BNB Chain hot wallet. NEAR Intents paused deposits and withdrawals across 11 networks, among them BSC, Polygon, TON, Optimism and Avalanche. The team traced the fault to a bug in how its Omni deposit and withdrawal system talked to the NEAR Intents smart contract, not to the NEAR blockchain itself. A preliminary count put the loss near $3.8 million. NEAR Protocol kept running. The team said deposits and withdrawals on the hit networks stayed offline for about 12 more hours while it finished repairs, even as trading resumed quickly.

Blockchain investigator ZachXBT said the stolen money was moved to the KuCoin exchange and bridged into Bitcoin soon after the breach. NEAR Intents first paused its services while it patched the Omni code. Days earlier the same team had frozen about $503,000 of funds stolen in a separate Bitget breach, which made it an unusual target. That record did not keep the protocol from becoming a victim itself.

The 48-hour ultimatum

Shevchenko said the team identified the person behind the exploit and gave them 48 hours to send everything back, framing it as responsible disclosure. The return transaction landed on BNB Chain at 16:15 UTC on October 2 and carried a message from the attacker's address. A Bitcoin wallet received 34.59 BTC, worth roughly $2.95 million at the time, with the rest coming back as a small amount of BNB and ether.

He would not name the attacker. "No. We dropped the investigation already," Shevchenko said when asked. His parting line to the industry was blunt. "Please use bug bounties instead of disrupting the services," he wrote.

Why a full recovery is rare

Full clawbacks are the exception. Most exploits in 2026 ended with partial recoveries or nothing at all. September was the worst month of the year for crypto hacks, with losses near $768 million by one industry count. Against that backdrop, getting every dollar back stands out.

The deal came at a price. By closing the case in exchange for the money, NEAR Intents let the attacker walk without charges. The recovery does nothing about the flaw that allowed the theft, though the team says it patched the Omni contract before restarting. It has not said how large its bug bounty is, or whether it offered one here. The cash returned fast. Trust takes longer.

White-hat style returns have become more common in 2026, but they still lean on advantages a victim rarely has. A named suspect. Funds parked on an exchange that can freeze them. A public deadline that raises the cost of staying quiet. NEAR Intents had at least one of those going for it. Many teams that get hit have none.

What to watch

A few things will show whether this was a clean win. Watch for a full post-mortem on the Omni bug, the kind that lets other teams check their own code. Watch whether all 11 networks come back without fresh problems. And watch whether the return-it-or-else approach keeps working, because it only holds when a team can actually name who took the funds.

Frequently asked

Did NEAR Intents users lose money?

No. NEAR Intents recovered the full $3.8 million taken on October 1, and the team said it would have repaid affected users even if it had not clawed the funds back. Deposits and withdrawals were paused during the incident and have since resumed across the networks the protocol supports.

How was the stolen $3.8 million returned?

The attacker sent it back voluntarily. After NEAR Intents identified the person and set a 48-hour deadline, a return transaction hit BNB Chain at 16:15 UTC on October 2. A Bitcoin address received 34.59 BTC, about $2.95 million at the time, and the rest came back in BNB and ether.

Was the attacker caught or charged?

No. General manager Alex Shevchenko said NEAR Intents dropped its investigation once the money was returned and chose not to name the person responsible. He urged others to use bug bounty programs rather than attack live services. The team has not said whether any reward was paid for the return.

Sources, and what is behind them

  1. NEAR Intents recovers entire stolen $3.8M after ultimatum to exploiter, Cointelegraph (October 3, 2026)Press report
  2. NEAR Intents hacked days after freezing stolen Bitget funds, Protos (October 1, 2026)Press report
  3. NEAR Intents GM says $3.8 million in hack funds returned in full, The Defiant (October 3, 2026)Press report
  4. NEAR Intents ends exploit probe after $3.8 million is returned, The Crypto Times (October 3, 2026)Press report