exploit
NEAR Intents recovers full $3.8M after 48-hour ultimatum to exploiter
General Manager Alex Shevchenko issued a public 48-hour deadline on X; the attacker returned the funds and NEAR Intents closed its investigation on October 4.
NEAR Intents said on October 4 that the attacker who drained roughly $3.8M USDT from its BNB Chain treasury on October 1 has returned the funds in full, and the team has closed its investigation. The reversal followed a 48-hour public ultimatum from General Manager Alex Shevchenko on X and marks one of the few 2026 exploits to recover 100% of stolen assets back to the protocol, Crypto Briefing reported.
How the recovery played out
On October 2, Shevchenko posted on X that the team had identified the suspected exploiter, with the quote "We have identified you, sir" circulating across coverage, and gave the attacker 48 hours to send the funds back or face legal referral, Cointelegraph reported. The exploiter complied within the window. According to Shevchenko's statement, "the funds from the $3.8M NEAR Intents hack were sent back in full." Blockchain investigator ZachXBT earlier traced the stolen USDT through KuCoin and a bridge into Bitcoin before the return.
Context — what the exploit was
The original drain, covered on this site on October 1, exploited a bug at the junction between the Omni deposit and withdrawal layer and the NEAR Intents smart contract on BNB Chain. Deposits and withdrawals were paused across 11 networks, including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, Scroll and Plasma. Core intent-matching resumed within about an hour; the contract-side patch landed the same day.
Why "voluntary return" is rarer than it sounds
Exploiters sometimes return funds in response to a public identity threat, but the 100% share seen here is unusual. The pattern — public identification plus a 48-hour window plus a bridge-and-exchange trail that is already in the hands of chain analytics — is the one that produces returns rather than negotiated bounties. NEAR Intents did not disclose whether the attacker's identity was escalated to law enforcement; Shevchenko said the matter is closed on the protocol's side.
Neither NEAR Intents nor Shevchenko has published the attacker's address or the recovery transaction hashes. Users who were affected by the October 1 pause were already slated for full reimbursement from protocol treasury; the recovery means that liability does not land on the treasury.
What to watch
- Whether NEAR Intents publishes the attacker's address and the return transaction hashes alongside its promised full post-mortem.
- Whether the exploit's Omni deposit/withdrawal interaction bug has been audited by a third party before the paused chain integrations are fully reopened to deposits.
- Whether other intent-based bridges (Across, UniswapX, deBridge DLN) adopt the same patch class if the vulnerability is architectural rather than implementation-specific.
- Whether KuCoin discloses how the funds moved on and off its platform, given ZachXBT's trace placed them there mid-flow.
Pattern
The recovery closes a short exploit cycle — October 1 drain, October 2 ultimatum, October 4 return — that compresses what has become the standard 2026 bridge-incident timeline. For a year in which Chainalysis has already pinned over $1B in DPRK-linked theft and Q3 crypto hack totals cleared $1.26B, a clean 100% recovery on a nine-figure-adjacent bug is the exception, not the trajectory.