Sponsored banner
NEWS

$3.8M Returned After NEAR Intents Gives Exploiter 48 Hours

  • October 5, 2026
  • 11 min read
$3.8M Returned After NEAR Intents Gives Exploiter 48 Hours

A $3.8 million crypto exploit has ended in one of the industry’s less common outcomes: all the stolen funds were returned.

NEAR Intents confirmed that approximately $3.8 million taken during an October 1 security incident was recovered after the protocol said it had identified the person responsible and gave them 48 hours to return the assets. Cointelegraph reported that the money came back before the deadline expired.

The unusual ending followed a fast-moving sequence of events. NEAR Intents detected the exploit, paused affected services, patched the vulnerability, traced the stolen funds and contacted law enforcement. Soon afterwards, General Manager Alex Shevchenko publicly told the suspected exploiter that the team knew who they were.

Crypto exploits rarely come with full refunds. This one did.

What Happened to NEAR Intents?

The incident began on October 1, 2026, when NEAR Intents detected unusual activity involving its cross-chain infrastructure. The protocol allows users to swap assets across different blockchains without manually moving through several bridges and exchanges.

According to the team, the attacker exploited a bug involving the interaction between its Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. The issue affected USDT on BNB Chain and resulted in roughly $3.8 million in user funds being withdrawn improperly.

NEAR Intents paused services while it investigated the incident. Crypto.news reported that the team identified and patched the vulnerability within about an hour of detecting the abnormal activity.

The incident was significant, but it is important to be precise about what was compromised.

The NEAR Blockchain Itself Was Not Hacked

The exploit did not compromise the NEAR blockchain itself. The vulnerability affected infrastructure operated by NEAR Intents rather than the core NEAR Protocol.

NEAR co-founder Illia Polosukhin said the NEAR token, the underlying blockchain and other NEAR applications were not affected. That distinction matters because describing the event simply as a “NEAR hack” could give readers the impression that the entire network had been breached.

A more accurate description is that NEAR Intents suffered a $3.8 million exploit involving its cross-chain deposit and withdrawal infrastructure.

Users Were Promised Full Compensation

When the incident was first disclosed, there was no guarantee that the stolen funds would ever be recovered. Even so, NEAR Intents said affected users would be fully compensated.

The Block reported that the team had committed to making users whole while investigators traced the missing assets. Law enforcement was also contacted as part of the response.

That promise came before the exploiter returned the money, meaning the protocol had already accepted responsibility for covering the losses if recovery efforts failed.

Fortunately for NEAR Intents, they did not.

Investigators Followed the Money

Blockchain investigator ZachXBT helped trace the movement of the stolen assets after the exploit. According to reports, the funds were transferred through KuCoin before eventually being moved into Bitcoin.

Cointelegraph reported that investigators were able to follow the transactions as the assets moved across different services and blockchains.

Moving crypto between chains can make investigations more complicated, but it does not necessarily make the funds invisible. Public blockchains create transaction records that investigators can analyse, particularly when funds eventually interact with centralised exchanges.

That became increasingly important as the investigation progressed.

“We Have Identified You, Sir”

On October 2, Shevchenko publicly addressed the person believed to be responsible for the exploit.

His message was unusually direct:

“We have identified you, sir.”

He then published addresses where Bitcoin, BNB and Solana could be returned and gave the exploiter 48 hours to cooperate. Cointelegraph reported that Shevchenko presented the deadline as a final opportunity to resolve the incident through cooperation rather than continue pursuing the case.

The message was essentially simple: the team believed it knew who was responsible, law enforcement had already been involved, and the exploiter now had two days to return the money.

That is probably not the message anyone wants to receive after moving $3.8 million.

The Exploiter Appeared to Respond

Shortly after the ultimatum was issued, wallets linked to the exploit appeared to begin communicating with NEAR Intents.

Reports said one address sent 1 BNB to a recovery wallet and included a request for a Signal contact. A smaller Ethereum transaction reportedly carried a similar message, suggesting that the person controlling the funds was willing to negotiate.

Then the situation changed completely.

The money came back.

The Full $3.8 Million Was Returned

NEAR Intents later confirmed that the entire estimated $3.8 million had been returned.

Cointelegraph reported that the recovery took place after the ultimatum was issued but before the full 48-hour period had expired.

Decrypt also reported that an on-chain message apparently linked to the exploiter acknowledged wrongdoing and encouraged security researchers to use bug bounty programmes instead of disrupting services.

After the funds were returned, Shevchenko said the investigation would be stopped.

For users affected by the incident, the outcome was about as favourable as a multimillion-dollar exploit could realistically become.

Why Would an Exploiter Return $3.8 Million?

The full reasoning of the person responsible has not been made public, but the pressure around the case had increased quickly.

NEAR Intents said it had identified the exploiter. Law enforcement had been contacted. Blockchain investigators were tracing the movement of the funds, and some of those funds had reportedly passed through a centralised exchange.

That combination can dramatically change an attacker’s risk calculation.

Crypto wallets are often described as anonymous, but pseudonymous is usually the more accurate word. A wallet address may not display someone’s real name, but transactions remain public and can sometimes be connected to services that collect identity information.

Once someone believes investigators know who they are, holding on to stolen crypto can become considerably less attractive.

What Does Responsible Disclosure Mean?

Shevchenko described the offer as an opportunity for responsible disclosure, although that term normally refers to a very different process.

Responsible disclosure usually happens when a security researcher discovers a vulnerability and privately reports it to a company before anyone loses money. The company then fixes the bug and may reward the researcher through a bug bounty programme.

Exploiting a vulnerability and taking millions of dollars is not the normal definition of responsible disclosure.

Still, NEAR Intents appears to have offered the exploiter a final route toward cooperation. After the recovery, the team again encouraged researchers to use bug bounty programmes rather than exploiting weaknesses.

That makes sense financially too. A large bug bounty can look expensive until the alternative is a multimillion-dollar security incident.

NEAR Intents Had Just Helped Stop Bitget-Linked Funds

The timing of the exploit is particularly interesting because NEAR Intents had been dealing with suspicious funds only days earlier.

The protocol said its SHIELD security system had detected more than $50 million in attempted swaps linked to wallets associated with the Bitget hack. CoinDesk reported that most of those attempted transactions were blocked.

About $503,000 was frozen, while roughly $166,000 reportedly passed through before restrictions were applied.

Two days later, NEAR Intents was responding to a security incident of its own.

Crypto security can be humbling.

What Is NEAR Intents?

For beginners, NEAR Intents is designed to make swapping assets between different blockchains easier.

Normally, someone who wants to move from one token on one network to another token on a different network may have to use bridges, switch networks, hold several gas tokens and search for liquidity.

NEAR Intents uses a different model. The user specifies the result they want, while market participants known as solvers compete to execute the transaction.

The NEAR Intents website describes the service as one-click cross-chain swapping with unified liquidity. The project says it has processed more than $30 billion in volume across 35 blockchains.

That scale also means security failures can become expensive very quickly.

What Was Actually Vulnerable?

Based on the team’s preliminary explanation, the vulnerability involved how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract.

The attacker found a way to use that interaction to withdraw funds improperly. NEAR Intents says its security monitoring system detected the abnormal behaviour, after which the team paused services and patched the affected contract.

A full technical post-mortem will still be important. A short incident summary can tell users where the problem occurred, but a detailed report should explain exactly how the flaw worked and what changes were made to prevent it from happening again.

That will ultimately matter more than the dramatic 48-hour ultimatum.

Does Getting the Money Back Mean the Problem Is Over?

Not entirely.

Recovering the funds is clearly a positive outcome, but the vulnerability still existed. A security failure matters even when the financial loss is later reversed.

The bigger questions are how the bug passed earlier reviews, why $3.8 million could be accessed through the affected infrastructure and whether the protocol’s monitoring systems could have stopped the withdrawal before the funds left.

NEAR Intents says the vulnerability has been fixed. The real test will be whether the new safeguards prevent a similar incident in the future.

The Incident Shows Why On-Chain Tracking Matters

This case also shows why blockchain transparency can sometimes work in favour of investigators.

Wallet addresses do not automatically reveal the real identity of the person controlling them, but blockchain transactions are public. Investigators can follow money as it moves between wallets, bridges, decentralised exchanges and centralised exchanges.

If stolen funds eventually reach a regulated exchange, investigators may gain another route toward identifying the person behind the transactions.

That does not mean every crypto theft can be solved. Many stolen assets are never recovered.

But attackers cannot always assume that moving funds across several blockchains makes them invisible.

In this case, NEAR Intents’ claim that it had identified the exploiter appears to have changed the situation dramatically.

A Rare Ending for a Crypto Exploit

Many crypto exploits end with funds disappearing permanently. Others result in only partial recovery, while some projects negotiate with attackers and allow them to keep part of the stolen money as a bounty.

The NEAR Intents incident ended differently.

The team said it had identified the exploiter, gave them 48 hours to cooperate and then recovered the entire estimated $3.8 million.

There has been no public indication that the person responsible was allowed to keep a large percentage of the funds.

For affected users, that is about as good an ending as a $3.8 million exploit can have.

Blockwisely Take

The most interesting part of this story is not that $3.8 million was stolen. Unfortunately, crypto exploits have become common enough that another multimillion-dollar incident is no longer surprising on its own.

What stands out is the response.

NEAR Intents detected the attack, paused services, patched the vulnerability, traced the funds and involved law enforcement. The team then said it had identified the exploiter and publicly gave them 48 hours to return the money.

The full amount came back before the deadline expired.

That does not turn the original vulnerability into a security success, but it does show the value of rapid detection, blockchain tracing and coordinated incident response.

Sometimes the strongest pressure on an exploiter may simply be convincing them that they are not as anonymous as they thought.

Frequently Asked Questions

How much was stolen from NEAR Intents?

NEAR Intents estimated that approximately $3.8 million was taken during the October 1, 2026 exploit.

Did NEAR Intents recover all the money?

Yes. The team said the entire estimated $3.8 million was returned.

Did the exploiter wait the full 48 hours?

No. Reports indicate the funds were returned after the ultimatum was issued but before the full deadline expired.

What caused the exploit?

NEAR Intents said the vulnerability involved the interaction between its Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract.

Was the NEAR blockchain hacked?

No. The incident affected NEAR Intents infrastructure. The core NEAR Protocol and the NEAR token were not compromised.

How was the money recovered?

NEAR Intents said it had identified the exploiter, provided recovery addresses and gave the person 48 hours to return the funds. The money was subsequently returned in full.

Where did the stolen funds go?

Investigators reported that the assets moved through KuCoin before being converted or bridged into Bitcoin.

What is NEAR Intents?

NEAR Intents is a cross-chain trading system that allows users to specify the transaction outcome they want while competing solvers handle the execution.

Henry Murangiri
About the author

Henry Murangiri

Co-Founder of Blockwisely

Crypto Trader | Blockchain Researcher | Blockchain Developer

Share:
About Author

Henry Murangiri

Crypto Trader | Blockchain Researcher | Blockchain Developer

Leave a Reply

Your email address will not be published. Required fields are marked *

ETHSafari