NEAR Intents GM Says $3.8 in Hack Funds Returned in Full, Ends Investigation
Key Takeaways
- •$NEAR Intents general manager Alex Shevchenko announced on Oct. 2 that all funds stolen in the roughly $3.8 million exploit had been returned in full and that the investigation was being ended.
- •The published Bitcoin recovery wallet received approximately 34.59 BTC, valued at about $2.95 million, while a shared Ethereum and $BNB Chain address received roughly 0.2953 ETH and 1 BNB.
- •The protocol attributed the Oct. 1 exploit to a bug in the interaction between its smart contract and the Omni infrastructure handling deposits and withdrawals, and said the contract-side vulnerability had been patched.
- •Deposits and withdrawals across 11 networks were temporarily halted for infrastructure fixes, and by Oct. 2 the status dashboard listed cross-chain infrastructure as operational although core services still showed a partial outage.
- •Shevchenko urged attackers to use bug bounty programs instead of disrupting services, and the team promised a detailed public report on the incident in the days ahead.

$NEAR Intents general manager Alex Shevchenko announced on Oct. 2 that the funds stolen in the protocol's roughly $3.8 million exploit had been returned in full, and that the team was ending its investigation.
The announcement came one day after the Oct. 1 incident, during which the protocol had pledged to fully compensate affected users. Shevchenko did not clarify whether that compensation had already been paid.
Recovery Wallets Receive Funds
The published Bitcoin recovery wallet received approximately 34.59 BTC on Oct. 2. Mempool valued the wallet's balance at about $2.95 million at the time of review. A shared Ethereum and $BNB Chain recovery address also received roughly 0.2953 ETH and 1 $BNB the same day.
Those receipts alone do not account for the entire preliminary loss estimate, and Shevchenko's announcement did not include an asset-by-asset reconciliation of the full recovery.
“We are stopping the investigation,” Shevchenko wrote. “Please use bug bounties instead of disrupting the services.”
Bug bounty programs pay security researchers to disclose vulnerabilities responsibly before they can be exploited — the channel Shevchenko pointed to in his message.
On the evening of Oct. 1 ET, Shevchenko had published three return addresses—for Bitcoin, Ethereum/$BNB Chain, and Solana—and given the recipient a 48-hour window to send the funds back. The Ethereum transfer carried an on-chain message that read: “Willing to cooperate, reply with your Signal so contact is possible.”
Cross-Chain Infrastructure Back Online
$NEAR Intents attributed the incident to a bug in the interaction between its smart contract and the Omni infrastructure that handles and withdrawals. In its Oct. 1 statement, the team said the contract-side vulnerability had been patched, but that deposits and withdrawals across 11 networks would remain unavailable for approximately another 12 hours while infrastructure fixes were completed.
Those deposit and withdrawal rails are how user funds move in and out of the protocol, so restoring them — not just patching the contract — is the step that lets normal cross-chain activity resume.
Shevchenko announced later that morning that near.com was back up. The app relies on $NEAR Intents to execute cross-chain swaps.
By Oct. 2, the protocol's status dashboard listed cross-chain infrastructure and integrated blockchains as operational, although core services still showed a partial outage—a narrower recovery than an all-services-clear notice.
The team's Oct. 1 statement also promised a detailed public report in the days ahead — the follow-up it pointed to for fuller detail on the incident — while the dashboard's core-services entry remains the live indicator of when the protocol returns to full operation.