TLDR
- General Manager Alex Shevchenko announced that NEAR Intents successfully recovered approximately $3.8 million stolen during an October 1 security breach.
- The vulnerability existed in the connection between the platform’s Omni infrastructure for deposits and withdrawals and its underlying smart contract.
- Operations were suspended across 11 blockchain networks, including BNB Chain, Polygon, TON, and Avalanche, as the team responded to the incident.
- Investigators followed the stolen assets through a BNB Chain hot wallet, the KuCoin exchange, and finally to a Bitcoin bridge.
- NEAR’s main blockchain network and its native cryptocurrency remained uncompromised throughout the incident.
NEAR Intents has successfully recovered approximately $3.8 million that was stolen during a security breach on October 1. General Manager Alex Shevchenko announced the complete return of funds after issuing a 48-hour ultimatum to the exploiter.
Before the assets were returned, the protocol had already committed to reimbursing all affected users completely. This means the recovered funds primarily impact NEAR Intents’ internal finances rather than obligations to its customer base.
Breaking Down The Security Breach
The security flaw originated from an integration issue between NEAR Intents’ Omni infrastructureāwhich handles cross-chain deposits and withdrawalsāand its smart contract architecture. Specifically, the vulnerability was located within the contract itself.
Illia Polosukhin, co-founder of NEAR, explained that the exploit specifically targeted USDT on the BNB Smart Chain. He noted that the platform’s AI-powered security system, SHIELD, detected the suspicious transactions and automatically initiated a service pause.
The team deployed a patch to fix the contract weakness within approximately 60 minutes of discovery. However, as a precautionary measure, deposit and withdrawal functions remained disabled for nearly 12 additional hours across multiple chains while engineers implemented supplementary security measures.
The suspension affected 11 networks in total: BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, Scroll, and Plasma. Officials at NEAR Protocol emphasized that neither the main NEAR blockchain nor its native token were compromised during the exploit.
Following The Money Trail
Blockchain security analysts tracked the suspicious withdrawals to systems connected with the HOT Bridge treasury operating on BNB Chain. Security investigator ZachXBT identified unusual fund movements from a BNB Chain wallet associated with NEAR Intents’ operations.
The tracking revealed that the stolen assets first passed through KuCoin exchange before being converted and transferred to Bitcoin. All evidence indicates the NEAR Protocol’s base layer remained secure throughout the incident.
In an interesting development, the wallet controlling the stolen funds began sending small quantities of ETH and BNB to a designated recovery address. Each transaction contained embedded messages requesting Signal contact information for communication.
Shevchenko responded by publishing three distinct recovery wallet addressesāone for Bitcoin, another for BNB Chain, and a third for Solana. He established a 48-hour window for the individual behind the exploit to voluntarily return the stolen assets.
In his public statement, Shevchenko declared, “We have identified you, sir,” characterizing it as a narrowing opportunity for responsible disclosure. He has not disclosed the suspected individual’s identity publicly or provided supporting evidence of the identification.
By October 2, the Bitcoin recovery wallet had received approximately 34.59 BTC. Shortly thereafter, Shevchenko confirmed the complete return of funds across all three designated addresses.
NEAR Intents filed reports with law enforcement agencies and engaged multiple security firms to assist in asset recovery efforts. While a comprehensive post-incident analysis has been promised, it remains unpublished at this time.
Polosukhin highlighted an emerging trend of attacks leveraging artificial intelligence tools, citing recent security incidents at Bitget, MetaMask, and Lido as examples. MetaMask acknowledged a separate infrastructure breach also occurring on October 1, while Lido confirmed a security compromise affecting its Ethereum validator infrastructure.
Bitget continues to address the fallout from a massive $387 million hack on September 24, with the stolen funds laundered through CoW Protocol and Chainflip. NEAR Intents characterized this as the platform’s first significant security incident since launching, noting that it currently processes over $4 billion in monthly transaction volume.
According to the most recent announcement, NEAR Intents has recovered the entire $3.8 million and has restored service functionality across all previously affected blockchain networks.



