NEAR Intents says it has recovered the full roughly $3.8 million taken in an exploit disclosed a day earlier, marking an unusually quick reported resolution to a cross-network security incident. General manager Alex Shevchenko said on Oct. 2 that all of the funds had been returned and that the project was ending its investigation.
The recovery claim comes after NEAR Intents paused parts of its service while it addressed the vulnerability and traced the assets. The amount and return have been reported by the project and subsequent coverage; the available accounts do not provide an independent, public audit of the recovery process.
NEAR Intents reports full recovery
Shevchenko announced the result in a post on X on Oct. 2, saying the approximately $3.8 million removed in the incident had been returned in full and that the investigation would stop. The statement followed the Oct. 1 disclosure of the exploit.
The turnaround matters because stolen crypto assets are often moved through several venues or converted into other assets before a victim can identify a route for recovery. In this case, NEAR Intents said it was able to identify the attacker and direct them toward a responsible-disclosure process, according to Decrypt.
Neither Shevchenko's announcement nor the supplied reporting details a negotiated settlement, a bounty amount, or the exact mechanism by which the assets were returned. The public record described in the reports instead centers on the project’s tracing work and a deadline issued to the person behind the exploit.
Omni infrastructure and contract bug
The exploit was attributed to a bug in the interaction between Omni’s deposit-and-withdrawal infrastructure and a NEAR Intents smart contract, The Block reported on Oct. 1. That description places the issue at the point where the infrastructure handling deposits and withdrawals interacted with the contract used by NEAR Intents, rather than identifying a broader failure across every system connected to the project.
NEAR Intents temporarily paused services and restricted deposits and withdrawals across multiple networks as it patched the contract vulnerability and followed the funds, according to CoinDesk. Those measures limited activity during the response, but the reporting does not specify when each restriction was lifted or provide a fuller technical post-mortem.
The distinction is important for users assessing the incident: a pause in deposits and withdrawals was part of the containment response, while the subsequent return of funds addressed the immediate loss. The available reports do not establish further details about the vulnerability beyond the interaction between Omni’s infrastructure and the NEAR Intents contract.
Fund trail and return deadline
Blockchain investigator ZachXBT reported that the assets moved from a BNB Chain hot wallet to KuCoin before being bridged into Bitcoin, CoinDesk said. The reported route illustrates why the response involved both contract remediation and asset tracing across networks and venues.
After identifying the attacker, NEAR Intents gave them 48 hours to use a responsible-disclosure route. The funds were returned after that ultimatum, Decrypt reported, linking the project’s identification of the attacker and the deadline to the recovery.
Shevchenko’s Oct. 2 declaration that the investigation had ended therefore came shortly after the exploit was made public and after the reported return of the full amount. The project has not, in the supplied material, released a detailed public accounting of the returned assets or additional technical findings from the incident.