NEAR Intents recovers $3.8 million from exploit and closes its investigation
The suspected exploiter reportedly returned the full amount after a 48-hour ultimatum from the cross-chain protocol
NEAR Intents got its money back. The suspected entity behind an exploit that drained approximately $3.8 million in USDT from the cross-chain trading and settlement protocol has reportedly returned the full amount.
The protocol wrapped up its investigation on October 4.
How the exploit unfolded
Between September 30 and October 1, 2026, a critical bug in the protocol’s smart contracts gave an attacker an opening. The attacker used it to pull USDT out of a treasury contract on BNB Chain.
The drain did not happen in one shot. It came through multiple withdrawals spread over the two days, adding up to approximately $3.87 million USDT.
The protocol’s SHIELD AI security layer flagged the activity. NEAR Intents then paused its services and patched the vulnerability within an hour.
The 48-hour ultimatum
General Manager Alex Shevchenko said the team had identified the suspected exploiter. On October 2, Shevchenko issued a 48-hour deadline for the funds to be returned. He also published specific return addresses across BTC, EVM and Solana.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
The suspected entity reportedly returned the full $3.8 million, and NEAR Intents closed its investigation on October 4.
Separately, NEAR Intents committed to compensating users affected by the incident.
The cleanup took longer than the patch
Deposits and withdrawals on 11 networks, including BSC and Polygon, stayed paused for around 12 hours. The protocol used that time to repair infrastructure after the exploit. After the fixes, NEAR Intents resumed operations on the affected networks.
A tough week for a protocol that was just being praised
Just days before its own exploit, NEAR Intents had blocked fund transfers linked to a separate hack of the Bitget exchange. It reportedly stopped nearly $50 million from that incident, freezing $503,000 in attempted transactions.
What this means for cross-chain protocols
The weak spot was a treasury contract on BNB Chain. The breadth of the follow-up pause, covering 11 networks, shows how one bug can ripple through a system built to connect many chains.
A critical contract bug made it into production and cost the treasury approximately $3.87 million USDT before anyone stepped in. The flaw was caught by NEAR Intents’ own tooling, patched within an hour, and the funds came back within days after the protocol publicly stated it had identified the suspected exploiter and set a firm deadline.