
Hacker returned $3.8 million after a 48-hour recovery deadline.
A smart contract bug enabled the exploit on BNB Chain USDT.
NEAR Intents recovered funds and restored most affected services.
A tense 48-hour period has ended with an unexpected outcome for NEAR Intents. Roughly $3.8 million stolen during an October 1 exploit has been returned in full. The recovery followed intense blockchain tracking, public negotiations, and cooperation with security teams. While affected users had already received assurances of full reimbursement, the fund recovery marks a major win for the protocol and closes a dramatic chapter for one of the platform’s biggest security incidents.
https://twitter.com/AlexAuroraDev/status/2106049685928677585 How the Exploit Unfolded and Why Services Were Paused
The exploit originated from a bug linking NEAR Intents' Omni deposit and withdrawal infrastructure with a smart contract. Investigators identified the vulnerability on the contract side. The flaw allowed an attacker to target USDT activity on BNB Chain. According to NEAR co-founder Illia Polosukhin, the incident remained limited to USDT on BSC. A security system known as SHIELD detected unusual behavior and immediately triggered a platform pause.
That response helped contain further damage. Developers moved quickly after discovering the issue. The vulnerable contract received a patch within about an hour. Despite the rapid fix, several services remained offline for nearly 12 additional hours. Teams needed extra time to complete broader security checks and deploy more safeguards. Several networks experienced temporary disruptions.
Those networks included BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, Scroll, and Plasma. Throughout the incident, NEAR Protocol confirmed no impact on the main blockchain or the native NEAR token. The platform also reassured users that all losses would receive full reimbursement. That commitment came before any stolen funds returned.
Stolen Funds Traced Across Chains Before Full Recovery
Blockchain investigators followed the suspicious transactions soon after the exploit. Analysts linked unusual activity to infrastructure connected with the HOT Bridge treasury on BNB Chain. On-chain investigator ZachXBT also highlighted unexpected outflows from a wallet associated with NEAR Intents. Tracking data showed the stolen assets moving through KuCoin before reaching Bitcoin through a bridge.
Available findings did not indicate any breach involving the underlying NEAR blockchain. As recovery efforts intensified, the wallet controlling the assets began sending small amounts of ETH and BNB to a recovery address. Each transfer contained messages requesting contact details through Signal. Those transactions suggested possible communication between both sides.
GM Alex Shevchenko later published three recovery addresses covering Bitcoin, BNB Chain, and Solana. He also gave the suspected attacker a 48-hour window to return the assets voluntarily. The deadline appeared to work. By October 2, the Bitcoin recovery address had received around 34.59 BTC. Shortly afterward, recovery across all three addresses reached completion. NEAR Intents then confirmed the entire $3.8 million had been returned.
