NEAR Intents GM addresses $3.865 million exploit tied to Omni bug
A flaw in the Omni deposit-and-withdrawal system drained USDT from a BNB Chain vault before the funds came back within days
NEAR Intents lost approximately $3.865 million in USDT to an exploit that straddled September 30 and October 1, 2026. Then, in a plot twist DeFi rarely gets, the money came back.
The attack traced to a bug in the Omni crosschain system. GM Alex Shevchenko publicly named the attacker, issued a 48-hour deadline, and recovered the full amount within 24 hours.
What broke, and how fast it got patched
NEAR Intents is a cross-chain trading and settlement protocol on the NEAR blockchain that lets users move and swap assets across multiple networks without manually routing every hop themselves.
The bug lived in the interaction between the Omni deposit-and-withdrawal system and the NEAR Intents smart contract.
The attacker pulled funds from a BNB Chain vault through five main withdrawals over roughly six hours.
Only USDT on BNB Smart Chain was affected, and the broader NEAR Protocol and its native token were not hit.
The team patched the flaw within an hour of detecting it. Services were then paused across 11 networks for about 12 more hours while remediation work continued.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The ultimatum that actually worked
The disclosure and service pause came on October 1. Shevchenko, the GM of NEAR Intents, publicly identified the attacker and set a 48-hour window for the funds to be returned. The full $3.865 million came back within 24 hours, with the return completed by October 2.
The attacker reportedly left a message along the way encouraging bug bounties.
NEAR Intents also promised full user compensation from treasury funds during the incident.
Illia Polosukhin, the co-founder of NEAR, was among the key figures involved as the situation unfolded.
What this means for users and the protocol
For users, the funds were recovered, the bug was patched within an hour of detection, and the team had already committed to covering losses from its treasury.
The public-identification tactic worked here, but it depends on having enough information to make that threat credible.
Things to watch from here include any detailed post-mortem on the Omni interaction bug and whether the 11 paused networks return to normal operations without further issues.