Short answer: NEAR Intents, a cross-chain swap protocol on the NEAR ecosystem, recovered the full $3.8 million drained in an October 1, 2026 exploit after giving the attacker a 48-hour ultimatum. About 34.59 BTC, worth roughly $2.95 million, came back on October 2, with the rest returned by another route, and the team closed its investigation. As of October 4, the promised technical post-mortem had not been published.
What happened
NEAR Intents lets users swap assets across blockchains by stating what they want and letting market makers fill the order. Decrypt reports it has handled more than $30 billion in swaps across 35 chains. The timeline of the incident:
- Thursday, October 1. An attacker drained about $3.8 million. The team blamed a bug in how its Omni deposit and withdrawal infrastructure interacted with the main NEAR Intents smart contract, paused services and pledged to compensate users in full.
- Same day. Investigator ZachXBT traced irregular outflows from the protocol's BNB Chain hot wallet; the funds moved to the KuCoin exchange and were bridged into Bitcoin.
- Ultimatum. General manager Alex Shevchenko posted Bitcoin, BNB/Ethereum and Solana return addresses, told the attacker the team had identified them, and set a 48-hour deadline running to October 4.
- Friday, October 2. Co-founder Illia Polosukhin said the funds were recovered in full at about 14:30 UTC. Between 14:31 and 15:05 UTC, the published Bitcoin address received 34.59 BTC.
- Afterwards. An on-chain message from an address labelled as the exploiter admitted wrongdoing and urged others to use bug bounties. Shevchenko said the investigation was closed.
How the $3.8 million came back
The Bitcoin return alone did not cover the loss. Blockchain researcher Kuncoro estimated the 34.59 BTC at about $2.95 million using a price of $85,200, and noted that the BNB/Ethereum address held only 1.04 BNB and 0.30 ETH, while the Solana address was empty. He concluded that about $850,000 was returned some other way; Shevchenko confirmed this without explaining how.
| Item | Figure |
|---|---|
| Amount drained on October 1 | About $3.8 million |
| Returned to the Bitcoin address | 34.59 BTC, about $2.95 million |
| Returned by another route | About $850,000 (researcher estimate) |
| Networks with paused deposits and withdrawals | 11, including BNB Chain, Polygon and Optimism |
| NEAR price on the day of the hack | Down 6.7% to $4.96 |
How the attacker was identified remains unclear. Polosukhin credited SHIELD, an AI security layer used by Intents, plus detective work; Shevchenko said only that an internal team did the tracing. Nobody has been named publicly.
Why the NEAR Intents exploit drew attention
The timing was awkward. Two days before the exploit, NEAR Intents blocked a $50 million swap attempt by the hacker behind the roughly $387.5 million Bitget breach, which Bitget and analytics firm Elliptic attribute to North Korea. There is no evidence the two incidents are linked. Bitwise's spot NEAR ETF had also started trading just days earlier and fell about 6% to 7% on the news.
The case fits a wider pattern: cross-chain infrastructure that pools funds across many networks remains one of the most attacked parts of crypto. A full recovery within about a day is unusual, but it depended on the attacker choosing to give the money back.
What it means for you
Users of NEAR Intents should not have lost funds, but the episode is a useful checklist for anyone moving assets between chains:
- Pauses hit specific networks. Deposits and withdrawals on 11 chains stayed offline for about 12 hours after the core service restarted. Check a service's status page before sending.
- Do not send to old deposit addresses. After a security incident, request a fresh address rather than reusing one from before the pause.
- Recovery is not guaranteed. Here the attacker returned funds; most bridge exploits end without a refund. A pledge to compensate depends on the operator's reserves.
- Watch for fake refund offers. Scammers often pose as support after hacks and ask for wallet connections or seed phrases.
Key takeaways
- NEAR Intents lost about $3.8 million on October 1, 2026, through an Omni infrastructure bug.
- The full amount was returned on October 2, including 34.59 BTC, after a 48-hour ultimatum.
- The team closed its investigation without naming the attacker or publishing a post-mortem.
- NEAR fell 6.7% to $4.96 on the day of the hack.
To understand why multi-chain systems are such frequent targets, read our explainer on cross-chain bridges and why they get hacked, and see how to avoid crypto scams that follow incidents like this one.
Frequently asked questions
Was the NEAR Intents hack money returned?
Yes. NEAR Intents says the full $3.8 million drained on October 1, 2026, was returned on October 2, including 34.59 BTC sent to a published Bitcoin address, and the team has closed its investigation.
What caused the NEAR Intents exploit?
The team said a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract let an attacker drain funds. The contract flaw was patched the same day; a detailed post-mortem has been promised but not yet released.
Is NEAR Intents safe to use after the exploit?
Core services resumed shortly after the October 1 pause, and deposits and withdrawals on 11 affected networks returned after roughly 12 hours. Users should check the service's status before sending funds and always request a fresh deposit address.