0ae267
NEAR Intents says exploiter returned $3.8M after ultimatum
NEAR Intents says the $3.8 million taken in an exploit was returned after its general manager set a 48-hour deadline, and the team has closed its investigation.
The Hashbeam Desk··3 min read

NEAR Intents says it recovered the full $3.8 million taken in an October 1 exploit after general manager Alex Shevchenko gave the person it identified as responsible 48 hours to return the funds. The team has closed its investigation, according to The Crypto Times’ report on the recovery.
The return followed a vulnerability in the interaction between NEAR Intents’ Omni deposit and withdrawal infrastructure and its smart contract. The incident interrupted deposits and withdrawals across 11 networks. The recovery matters to affected users because the team had initially pledged to compensate them in full; its later statement says the stolen funds themselves came back.
How did the Omni integration let funds leave?
NEAR Intents attributed the incident to a bug in how the Omni deposit and withdrawal system interacted with the NEAR Intents smart contract, The Block reported after the team’s initial disclosure. Blockchain investigator ZachXBT said irregular outflows came from the protocol’s BNB Chain hot wallet, and that the funds moved through KuCoin and were bridged to Bitcoin.
The available disclosures do not name a contract address, opcode, or specific validation step that failed. They describe the fault at the boundary between Omni’s deposit and withdrawal infrastructure and the NEAR Intents smart contract. NEAR Intents said the contract-side vulnerability had been patched and paused services while it investigated. Deposits and withdrawals on 11 networks remained unavailable for longer than the initial service interruption.
That account establishes the reported path—an integration bug, unauthorized outflows from a BNB Chain hot wallet, and cross-chain movement—but not the exact call sequence or how the flaw let the attacker withdraw funds. NEAR Intents has not published those technical details in the reports reviewed.
What did the ultimatum change?
On October 2, Shevchenko said the team had identified the individual behind the breach and published return addresses for Bitcoin, BNB, Ethereum, and Solana. He gave the person 48 hours to return the funds under what he called “responsible disclosure.” Cointelegraph reported that the team had also pledged to compensate affected users in full while its preliminary investigation assessed the loss at $3.8 million.
Shevchenko later said the funds had been returned in full and that the team was stopping its investigation. NEAR co-founder Illia Polosukhin said the team identified the responsible party in under 24 hours and established communication before the recovery. He credited SHIELD, NEAR Intents’ AI security layer, alongside investigative work, but did not explain how either identified the person or traced the funds.
What can the on-chain evidence confirm?
A BNB Chain transaction associated with the return included a message saying the funds had been returned. The Crypto Times reported that the transaction came from an address labeled “Near Intents Exploiter 1” by BscScan. The label and message support the reported account, but neither independently establishes who controlled the address or proves the complete return. The recovery amount and closure of the investigation remain statements from NEAR Intents’ leadership; the team has not published a full transaction breakdown or post-mortem in the reports reviewed.
Shevchenko urged security researchers to report vulnerabilities through bug-bounty programs instead of exploiting live services. For users, the immediate outcome is that the team says it recovered the stolen amount and ended the investigation. For engineers, the unreported contract-level failure path leaves open how the integration was corrected and what checks now prevent the same withdrawal failure.
References
- The Crypto Times’ report on the recovery — cryptotimes.io
- The Block reported — theblock.co