MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / DeFi / NEAR Intents Says Full $3.8M Recovered After Exploit
DeFi

NEAR Intents Says Full $3.8M Recovered After Exploit

By MABOnChain Desk · Published · Updated · 3 min read

Abstract illustration for NEAR Intents Says Full $3.8M Recovered After Exploit

Published October 5, 2026, 04:36 UTC. NEAR Intents has not yet published its full post-mortem.

NEAR Intents, a cross-chain swap service built on NEAR, says it has recovered the full $3.8 million taken in an exploit on Thursday, October 1. The attacker sent the funds back after the team said it had identified them and set a 48-hour deadline, according to Decrypt and Cointelegraph.

What went wrong

NEAR co-founder Illia Polosukhin said on October 1 that SHIELD, which he described as an AI-based security layer on Intents, detected "outlier behavior" and the service was temporarily paused, crypto.news reported. He said the attacker exploited a bug in how Omni's deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract, and that the affected asset was USDT on BSC.

Polosukhin said the team identified and fixed the flaw within an hour of detection, and that NEAR Intents and near.com came back online with some chains still restricted. He said the core NEAR Protocol, the NEAR token and other NEAR applications were not affected. He also pledged: "All of the affected users will be compensated in full."

The ultimatum and the return

General manager Alex Shevchenko then posted Bitcoin, BNB/Ethereum and Solana addresses for returning the funds and addressed the attacker directly: "We have identified you, sir." Decrypt reported that he framed it as a last chance at responsible disclosure, with a 48-hour window.

Shevchenko later wrote on X: "The funds from the $3.8M NEAR Intents hack were sent back in full. We are stopping the investigation." Decrypt said an on-chain message that appears to come from the exploiter read, "We've returned all the funds, we were in the wrong," and urged others to use bug bounties.

Before the return, blockchain investigator ZachXBT said the stolen funds had been sent to the KuCoin exchange and bridged to Bitcoin, according to both outlets. Decrypt said the team had also reported the incident to law enforcement.

What comes next

Polosukhin called this the first major exploit on Intents and said the team would run a full review and post-mortem. He said findings would feed into new security measures, alongside formal verification work for NEAR contracts. He put the service's monthly trading and payments volume above $4 billion, and Decrypt reported it has processed more than $30 billion in swaps across 35 blockchains, citing the service's data.

The team has not said how many users were affected or published a detailed transaction breakdown of the returned funds.

This article is news reporting and is not investment advice.

Sources

Related: Base Vault Loses $6M in wstETH After Whitelist Change · FlashLoop, GoldPesa, MALT: A Week of Smaller DeFi Exploits · How to Spot Crypto Scams: Seven Red Flags

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading