NEAR Intents recovers all $3.8 million taken in exploit a day after the attack

NEAR Intents lost about $3.8 million on Oct. 1 to a bug between its deposit and withdrawal infrastructure and its smart contract.
The team said it had identified the attacker and set a 48-hour deadline; the funds came back in full on the night of Oct. 2.
The company said the investigation is closed, but its detailed incident report has not yet been published.
NEAR Intents, a cross-chain trading service built on the NEAR blockchain, recovered the full amount of roughly $3.8 million taken in an exploit, one day after the attack. "The funds from the $3.8M NEAR Intents exploit have been returned, just one day later, and the investigation is closed," the project said on its official X account on Oct. 2 (local time). NEAR Intents lets users specify the trade outcome they want and handles the swap across chains on their behalf; it connects more than 30 networks.
- NEAR Intents says services were stopped after a security incident; preliminary loss put at about $3.8 million, with a pledge to compensate users in full
- Alex Shevchenko, head of NEAR Intents, says near.com is back up
- Shevchenko tells the attacker "We have identified you, sir," posts return addresses and sets a 48-hour deadline
- Shevchenko posts encrypted messages that can only be read with the private key of the attacker's wallet
- Funds returned in full (according to NEAR Protocol co-founder Illia Polosukhin)
- NEAR Intents' official account announces the return and the end of the investigation
All times are KST.
The flaw sat between the deposit and withdrawal infrastructure and the contract
In its Oct. 1 notice, NEAR Intents attributed the incident to "a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract." Omni is the layer that moves assets from other chains into and out of NEAR Intents. The company said it had patched the contract-side vulnerability, and trading resumed about an hour later.
It said deposits and withdrawals on 11 networks (BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma) would remain unavailable for roughly another 12 hours while fixes to the Omni infrastructure were completed. Users holding assets from those chains inside NEAR Intents, for example in HOT wallet or on near.com, were told they could only swap them into other assets in the meantime. The company said it had reported the incident to law enforcement and was working with security and blockchain analytics partners to trace the funds. It said a detailed report would be shared publicly "in the following days," but as of the evening of Oct. 3 KST no report had been posted on its official account.
A 48-hour deadline, settled in a day
On the morning of Oct. 2, Shevchenko posted three return addresses on X: one for bitcoin, one shared by BNB Chain and Ethereum, and one for Solana. Invoking responsible disclosure, the practice of reporting a vulnerability to its operator rather than exploiting it, he wrote: "You know better than most how responsible disclosure works — this is the last window to use it. After 48 hours, that window closes." Later that night he published encrypted messages that only the attacker's private key could unlock, writing, "Thank you for your willingness to cooperate."
Polosukhin said SHIELD, the AI security layer on NEAR Intents, together with investigative work, allowed the team to identify the party responsible less than 24 hours after the hack and establish contact, and that the funds were recovered in full at 14:30 UTC on Oct. 2. He added a call to use bug bounties, programs that pay rewards for reporting vulnerabilities: "for security researchers looking for exploits, we encourage you to use bug bounties."
"The funds from the $3.8M NEAR Intents hack were sent back in full. We are stopping the investigation. Please use bug bounties instead of disrupting the services."
Alex Shevchenko, head of NEAR Intents
The company did not say separately how user compensation was handled alongside the returned funds.
A week earlier, it blocked Bitget hacker funds
The exploit came only days after NEAR Intents said it had blocked laundering of funds from another hack. In a Sept. 28 post on X titled "The Bitget Hack: What We Saw at NEAR Intents," Shevchenko said that after exchange Bitget was hacked for about $387.5 million on Sept. 24, the attackers tried to move more than $50 million through NEAR Intents, yet only $166,000 got through, while $503,000 was halted mid-transaction. He noted that the figures were rounded estimates that could deviate from the true values by up to 10%.
In his post on the return, Polosukhin said, "The events of the last week have shown the value of SHIELD to find suspicious activity before things escalate too far," adding that work was already underway to harden its security systems. NEAR Intents has been expanding a confidential trading feature that hides users' transaction details, and he also wrote: "Confidentiality cannot come at the expense of lawfulness."
NEAR prices on Upbit and Bithumb
NEAR is listed on the Korean won markets of both Upbit and Bithumb. On Binance's one-hour chart, NEAR fell from $5.09 to $4.74 in the 10 p.m. KST hour on Oct. 1, right after the incident notice, before closing the hour at $4.96. The low was nearly 9% below the $5.20 opening price of the 7 p.m. hour that day.
The price did not recover after news of the return. Around 8:30 p.m. KST on Oct. 3, NEAR traded at $4.69 on Binance, down 3.9% over 24 hours. At the same time it changed hands at 6,385 won on Upbit and 6,375 won on Bithumb. The Upbit price was about 1% above the won-converted overseas price, putting the kimchi premium (the gap between prices on Korean exchanges and global markets) at around 1%.