Tuesday, October 6, 2026
Industry / Security

NEAR Intents recovers all $3.8 million taken in exploit

A technician works on a server rack. File photo. Photo: Derrick Coetzee / Wikimedia Commons (CC0)

NEAR Intents lost $3.8 million in user funds to an exploit on October 1 and, within days, had all of it back. Cointelegraph reported that the attacker used a bug in the way the protocol's smart contract interacted with Omni deposit and withdrawal infrastructure.

The team said it identified the exploiter and set a deadline of 48 hours to return the money. General manager Alex Shevchenko later said on X that the funds had come back in full and that the investigation was closed.

Full recovery is unusual. Stolen crypto is usually moved quickly through exchanges and bridges and does not come back. In this case the trail was visible early. On-chain investigator ZachXBT had already traced the funds to KuCoin and to a bridge to Bitcoin before they were returned. An attacker who can be followed has less to gain from holding on.

The technical lesson is about seams. The flaw was not in either system on its own but in how the two connected, and connections of that kind are harder to test than a single contract. Reviews that look at components separately can miss them.

Closing the investigation does not close the questions for users. A published post-mortem, and an independent audit of the fix, would show whether the same kind of bug could appear elsewhere.

This story is reporting and analysis. It is not financial, legal or tax advice.