Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,810▼ 1.52%ETH$2,681▼ 1.79%SOL$119.40▼ 1.92%TOTAL CRYPTO$2.9T▼ 4.55%S&P 5007,722.72▲ 0.73%NASDAQ27,190.86▲ 1.19%DOW51,176.96▲ 0.49%GOLD4,162.30▼ 0.95%WTI91.11▼ 1.90%BRENT102.25▼ 0.06%EUR/USD1.1257▲ 0.06%USD/JPY157.83▼ 0.06%DXY101.92▼ 0.17%
Crypto

NEAR Intents Gets $3.8M Back as Attacker Returns Funds

The attacker behind the $3.8 million NEAR Intents exploit returned all stolen USDT after the team identified them and issued a 48-hour deadline across three chains.

Pexels – Melvin Silva

NEAR Intents got its money back. The suspected exploiter behind last week’s $3.8 million drain on the cross-chain trading protocol returned all stolen assets after the team identified them and issued a 48-hour deadline, closing one of the year’s faster hack recoveries.

NEAR Protocol co-founder Illia Polosukhin confirmed the return in a Friday post on X. The exploit had hit on October 1, when irregular withdrawals began flowing from a BNB Chain hot wallet linked to NEAR Intents. Blockchain investigator ZachXBT flagged the outflows early, and the project confirmed losses of roughly $3.8 million, mostly in USDT, the dollar-pegged stablecoin.

The team traced the bug to the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. Deposits and withdrawals were suspended on eleven connected networks while the vulnerability was patched. Server infrastructure resumed quickly, but transfers stayed down longer, and the project promised full reimbursement to affected users before the attacker ever surfaced.

The 48-hour ultimatum that produced an answer

On October 2, NEAR Intents general manager Alex Shevchenko published a short ultimatum. The team had identified the suspected exploiter, he wrote, and gave a 48-hour window for the funds to be returned. The protocol posted three specific return addresses, one each for Bitcoin, EVM chains and Solana, leaving no ambiguity about where the money should go.

The count worked. By October 4, the protocol said the full amount had come back and declared the investigation closed. No on-chain enforcement was needed in the end. The realistic threats a named attacker faces, from exchange blacklisting to legal referral, appear to have been enough, which is not how most crypto exploits end.

“The exploiter returned all stolen assets one day later after the NEAR Intents team identified the attacker and established communication,” Polosukhin said on X.

What NEAR Intents actually is, and why the bug mattered

NEAR Intents sits in the orbit of the NEAR protocol as a cross-chain swap and settlement layer. Rather than routing trades through a classic bridge, it takes a user’s stated intent, say a token swap from one chain to another, and lets service providers compete to execute the order. Speed and price competition between those providers is the selling point. The tradeoff is that settlement flows through shared infrastructure, and a bug in that layer touches every route on the network at once.

Intent-based designs have grown fast this year precisely because they remove the mechanics from the user. A trader states what they want, an order matching layer fills it, and neither side has to know which bridges or pools sat underneath. The hidden cost is complexity. When the Omni deposit and withdrawal system interacted with the smart contract in a way its developers had not anticipated, the attacker found a way to pull treasury funds out instead of ordinary user funds. That a bug in plumbing, not in a market mechanism, produced the loss says a fair amount about where risk concentrates in these designs.

Date Development
Sept 30 – Oct 1 Exploiter uses smart contract bug to pull USDT from a BNB Chain treasury
Oct 1 NEAR Intents confirms $3.8M loss, patches bug, halts deposits and withdrawals on 11 networks
Oct 2 GM Alex Shevchenko identifies suspect, issues 48-hour deadline, posts return addresses
Oct 4 Full $3.8M returned, investigation closed

The episode fits a rough year for crypto security. Hack losses across the industry are on a pace well above 2025 levels, and July alone saw more than $400 million in exploit-related losses, the worst month of the summer. The Bitget breach of September 24, attributed by Chainalysis to North Korean actors, pushed 2026 losses from DPRK-linked hackers past $1 billion on its own. Cross-chain infrastructure keeps drawing attackers because treasury contracts and bridge flows concentrate value in single failure points, and this incident was no different.

What made this case unusual was not the size. A $3.8 million drain would have registered as a moderate hit in almost any other week. It was the ending. Most protocols that get hit face a quieter path: funds frozen in attacker wallets, negotiations conducted discreetly, sometimes no contact at all. Forcing the return inside two days through public attribution and named return addresses is rare enough that SafeWars, a security firm tracking exploiter behavior, noted that stolen funds rarely move back on this timeline without pressure the attacker takes seriously.

What comes next for transfers

Recovery of the funds does not immediately restore the service. Deposits and withdrawals were expected to come back in stages once the patched system passed internal checks, and users who interacted with the protocol during the frozen window were told to watch for official guidance on reimbursements. The project said full repayment of user losses would happen regardless of the attacker’s behavior, which leaves only the timeline open.

For the wider sector, the case sets a template that others can borrow. Name the attacker publicly, publish return addresses, and put a short clock on the response. It worked here because the team had already identified the suspect before going public, and because the exploit was small enough that returning it was plausibly the cheaper path compared with what comes after being named and tracked. Whether the approach repeats depends less on the tactic itself than on whether the next attacker is as easy to trace, and whether the next target is willing to move this fast.

SourcesCoinDesk; Crypto Briefing; CryptoTicker; Crowdfund Insider
Share: X