The attacker who drained $3.8 million from NEAR Intents has sent every dollar back, ending a standoff that began a day earlier when the cross-chain protocol froze its services and set a 48-hour deadline for the funds to be returned.
The protocol had promised its users full reimbursement prior to the return. The incident is one of the few hacking cases the crypto industry has experienced this year that ended with the money coming back.
How did the NEAR Intents exploit work?
NEAR Intents posted on X that it had halted operations on Thursday after spotting what it called a bug in how its Omni deposit and withdrawal infrastructure interacted with its smart contract. The protocol’s first estimate put user losses at roughly $3.8 million.
The protocol works by letting its users state the outcome they want from a trade and having independent market makers called solvers take over from there. This way, users never have to pick a bridge or exchange themselves. The platform has reportedly handled more than $30 billion in volume across 35 blockchains.
Co-founder Illia Polosukhin said that the damage from the hack was limited to USDT on the BNB Smart Chain. The NEAR token, the core protocol, and other apps on the network were untouched.
Even so, NEAR slipped about 6% in the hours after the news, trading near $4.95 before settling around $4.81.
Cryptopolitan reported that eleven networks, among them BSC, Polygon, TON, and Scroll, stayed restricted for roughly another 12 hours while repairs finished.
By Friday, the team had moved on from simply dealing with the aftermath to pursuing the perpetrator. General manager Alex Shevchenko posted three wallet addresses, one each for Bitcoin, BNB, and Solana, and told the attacker the clock was running.
“We have identified you, sir,” Shevchenko wrote. He went on to give the attacker a 48-hour deadline.
Did NEAR Intents receive a full refund?
Following the threats, Shevchenko opened a private channel to communicate with the perpetrator. In one post, he thanked the attacker “for your willingness to cooperate” and pointed to messages that could be decrypted with the private key from an Ethereum address, 0x09Fd1f5d9F185067A92493E43AA259ea4AB3ad37.
Shevchenko announced on Friday that the $3.8 million stolen in the hack was returned in full. “We are stopping the investigation. Please use bug bounties instead of disrupting the services.”
Cryptopolitan reported that prior to the hack and the resolution, NEAR Intents turned away more than $50 million in funds tied to the September 24 Bitget breach, freezing about $503,000 of it through its SHIELD risk system.
During that period, Shevchenko criticized crypto builders, saying that they cannot run infrastructure that is designed to “help launder stolen funds” while asking for the recognition of digital assets.
Full recoveries remain uncommon in the crypto industry, but NEAR Intents is not the first to pull one off. Following what the project called successful negotiations, the Euler Finance attacker returned the last $31 million from the $197 million hack that occurred in March 2023. Euler Finance ended up with more than $177 million in recovered assets.
In July 2025, Cryptopolitan reported that the GMX exploiter returned about $37.5 million after accepting a 10% white-hat bounty.
If you’re reading this, you’re already ahead. Stay there with our newsletter.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
