Sat. Oct 3rd, 2026

NEAR Intents Says $3.8M Exploit Funds Were Returned in Full

ByJohan Shamshad

October 2, 2026 #NEAR Intents
Crypto Hack

NEAR Intents says the approximately $3.8 million taken in this week’s exploit has now been returned in full, transforming what began as a multi-chain asset-recovery operation into a much harder question about how the attacker was able to drain the system in the first place.

NEAR Intents General Manager Alex Shevchenko said late October 2 that all stolen funds had been returned and that the related investigation into the attacker would be halted. The recovery came only hours after he publicly said the team had identified the person responsible and gave them 48 hours to return the assets.

The return is supported in part by public blockchain activity. The Bitcoin recovery address published by Shevchenko received approximately 34.59 BTC, representing the largest component of the stolen assets after the attacker converted much of the haul into Bitcoin.

The rapid recovery materially changes the immediate financial impact of the NEAR Intents security incident. The team had already promised to compensate affected users in full, meaning the central question is no longer whether NEAR Intents will have to absorb the entire loss.

It is now how a wallet that began by testing the system with withdrawals worth only $10 and $11 was subsequently allowed to remove almost $3.9 million.

The Attacker Tested the Withdrawal Path Before Taking $3.865 Million

Blockchain intelligence firm Bitquery reconstructed the theft in an on-chain investigation covering activity across six chains.

Its analysis found that 3.865 million USDT left the BNB Chain vault used by NEAR Intents through five major withdrawals over roughly six hours.

Before taking meaningful amounts, however, the attacker appears to have tested the withdrawal mechanism twice.

A 10 USDT transaction occurred at 18:57 UTC on September 30, followed by another test for 11 USDT at 20:05 UTC. Both succeeded.

Nearly four hours after the first test, the first major withdrawal arrived: 800,000 USDT at 23:54 UTC. That was followed by 1.2 million USDT at 00:24 UTC and another 1.5 million USDT just 26 minutes later.

The wallet then received another 330,000 USDT at 01:46 UTC and a final 35,000 USDT at 06:08 UTC.

Those five large withdrawals total 3.865 million USDT.

Bitquery noted that the three largest withdrawals occurred inside roughly one hour. It also found that, during the two days preceding the theft, the vault’s largest individual stablecoin payout had been below $400,000.

That makes the escalation striking. A wallet moved from two transactions totaling $21 to individual withdrawals of $800,000, $1.2 million and $1.5 million without the sequence being stopped before most of the money had left.

Most of the Money Became Bitcoin, but Some Passed Through NEAR Intents Again

After leaving the vault, the stolen USDT was rapidly converted and distributed across new addresses.

Bitquery said it could account for approximately 99% of the stolen amount as of its October 1 analysis.

The largest share became Bitcoin. Around 34.69 BTC, representing roughly 76% of the stolen value at the transaction prices used in the investigation, eventually reached four Bitcoin wallets.

Approximately $802,000 also reached KuCoin deposit infrastructure through two routes. Only KuCoin can establish who controlled the accounts behind those deposits, and an exchange deposit does not by itself establish the identity of the attacker.

One of the stranger findings was that roughly $822,000 worth of the stolen assets was routed through NEAR Intents itself while the theft was unfolding.

That creates an uncomfortable contrast with NEAR Intents’ recent role in blocking suspected Bitget attacker funds. Its SHIELD risk system had recently rejected tens of millions of dollars in attempted flows associated with another major exploit, demonstrating that the platform can identify and restrict suspicious activity under some circumstances.

Yet during the attack on its own infrastructure, stolen assets were apparently able to use the same broader service as part of the exit route.

The Recovery Followed a Direct Ultimatum to the Attacker

The recovery process accelerated on October 2.

Shevchenko publicly said the team had identified the attacker and published Bitcoin, EVM and Solana addresses for returning the assets. He gave the person 48 hours to return the funds through what he described as a final responsible-disclosure window.

Later that day, an address tied to the exploit sent 1 BNB to the published recovery address with an on-chain message indicating willingness to cooperate and requesting contact through Signal.

The much larger repayment followed.

Shevchenko subsequently said all of the stolen funds had been returned. The published Bitcoin address received about 34.59 BTC, close to the 34.69 BTC Bitquery had previously traced into the attacker’s Bitcoin holdings.

The slight difference between those figures should not automatically be treated as an unrecovered shortfall. The attacker had moved value across several chains and services, while the “full return” statement concerns the total recovery rather than requiring the exact Bitcoin quantity identified at an earlier snapshot to arrive in one address.

The episode also demonstrates why cross-chain chokepoints can matter during recovery. During its tracing, Bitquery found that Chainflip had processed 17 attacker swaps before a broker rejected the next three, after which the attacker shifted routes. Dave Finances observed the same mechanism during the Bitget attacker’s attempts to move stolen assets.

Getting the Money Back Does Not Answer Why the Controls Failed

From a financial-loss perspective, a full return is about as good an outcome as NEAR Intents could have hoped for.

From a security perspective, it solves almost nothing.

The promised post-mortem now matters more than the recovery.

The first question is why the $10 and $11 test withdrawals did not create a meaningful signal. Tiny transactions followed by dramatically larger withdrawals are a familiar probing pattern in cyberattacks. A small transaction by itself is not suspicious, but the later acceleration should give investigators useful information about how withdrawal monitoring was configured.

The second question is how the system evaluated transaction size. Bitquery found that the vault’s largest stablecoin payout during the preceding two days had been below $400,000. The attacker then received $800,000, $1.2 million and $1.5 million in rapid succession.

That does not prove a specific risk limit should have blocked the transactions. NEAR Intents may legitimately process much larger transfers under normal conditions. But the post-mortem should explain what limits, anomaly detection, rate controls or authorization checks existed and why the sequence passed them.

The $822,000 NEAR Intents Route May Be the Hardest Question

The third issue is more awkward.

Why could assets taken from NEAR Intents infrastructure be routed back through NEAR Intents while the vault was being drained?

This matters because the platform had just demonstrated sophisticated transaction-screening capabilities during the Bitget incident. NEAR Intents said SHIELD had detected more than $50 million in attempted transfers associated with that attacker, rejecting most of them and freezing part of the remainder.

The two incidents may involve completely different detection layers. SHIELD can screen known malicious addresses based on existing intelligence, while preventing a brand-new exploit requires controls capable of recognizing abnormal behavior before an address has been labeled malicious.

That distinction would actually explain part of the apparent contradiction.

But it also highlights an important limitation of blockchain security systems. Blacklists and forensic intelligence work best after investigators know what they are looking for. A previously clean wallet exploiting a new bug may have several transactions of advantage before reputation-based controls catch up.

The Post-Mortem Should Matter More Than the Happy Ending

Crypto hacks increasingly end with some form of recovery, negotiation, asset freeze or bounty arrangement. That is good for users, but recovery should not become a substitute for explaining why the loss happened.

September alone produced $766.5 million in losses across 55 major incidents according to PeckShield’s monthly security tally. The more useful lessons from those incidents come from controls that prevent the next attacker, not from whether the current attacker eventually gives the money back.

NEAR Intents had already said it would publish a full post-mortem and review its security systems. That commitment is now the most consequential remaining part of the incident.

The report should establish the exact technical flaw in the interaction between the Omni deposit-and-withdrawal infrastructure and NEAR Intents contracts, when the team first detected abnormal activity, which controls evaluated the test and large withdrawals, why the final 35,000 USDT payment was still processed more than six hours after the first major withdrawal, and how stolen funds were able to use NEAR Intents itself during the attack.

Shevchenko’s statement that the attacker investigation is being halted after the funds were returned should also be separated from that technical review. There may be little reason to continue pursuing an asset-recovery investigation after restitution, but understanding the vulnerability is an entirely different task.

The recovery removes the immediate balance-sheet damage. It does not remove the engineering lesson.

In fact, the complete return may give NEAR Intents an unusually clean opportunity to publish it. There is no longer a need to frame every disclosure around locating missing assets or reassuring users that compensation will arrive.

The money is back. Now the more valuable question is how $21 in test withdrawals became $3.865 million before the system stopped paying.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *