NEAR Intents lost $3.8 million on October 1. It got every dollar back by October 4.

A bug where its Omni deposit and withdrawal layer talked to the protocol's smart contract let an attacker drain roughly $3.87 million in USDT from a treasury contract on BNB Chain across September 30 and October 1, per KuCoin's reporting. The protocol's own SHIELD anomaly system flagged the outflow. Services froze, the contract was patched within about an hour, and deposits stayed restricted on 11 networks for roughly 12 hours while the rest of the fix shipped. ZachXBT traced the money through a BNB Chain hot wallet to KuCoin, where it was swapped into bitcoin.

Then general manager Alex Shevchenko went public. He named the suspected exploiter, posted return addresses, and set a 48-hour deadline framed as a last shot at responsible disclosure. The full $3.8 million came back. The attacker attached an on-chain note admitting fault. Shevchenko closed the investigation, asked hackers to use bug bounties instead, and committed to reimbursing any affected users.

The twist worth your attention: two days before its own treasury was drained, Intents' SHIELD system had blocked more than $50 million in transfers tied to the $387.5 million Bitget hack, with Shevchenko waiving the bounty so Bitget could recover more, according to Cointelegraph. A protocol that stopped someone else's stolen money, then got robbed itself, then got it all back.

The lesson is not that audited code is safe. It is that incident response is the real security product. The protocols that survive exploits are the ones that detect, freeze, negotiate, and recover faster than the attacker can cash out. $NEAR