BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
DeFi

The NEAR Intents hacker gave it all back, and fast...

The attacker behind Thursday's $3.8 million exploit on @near_intents returned the stolen funds in full, and did so well ahead of the deadline set by the project's general manager, @AlexAurora

AnonymousCryptoCompass newsroom
October 2, 2026
2 min read
NEWS
The NEAR Intents hacker gave it all back, and fast...
CryptoCompass editorial visual for defi coverage.

The attacker behind Thursday's $3.8 million exploit on @near_intents returned the stolen funds in full, and did so well ahead of the deadline set by the project's general manager, @AlexAuroraDev.

A Quick Turnaround After a Public Ultimatum

@AlexAuroraDev announced the full return roughly 15 hours after issuing a public warning that the team had identified the attacker and was giving them 48 hours to send the money back. The announcement came through Shevchenko's personal account, which identifies him as general manager of NEAR Intents.

The exploit itself occurred on October 1, 2026. NEAR Intents suffered the loss after a bug in the interaction between its Omni deposit and withdrawal infrastructure and its smart contract enabled the loss of user funds.The attackers exploited the vulnerability to make unauthorized withdrawals from the platform's hot wallet on BNB Chain, then transferred the stolen assets to KuCoin and converted them into Bitcoin through cross-chain bridges.

NEAR Intents confirmed the exploit, closed the vulnerability, and halted deposits and withdrawals on eleven networks. The protocol also pledged to compensate all affected users in full from its treasury.

Investigation Closed, Bug Bounties Urged

Shevchenko said on October 2 that the team had identified the person responsible for the loss and gave that person 48 hours to return the funds, describing the deadline as the final chance to settle the matter under responsible disclosure. The attacker acted well within that window.

With the funds back, Shevchenko confirmed the team is ending its investigation. He used the moment to encourage security researchers and hackers to engage through official bug bounty programs rather than exploiting live protocols and disrupting services.

The incident added an unusual footnote to what has already been a difficult stretch for NEAR Intents. The exploit followed the protocol's assistance to Bitget after a separate security breach, in which Bitget reported a $388 million loss. NEAR Intents reported blocking $50 million and freezing more than $500,000 linked to that attack.

The rapid recovery will likely be watched closely across the DeFi space. If the pattern holds, public identification threats could become a standard recovery tool across DeFi.

Sources:NEAR Intents GM Says $3.8M Exploiter Identified, Sets 48-Hour Return Deadline – The Crypto TimesNEAR Intents Suffers $3.8M Exploit After Assistance With Bitget Breach – CoinTelegraphNEAR Intents Hit by $3.8M Exploit – CoinDesk