Newsroom
3 October, 2026 / News / AI / Tags: intents, shevchenko, polosukhin, bug, alex

Cross-chain protocol ends probe following rapid identification of the exploiter and successful private talks that secured complete restitution within two days
NEAR Intents has recovered the entire $3.8 million taken in an exploit after the individual responsible returned the assets in full. The cross-chain platform confirmed the return on Friday and closed its investigation, marking one of the quicker resolutions among recent cryptocurrency security incidents.
The incident began on October 1 when a vulnerability in the Omni deposit-and-withdrawal infrastructure allowed the attacker to drain approximately $3.8 million in USDT on the BNB Smart Chain. The bug involved how that system interacted with the NEAR Intents smart contract. The platform’s AI security layer, known as SHIELD, detected unusual activity and prompted an immediate halt of services lasting roughly one hour while the issue was addressed.
Repairs to the contract were completed quickly. Operations on several networks, including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma, stayed restricted for about 12 additional hours until full Omni fixes were finished. The core NEAR Protocol and its native token remained untouched throughout. Co-founder Illia Polosukhin stated that the damage was limited to USDT on BNB Smart Chain and that neither the main blockchain nor other applications on the network were affected.
NEAR Intents had already promised users complete reimbursement. The platform processes significant volume across dozens of blockchains and described this as its first major security event of this scale.
By the following day, Alex Shevchenko, general manager of NEAR Intents and co-founder of Aurora Labs, announced that the team had identified the attacker. He publicly shared Bitcoin, BNB and Solana wallet addresses and set a 48-hour deadline for the return of the funds.
Shevchenko later opened a private communication channel. Messages were arranged so they could be decrypted using the private key associated with a specific Ethereum address. The attacker responded and indicated a willingness to cooperate. Shortly afterward, Shevchenko confirmed that the full amount had been returned.
Polosukhin reinforced the message, urging security researchers to use established bug bounty programs rather than exploiting live systems.
The identity of the individual has not been disclosed publicly. The platform also reported the matter to law enforcement and continued working with security partners during the tracing phase before the funds came back.
Complete recoveries remain relatively uncommon. Comparable cases include the Euler Finance exploit in 2023, where negotiations led to the return of the majority of the $197 million taken, and a 2025 GMX incident in which the exploiter returned roughly $37.5 million after accepting a bounty. In another recent event, attackers returned about 85 percent of funds from a large Liquid Network breach within 24 hours.
Industry-wide losses from hacks rose sharply in the third quarter, climbing from $86 million at the end of June to $742 million by the end of September. Larger incidents in the same period included a Bitget breach of approximately $388 million, of which only a small portion was frozen, and other attacks targeting infrastructure providers. Polosukhin noted that attackers appear to be employing more advanced techniques, including AI tools, and called for stronger on-chain standards and off-chain monitoring across the sector.
NEAR Intents itself had previously blocked more than $50 million linked to the Bitget incident and frozen roughly $503,000 through its risk systems. Shevchenko had publicly criticized infrastructure that facilitates movement of stolen assets while the industry seeks broader legitimacy for digital assets.
Despite the full recovery of funds, the NEAR token continued to trade lower in the days after the incident. Reports indicated declines ranging from around 5 percent to as much as 16 percent in various windows, with the price breaking below certain technical support levels amid wider market softness. The restitution itself did not produce an immediate positive price response.
The rapid identification, direct outreach and complete return of assets distinguish the NEAR Intents case from many other recent exploits. The platform has resumed normal operations and reiterated its preference for formal bug bounty channels going forward.









