NEAR Intents Hacker Returns Full $3.8 Million After Encrypted Negotiations
Key Takeaways
- •NEAR Intents suspended operations on Thursday after finding a flaw in the interaction between its Omni deposit and withdrawal infrastructure and its smart contract, with initial loss estimates of roughly $3.8 million.
- •Co-founder Illia Polosukhin confirmed the impact was limited to USDT on BNB Smart Chain, while the NEAR token, the core protocol, and other applications on the network were left untouched.
- •General manager Alex Shevchenko set a 48-hour deadline, published three wallet addresses on Bitcoin, BNB, and Solana, and negotiated through encrypted messages before the full $3.8 million was returned on Friday.
- •The protocol had committed to fully reimbursing affected users before the funds were recovered, and the distribution of reimbursements along with a fuller technical disclosure of the bug remain outstanding.
- •Prior to the exploit, NEAR Intents had rejected more than $50 million in funds tied to the September 24 Bitget breach and froze about $503,000 through its SHIELD risk system.

The attacker who drained $3.8 million from NEAR Intents has sent the entire amount back, ending a standoff that began a day earlier, when the cross protocol froze its services and set a 48-hour deadline for the funds to be returned. The protocol had already pledged full reimbursement to users before the money arrived, meaning affected users were set to be made whole even if the recovery effort had failed. The episode stands out as one of the few crypto hacking cases this year in which the stolen funds came back.
How the NEAR Intents exploit worked
In a post on X, NEAR Intents said it halted operations on Thursday after identifying what it called a bug in how its Omni deposit and withdrawal infrastructure interacted with its smart contract. The protocol's first estimate put user losses at roughly $3.8 million.
The protocol lets users state the outcome they want from a trade, after which independent market makers known as solvers take over execution. As a result, users never have to choose a bridge or exchange themselves. The platform has reportedly processed more than $30 billion in volume across 35 blockchains.
Co-founder Illia Polosukhin said the damage was limited to USDT on the BNB Smart Chain, adding that the NEAR token, the core protocol, and other applications on the network were untouched.
Even so, NEAR slipped about 6% in the hours after the news, trading near $4.95 before settling around $4.81. Cryptopolitan reported that eleven networks, among them BSC, Polygon, TON, and Scroll, remained restricted for roughly another 12 hours while repairs were completed.
Pressure on the perpetrator
By Friday, the team had moved from managing the aftermath to pursuing the attacker. General manager Alex Shevchenko posted three wallet addresses—one each for Bitcoin, BNB, and Solana—and told the perpetrator the clock was running. "We have identified you, sir," Shevchenko wrote on X, imposing a 48-hour deadline.
Following those warnings, Shevchenko opened a private channel to communicate with the hacker. He thanked the attacker "for your willingness to cooperate" and pointed to messages that could be decrypted with the private key from an Ethereum address, 0x09Fd1f5d9F185067A92493E43AA259ea4AB3ad37, so only whoever controlled that key could read them.
Shevchenko announced on Friday that the $3.8 million stolen in the hack had been returned in full. "We are stopping the investigation. Please use bug bounties instead of disrupting the services," he said. Bug bounty programs, which pay researchers who report vulnerabilities responsibly rather than exploiting them, are a standard security mechanism across major crypto protocols.
Prior red flags and industry context
Cryptopolitan reported that before the exploit and its resolution, NEAR Intents had turned away more than $50 million in funds tied to the September 24 Bitget breach, freezing about $503,000 of it through its SHIELD risk system. During that period, Shevchenko criticized crypto builders, saying they cannot operate infrastructure designed to "help launder stolen funds" while asking for the recognition of digital assets.
Full recoveries remain uncommon in the crypto industry, but NEAR Intents is not the first to achieve one. After what the project described as successful negotiations, the Euler Finance attacker returned the final $31 million of the $197 million hack that occurred in March 2023. Euler Finance ended up with more than $177 million in recovered assets. In July 2025, Cryptopolitan reported that the GMX exploiter returned about $37.5 million after accepting a 10% white-hat bounty. In each of those cases, as with NEAR Intents, direct communication between the project and the attacker preceded the return of funds. For NEAR Intents, the remaining open threads are the distribution of the pledged reimbursements and any fuller technical disclosure about the bug itself.