BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

Attacker Returns Funds After NEAR Intents Issues 48-Hour Recovery Deadline

TLDR General Manager Alex Shevchenko of NEAR Intents announced the complete recovery of approximately $3.8 million stolen during an October 1 security breach. A vulnerability was discovered i

AnonymousCryptoCompass newsroom
October 3, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

TLDR

  • General Manager Alex Shevchenko of NEAR Intents announced the complete recovery of approximately $3.8 million stolen during an October 1 security breach.
  • A vulnerability was discovered in the interaction between NEAR Intents’ Omni deposit-withdrawal infrastructure and its underlying smart contract.
  • Operations were temporarily suspended across 11 blockchain networks, including BNB Chain, Polygon, TON, and Avalanche, as teams responded to the incident.
  • Blockchain forensics tracked the stolen assets moving through a BNB Chain hot wallet, the KuCoin exchange, and ultimately to a Bitcoin bridge.
  • NEAR Protocol’s main blockchain infrastructure and its native cryptocurrency remained unaffected throughout the incident.

NEAR Intents has successfully recovered the entire $3.8 million taken during a security breach that occurred on October 1. The protocol’s General Manager, Alex Shevchenko, announced the complete fund recovery following an intensive 48-hour period after the attack.

Before the assets were returned, the protocol had publicly committed to compensating all impacted users in full. Consequently, the fund recovery primarily impacts NEAR Intents’ internal finances rather than representing an outstanding liability to its user base.

Technical Breakdown of the Vulnerability

The security flaw originated from a defect in the way NEAR Intents’ Omni deposit-withdrawal system communicated with its smart contract infrastructure. Technical analysis identified the vulnerability on the contract layer itself.

Illia Polosukhin, co-founder of NEAR Protocol, clarified that the exploit specifically targeted USDT tokens on the Binance Smart Chain. He noted that SHIELD, the platform’s artificial intelligence-powered security monitoring system, detected the suspicious transactions and automatically implemented protective measures.

Development teams deployed a patch addressing the contract vulnerability approximately one hour after detection. However, as a precautionary measure, deposit and withdrawal functionality remained disabled across multiple networks for nearly 12 additional hours while comprehensive security audits were completed.

The temporary suspension impacted 11 blockchain ecosystems: BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, Scroll, and Plasma. NEAR Protocol emphasized that its foundational blockchain architecture and native digital asset were never compromised during the security event.

Following the Digital Money Trail

Blockchain security analysts traced the suspicious transactions back to infrastructure connected with the HOT Bridge treasury on BNB Chain. Security researcher ZachXBT separately identified anomalous fund movements originating from a BNB Chain address associated with NEAR Intents.

Forensic analysis revealed the stolen assets were routed through the KuCoin cryptocurrency exchange before being converted and transferred via a bridge to the Bitcoin network. Available evidence indicates the NEAR blockchain’s core infrastructure was never directly compromised.

Throughout the recovery operation, the wallet controlling the stolen funds transmitted small quantities of ETH and BNB tokens to a designated recovery address. Each transaction contained embedded messages requesting Signal communication channel information.

Shevchenko subsequently published three distinct recovery wallet addresses for Bitcoin, BNB Chain, and Solana respectively. He established a 48-hour ultimatum for the suspected perpetrator to voluntarily return the misappropriated funds.

In his public statement, Shevchenko declared, “We have identified you, sir,” characterizing the deadline as a limited opportunity for responsible disclosure. He has not revealed the alleged perpetrator’s identity or shared documentation supporting the claimed identification.

By October 2, the Bitcoin recovery wallet had received approximately 34.59 BTC. Complete fund restitution across all three designated addresses was verified shortly thereafter.

NEAR Intents filed formal reports with law enforcement agencies and collaborated with cybersecurity specialists to track the stolen digital assets. While a comprehensive incident analysis has been announced, it remains unpublished at this time.

Polosukhin identified an emerging trend of cyberattacks leveraging artificial intelligence capabilities, citing Bitget, MetaMask, and Lido as additional recent victims. MetaMask verified a separate infrastructure breach on October 1, while Lido acknowledged a security compromise affecting its Ethereum validation infrastructure.

Bitget continues addressing the consequences of a $387 million security breach from September 24, with investigators tracking laundered funds through CoW Protocol and Chainflip. NEAR Intents characterized this as its first significant security incident since platform inception, noting the service currently processes over $4 billion monthly.

According to the most recent communications, NEAR Intents has verified the complete $3.8 million recovery and restored the majority of services across all previously affected blockchain networks.

The post Attacker Returns Funds After NEAR Intents Issues 48-Hour Recovery Deadline appeared first on Blockonomi.