NEAR Intents exploit funds have been returned in full. Specifically, roughly $3.8 million was recovered. The protocol had already promised to cover affected users.
Why the NEAR Intents exploit recovery matters
NEAR Intents general manager Alex Shevchenko confirmed the return. The recovery followed a response that briefly froze deposits and withdrawals. That freeze affected 11 networks. For affected users, timing matters. NEAR Intents had already committed to compensate the loss. Therefore, the return affects the protocol’s balance sheet. It does not change the reimbursement owed to users.
How the NEAR Intents exploit happened
NEAR Intents halted services on October 1. The team detected a bug involving Omni infrastructure. That infrastructure handles deposits and withdrawals. The bug also involved an Intents smart contract. The flaw was on the contract side. Developers patched it shortly after detection.
That distinction matters. NEAR Intents coordinates deposits and cross-chain execution. Therefore, a problem in one component can stop activity elsewhere. The initial response affected 11 networks. These included BNB Chain, Polygon, and TON. Optimism, Avalanche, Stellar, and Scroll were also affected.
The money moved through BNB Chain
Initial analysis traced the activity to BNB Chain. Specifically, it involved infrastructure tied to the HOT Bridge treasury. It did not involve the NEAR blockchain itself. Investigator ZachXBT also identified abnormal outflows. These came from a BNB Chain hot wallet linked to NEAR Intents.
The assets moved through KuCoin. Then they bridged into Bitcoin. However, available evidence does not show the base NEAR chain was compromised. Midway through the response, the attacker offered cooperation. They sent 0.295 ETH on Ethereum. About an hour later, they sent 1 BNB to a recovery wallet. Both transfers requested Signal contact details.
A public deadline set a recovery path
Shevchenko later published three return addresses. These covered Bitcoin, BNB Chain, and Solana. He also set a 48-hour deadline for the suspected attacker. In his ultimatum, Shevchenko wrote: “We have identified you, sir.” He described responsible disclosure as a closing window. He has not publicly named the attacker. He also has not shown evidence supporting the identification claim.
As of early October 2, none of the addresses had received funds. The Bitcoin recovery address later received about 34.59 BTC. The supplied reporting does not include direct on-chain verification. It also does not explain how other assets returned.
What full recovery changes
A voluntary return does not erase the need for a post-mortem. The incident crossed several infrastructure layers. These include a BNB Chain hot wallet and an exchange. They also include a Bitcoin bridge and cross-chain contracts. A system serving 11 networks was also involved. Understanding where those connections failed is more useful. It is more useful than treating the return as a complete answer.
NEAR Intents reported the incident to law enforcement. Security and blockchain analytics firms helped with tracing. A fuller post-mortem has been promised. However, its publication and contents remain unconfirmed.
The return removes the immediate loss of about $3.8 million. It also spares users a reimbursement process. The protocol had already promised to fund that process. But until the post-mortem explains the flaw, the larger lesson remains unsettled. The money came back. The design failure that let it leave still awaits a full explanation.