On October 3, NEAR Intents’ CEO Alex Shevchenko announced that the previously stolen $3.8 million had been fully returned, and the team stopped its investigation. The whole incident is worth reviewing in terms of its timeline: the issue occurred due to an error in the interaction between Omni’s withdrawal infrastructure for deposits and NEAR Intents’ smart contracts. The platform first paused services and promised full reimbursement for affected users; then on-chain analysis traced the flow of funds, identified the attacker entity, and issued a final 48-hour ultimatum under “responsible disclosure.” Ultimately, the funds were returned, and Shevchenko publicly urged people to pursue bug bounties instead of launching direct attacks.
As for the actual impact on $NEAR , I think it has two layers. The first layer is direct: the $3.8 million does not constitute a financial shock to its market value, and user compensation is in place—there’s no reason for short-term panic selling. The second, more important layer is that this exposed not the security of NEAR Intents’ own contracts, but the interface risk of a cross-system combination (deposit bridge + intent layer). The value proposition of the Intents track is “users don’t need to worry about how the underlying execution works.” The trade-off is that once errors happen in these boundary areas, responsibility can become unclear.
What’s truly worth tracking is what happens next. This time it ended smoothly through cooperation from the attacker—luck. If a similar vulnerability shows up again and the other party doesn’t cooperate, there’s no safety net. Whether the platform publicly shares a fix for the interface layer matters far more than the $3.8 million itself.
Will you reduce your position in the Intents track because of events like this, or treat it as a one-off accident?
#NEARIntentsRecovered$3.8MillionEndingInvestigation
As for the actual impact on $NEAR , I think it has two layers. The first layer is direct: the $3.8 million does not constitute a financial shock to its market value, and user compensation is in place—there’s no reason for short-term panic selling. The second, more important layer is that this exposed not the security of NEAR Intents’ own contracts, but the interface risk of a cross-system combination (deposit bridge + intent layer). The value proposition of the Intents track is “users don’t need to worry about how the underlying execution works.” The trade-off is that once errors happen in these boundary areas, responsibility can become unclear.
What’s truly worth tracking is what happens next. This time it ended smoothly through cooperation from the attacker—luck. If a similar vulnerability shows up again and the other party doesn’t cooperate, there’s no safety net. Whether the platform publicly shares a fix for the interface layer matters far more than the $3.8 million itself.
Will you reduce your position in the Intents track because of events like this, or treat it as a one-off accident?
#NEARIntentsRecovered$3.8MillionEndingInvestigation