Read as article
NEAR Intents Gets All $3.8M Back After 48-Hour Ultimatum
By @sharedot · · 8 pages
- Crypto
- Near Intents
- Exploit
- Defi
NEAR Intents recovered the full $3.8 million stolen in its Omni exploit after issuing a 48-hour ultimatum.
What Happened
NEAR Intents general manager Alex Shevchenko announced that the roughly $3.8 million taken in the October 1 exploit was sent back in full, saying on X, 'We are stopping the investigation. Services had been halted after a bug in the Omni deposit and withdrawal infrastructure interacted with a NEAR Intents smart contract.
Why It's Surprising
The team deployed a contract patch within an hour of detection, committed to full reimbursement before the money came back, and still recovered everything. NEAR co-founder Illia Polosukhin said the platform's AI security layer, SHIELD, flagged outlier behavior and triggered the pause. He argued crypto is entering a period of more sophisticated attacks, citing recent AI-assisted incidents at Bitget, MetaMask and Lido.
The Evidence
The trail crossed infrastructure layers: initial analysis pointed to infrastructure associated with the HOT Bridge treasury on BNB Chain rather than the NEAR blockchain itself. Altcoin Buzz reports blockchain investigator ZachXBT identified abnormal outflows from a BNB Chain hot wallet tied to NEAR Intents, with assets moved through KuCoin and then bridged into Bitcoin. Midway through the response, the address moving the funds sent 0.295 ETH and later 1 BNB to a recovery wallet, both carrying messages requesting Shevchenko's Signal contact details.
The Ultimatum That Worked
Shevchenko's public post directly addressed the attacker with 'We have identified you, sir,' publishing three return addresses for Bitcoin, BNB Chain and Solana alongside a 48-hour deadline, and writing that the window for responsible disclosure would close after that. Altcoin Buzz notes the Bitcoin recovery address later received about 34.59 BTC. The reporting does not include direct on-chain verification of every arrival or explain how the other assets returned, and Shevchenko has not publicly named the attacker.
The Stakes
For users, the timing matters: the protocol had already pledged full compensation before the funds returned, so the recovery affects the protocol's balance sheet rather than any reimbursement owed. CryptoPotato reports the exploit was isolated to USDT on BSC and that the core NEAR blockchain and its native token were not affected, though NEAR traded down more than 5% in 24 hours. Deposits and withdrawals on 11 networks including BSC, Polygon, TON, Optimism, Avalanche, Stellar and Scroll were paused about 12 additional hours for Omni fixes.
What Comes Next
A fuller post-mortem has been promised but its publication was not confirmed in the available reporting, and the design failure that let the funds leave remains only partially explained. Polosukhin said NEAR plans to add formal verification to its contract release process and is inviting new SHIELD partners to share information faster, noting the platform now processes over $4 billion a month and that this was its first major exploit. investx.fr notes whether TVL holds will be the true measure of restored confidence.
Sources
- tradingview.com › NEAR Intents recovers entire stolen $3.8M after ultimatum to exploiter
- cryptoninjas.net › NEAR Intents Suffers $3.8M Omni Exploit, Promises Full Compensation After Service Halt
- cryptopotato.com › NEAR Intents Identifies $3.8M Hacker, Gives Them 48 Hours to Return Funds
- investx.fr › NEAR Intents $3.8M Hack: An Exemplary Crisis Response?
- altcoinbuzz.io › NEAR Intents $3.8 Million Exploit Funds Returned