NEAR Intents Recovers Full $3.8M After Exploit, Closes Investigation
NEAR Intents has recovered the full $3.8 million stolen in an exploit, less than a day after disclosing the incident, and has officially closed its investigation.
According to NEAR Intents CEO Alex Shevchenko, the entire amount was returned on October 2, 2026. The team also urged security researchers to use its bug bounty program rather than actions that could disrupt services.
The incident occurred between September 30 and October 1 due to a vulnerability involving the interaction between Omni’s deposit and withdrawal infrastructure and NEAR Intents’ smart contracts. The flaw allowed the attacker to withdraw approximately $3.865 million in USDT from a vault on BNB Chain across multiple transactions.
NEAR Intents’ AI-powered SHIELD security system detected the suspicious activity, allowing the team to pause services and patch the vulnerability within roughly an hour. The team had previously pledged to fully reimburse affected users.
Illia Polosukhin, co-founder of NEAR Protocol, said the team identified the party involved in less than 24 hours through a combination of SHIELD and investigative work. Contact was established, and the full amount was returned at around 14:30 UTC on October 2, well ahead of the 48-hour deadline previously issued by Shevchenko.
The party that returned the funds also left an on-chain message acknowledging the repayment, thanking the NEAR team for its handling of the incident and reiterating the importance of using bug bounty programs.
Polosukhin emphasized that privacy is a fundamental right but should not be used to conceal illicit activity. He added that NEAR is strengthening its security infrastructure as AI could accelerate increasingly sophisticated cyberattacks.
The NEAR Protocol and $NEAR token were not affected by the incident.
NEAR Intents has recovered the full $3.8 million stolen in an exploit, less than a day after disclosing the incident, and has officially closed its investigation.
According to NEAR Intents CEO Alex Shevchenko, the entire amount was returned on October 2, 2026. The team also urged security researchers to use its bug bounty program rather than actions that could disrupt services.
The incident occurred between September 30 and October 1 due to a vulnerability involving the interaction between Omni’s deposit and withdrawal infrastructure and NEAR Intents’ smart contracts. The flaw allowed the attacker to withdraw approximately $3.865 million in USDT from a vault on BNB Chain across multiple transactions.
NEAR Intents’ AI-powered SHIELD security system detected the suspicious activity, allowing the team to pause services and patch the vulnerability within roughly an hour. The team had previously pledged to fully reimburse affected users.
Illia Polosukhin, co-founder of NEAR Protocol, said the team identified the party involved in less than 24 hours through a combination of SHIELD and investigative work. Contact was established, and the full amount was returned at around 14:30 UTC on October 2, well ahead of the 48-hour deadline previously issued by Shevchenko.
The party that returned the funds also left an on-chain message acknowledging the repayment, thanking the NEAR team for its handling of the incident and reiterating the importance of using bug bounty programs.
Polosukhin emphasized that privacy is a fundamental right but should not be used to conceal illicit activity. He added that NEAR is strengthening its security infrastructure as AI could accelerate increasingly sophisticated cyberattacks.
The NEAR Protocol and $NEAR token were not affected by the incident.
