NEAR Intents $3.8M Hack: From Incident to Full Refund, and the Spirit of White-Hat Security Is Celebrated
On October 1, 2026, the cross-chain interaction component NEAR Intents within the NEAR Protocol ecosystem was hacked, and about $3.8 million was stolen. The attacker exploited a logic flaw in the interaction between its Omni deposit-withdrawal layer and the main contract to carry out the theft. The project team promptly paused service to control the risk.
After the incident, Alex Shevchenko, the General Manager of NEAR Intents, responded quickly: he used on-chain analysis to identify the attacker and then posted a “final notice” on social media. He disclosed three refund addresses—Bitcoin, BNB/Ethereum, and Solana—and warned that this was the last window for leniency granted to the attacker through “responsible disclosure.”
Within less than 48 hours, the attacker submitted early and fully refunded the $3.8 million. Late on October 2, Shevchenko confirmed the funds had been returned and announced that the investigation had been stopped, while urging: “Please use the bug bounty program instead of interfering with services.”
This incident not only recovered the losses, but also became a positive case study for Web3 security: through technical deterrence and value-driven guidance, the project turned potential malicious attackers into ecosystem builders. It strengthened industry consensus that “white-hat hackers” who report vulnerabilities through proper channels should be rewarded, providing practical experience for the security evolution of Intent-centric architecture.
Keep looking—this is a clear reflection of the project team’s sincerity and capabilities.
$NEAR
On October 1, 2026, the cross-chain interaction component NEAR Intents within the NEAR Protocol ecosystem was hacked, and about $3.8 million was stolen. The attacker exploited a logic flaw in the interaction between its Omni deposit-withdrawal layer and the main contract to carry out the theft. The project team promptly paused service to control the risk.
After the incident, Alex Shevchenko, the General Manager of NEAR Intents, responded quickly: he used on-chain analysis to identify the attacker and then posted a “final notice” on social media. He disclosed three refund addresses—Bitcoin, BNB/Ethereum, and Solana—and warned that this was the last window for leniency granted to the attacker through “responsible disclosure.”
Within less than 48 hours, the attacker submitted early and fully refunded the $3.8 million. Late on October 2, Shevchenko confirmed the funds had been returned and announced that the investigation had been stopped, while urging: “Please use the bug bounty program instead of interfering with services.”
This incident not only recovered the losses, but also became a positive case study for Web3 security: through technical deterrence and value-driven guidance, the project turned potential malicious attackers into ecosystem builders. It strengthened industry consensus that “white-hat hackers” who report vulnerabilities through proper channels should be rewarded, providing practical experience for the security evolution of Intent-centric architecture.
Keep looking—this is a clear reflection of the project team’s sincerity and capabilities.
$NEAR
