NEAR Intents Recovers Full $3.8 Million After 48-Hour Ultimatum to Exploiter
Key Takeaways
- •NEAR Intents recovered all $3.8 million stolen in the exploit after the identified attacker met a 48-hour return deadline set under a responsible-disclosure arrangement.
- •The breach originated from a flaw in the platform's Omni deposit and withdrawal infrastructure and smart contract, leading to a service suspension that disrupted transfers across multiple connected networks.
- •On-chain analysis traced approximately $3.87 million in USDT withdrawn from a vault on BNB Chain, with much of the amount converted to Bitcoin and a portion routed to deposit addresses linked to KuCoin.
- •The team patched the affected contract, engaged law enforcement and blockchain analytics firms, and committed to fully compensating affected users.
- •A BNB Chain transaction containing a message from the address labeled as the exploiter corroborated the fund return, and NEAR Intents has since concluded its investigation.

NEAR Intents has recovered the full $3.8 million stolen in a security exploit after identifying the alleged attacker and setting a 48-hour deadline for the funds to be returned. According to CoinDesk, the exploiter sent the assets back one day after the breach, closing out an unusual episode for the cross-chain trading platform. Full returns of exploited funds are uncommon in decentralized finance, where stolen assets are typically dispersed across wallets and services within hours of an attack.
The protocol suspended services after detecting a bug involving its Omni deposit and withdrawal infrastructure and its smart contract. The incident disrupted deposits and withdrawals across several connected networks, as covered in an earlier report. Because the platform routes trades across multiple blockchains, a flaw in shared deposit and withdrawal infrastructure can ripple across every network connected to it.
Smart Contract Flaw Behind the Breach
NEAR Intents said the exploit resulted in losses of approximately $3.8 million. Subsequent on-chain analysis placed the figure at roughly $3.87 million in USDT withdrawn from a vault on BNB Chain.
The stolen funds moved through a series of wallets and services. Blockchain tracking showed that much of the amount was converted into Bitcoin, while another portion reached deposit addresses linked to KuCoin. That kind of tracing is a core function of the blockchain analytics firms the team engaged during the investigation, and stolen assets that reach deposit addresses at centralized exchanges can be flagged to support law-enforcement action.
The team patched the affected contract and said it would fully compensate users. It also contacted law enforcement and blockchain analytics firms during the investigation, and stated that the vulnerability had been fixed as it worked to restore normal operations.
Ultimatum Precedes Full Recovery
On Oct. 2, general manager Alex Shevchenko said the team had identified the individual behind the attack and given the alleged exploiter 48 hours to return the assets under a responsible-disclosure arrangement. The funds were subsequently returned in full, according to Shevchenko. Deadlines of this kind have appeared in other crypto security incidents as a negotiated route to recovery once an attacker is identified.
A BNB Chain transaction associated with the recovery also contained a message from an address labeled as the NEAR Intents exploiter, corroborating the reported return.
NEAR Intents said it has stopped its investigation following the recovery. The episode underscores the risks that can arise when cross-chain infrastructure and smart contracts interact, even when a protocol is able to trace and recover stolen assets quickly. With the exploit resolved, the remaining open question for users is the pace of the platform's return to normal operations, including deposits and withdrawals on the networks affected by the suspension.