Overview In a year when stolen crypto rarely comes back, a full return of $3.8 million stands out. Cross-chain trading protocol NEAR Intents disclosed an exploit on October 1, identified the suspectedOverview In a year when stolen crypto rarely comes back, a full return of $3.8 million stands out. Cross-chain trading protocol NEAR Intents disclosed an exploit on October 1, identified the suspected

NEAR Intents Hacker Returns All $3.8M Stolen Funds After 48-Hour Ultimatum, Probe Closed

Overview

 
In a year when stolen crypto rarely comes back, a full return of $3.8 million stands out. Cross-chain trading protocol NEAR Intents disclosed an exploit on October 1, identified the suspected attacker within a day, published recovery addresses and set a 48-hour deadline. The funds arrived before the clock ran out. According to Crypto Times, general manager Alex Shevchenko confirmed on October 2 that the entire sum had been returned and that the team was ending its investigation.
 
What the market is pricing is not the amount. It is the sequence: public identification, a hard deadline, on-chain tracing and a risk-intelligence layer that had already proven itself a week earlier. For the NEAR ecosystem, a security incident turned into a trust event. For cross-chain infrastructure more broadly, it raises a sharper question about whether deterrence is becoming a core competitive asset rather than a compliance afterthought.
 
 

Key Takeaways

 
The funds are back and the case is closed. Shevchenko confirmed on October 2 that roughly $3.8 million had been returned in full, and urged others to use bug bounty channels rather than disrupt live services.
 
The flaw sat in the integration layer. Public reporting points to a bug in how the Omni deposit and withdrawal infrastructure interacted with the protocol's smart contract, with the drained assets being USDT held in a BNB Chain vault.
 
The 48-hour deadline was the decisive variable. The team traced the attacker within 24 hours, then published Bitcoin, BNB, Ethereum and Solana addresses alongside a firm return window.
 
Users were never on the hook. NEAR Intents had pledged full compensation before any funds came back, so the recovery mainly repairs the protocol's own balance sheet.
 
Key details remain undisclosed. As of October 3 there was no full technical post-mortem and no public identification of the attacker, which limits how far the outcome can be generalized.
 

An Attack and Recovery Compressed Into 72 Hours

 

From Exploit to Paused Services

 
Reporting places the exploit between September 30 and October 1. CryptoBriefing notes that a critical bug in the protocol's smart contracts created the opening, that the flaw was caught by NEAR Intents' own tooling, and that it was patched within an hour. A detailed incident record from Shattered adds that the attacker began pulling funds from a BNB Chain vault late on September 30, that roughly $3.8 million in USDT was drained, and that the breach was disclosed publicly on October 1. The same record states that as of October 3 no full technical post-mortem had been published, leaving the precise failure, whether a missing signature check, a replay flaw or broken nonce validation, unconfirmed.
 
Services on the affected networks were suspended once the breach was confirmed. According to KuCoin's summary of Odaily's reporting, the incident stemmed from the interaction between the Omni deposit and withdrawal layer and the main smart contract, and the team paused services while pledging full compensation to users. NEAR co-founder Illia Polosukhin specified that the exploit targeted USDT on BNB Smart Chain, as reported by MoneyCheck.
 

The Ultimatum and the On-Chain Message

 
October 2 changed the trajectory. AMBCrypto reports that the attacker was tracked within 24 hours, after which Shevchenko issued a 48-hour window for the funds to come back. Recovery addresses were published across four chains, and MoneyCheck notes that the Bitcoin recovery wallet had received roughly 34.59 BTC by October 2, with Shevchenko confirming shortly afterward that every designated address had been funded.
 
Crypto Economy documents the precise timing. The return transaction on BNB Chain was confirmed at 16:15:28 UTC on October 2, carrying an input message from the attacker, with the capital fully restored around 14:30 UTC that day, at which point the engineering team closed the matter nearly two days ahead of the October 4 deadline. Crypto Times adds that a BNB Chain transaction included a message from an address labeled as the exploiter stating the funds had been returned. Shevchenko's own statement was blunt: "The funds from the $3.8M NEAR Intents hack were sent back in full."
 
One detail deserves attention. The attacker's message encouraged others to report issues through bug bounty channels instead. NEAR Intents does run such a program: its SDK bounty page on HackenProof covers intent signing and submission, cross-chain withdrawals and related flows, with the maximum reward for high and critical findings capped relative to the funds practically affected. That framing gives the episode a grey-hat texture, though without official disclosure the attacker's actual motive remains speculation.
 

Why the Market Read This as Bullish

 

Full and Fast Recovery Is a Statistical Outlier

 
The reaction makes sense only against this year's security backdrop. A summary of TRM Labs data for the first half of 2026 records 207 separate hacks, more than double the 83 incidents in the same period last year and the highest count for any half-year in that dataset, while total losses came in at $972 million, less than half the $2.3 billion stolen a year earlier. The same data shows smart contract exploits hitting a record 125 incidents while accounting for only about 17% of stolen value, with roughly three quarters of losses tracing to compromised keys, custody systems and signing infrastructure.
 
Against that distribution, an integration-layer bug costing under $4 million is unremarkable. The ending is what is rare. The Chainalysis 2026 Crypto Crime Report recorded more than $3.4 billion stolen during 2025, the overwhelming majority of which never returned. In an industry where stolen funds usually head toward mixers, a 100% recovery inside 72 hours sits far outside the normal distribution.
 

A Second Data Point for the SHIELD Narrative

 
The tracing capability on display did not appear out of nowhere. A week earlier, Bitget suffered a breach of roughly $387.5 million, and the attackers tried to push proceeds through cross-chain rails. According to Bitcoin.com, NEAR Intents' automated risk-intelligence layer SHIELD blocked more than $50 million in attempted transfers, froze $503,000 mid-execution, and let only about $166,000 slip through. For a protocol routinely handling more than $100 million in daily cross-chain volume, that interception ratio carries weight.
 
Bitget's chief executive publicly thanked the team at the time, and NEAR Intents waived its share of the recovery bounty so the exchange could retain more, as covered by Unchained. The same report quotes Polosukhin arguing that permissionless means nobody needs permission to own, transfer or deploy, not that every application must process every transaction. Within a single week, SHIELD was tested both as a filter against someone else's stolen funds and as a recovery tool for the protocol's own loss. That double validation is what moved sentiment.
 

Where Restraint Is Warranted

 
Treating one success as institutional capability is the easiest error here. Because the attacker's identity remains undisclosed, outsiders cannot judge whether the deterrent came from on-chain tracing, off-chain leads or something else entirely. Because no full post-mortem has been published, it is impossible to verify whether comparable integration-layer risks have been systematically reviewed. And the return was legally a voluntary act, not a repeatable enforcement mechanism. SHIELD's discretion has also drawn criticism on neutrality grounds, with the Unchained report capturing objections about how far a protocol's judgment should extend. These are open questions, not settled ones.
 

What It Means for Cross-Chain Intents

 

Risk Control as Infrastructure Moat

 
Competition among cross-chain protocols has centered on chain coverage, slippage, settlement speed and solver depth. Two consecutive episodes have pushed a different dimension forward: whether illicit flows can be recognized on the way through, and whether losses can be clawed back when the protocol itself is breached. For solvers, market makers and institutional capital, that capability feeds directly into counterparty risk pricing. Bankless, analyzing the Bitget episode, noted that Intents is a cross-chain layer sitting atop NEAR rather than part of consensus, and that SHIELD decides which trades the protocol executes but cannot freeze wallets or reverse completed transactions. That boundary matters: risk control here is a service-level choice, not a rewriting of base-layer neutrality.
 

The Cost Curve Between Bounties and Exploits

 
The attacker's own suggestion about bug bounties points to a shifting incentive structure. When a protocol can identify and apply public pressure quickly, the expected value of holding stolen funds compresses while the certainty of a compliant disclosure payout rises in relative terms. The reward mechanism on the HackenProof page, which ties maximum payouts to the funds practically affected, is itself an attempt to reshape that curve. The industry lesson is that credible tracing and credible bounties are complements. Without both, the white-hat path rarely becomes the rational one.
 

A Trader's Perspective

 

How Event-Driven Moves Typically Behave

 
Price effects from incidents like this usually front-load: a sell-off on disclosure, a sentiment repair once recovery is confirmed, then handover to broader macro and liquidity factors. AMBCrypto cites analyst Michael van de Poppe viewing the full return as a positive signal for the token. That is a market participant's public opinion rather than a judgment on price direction, and sentiment repair does not automatically convert into trend reversal.
 
More useful to traders is what happens to liquidity structure. Security events widen spreads and amplify volatility, and when funding rates on perpetuals swing alongside, the carrying cost of short-term positions can run well above calm-market levels. In that environment, execution quality, depth and the completeness of risk tools often shape outcomes before directional calls do. MEXC offers access through its NEAR/USDT spot market and perpetual futures market for users adjusting exposure during volatile windows, and its approach to asset security and risk management is set out on the Why MEXC page.
 
When volatility widens, execution quality becomes part of your return, sign up on MEXC and claim up to 10,000 USDT in new user rewards.
 

Weighing On-Chain Venues Against Centralized Ones

 
The episode also reopened the question of where capital should sit. On-chain protocols offer self-custody and composability, but integration-layer bugs, contract risk and cross-chain complexity are hard for an individual user to assess independently. Centralized exchanges concentrate custody and risk control, which concentrates counterparty exposure and makes transparency dependent on the platform's own disclosures. These are not substitutes so much as different jobs. The practical approach is to tier capital by purpose: funds needed for trading and margin management in venues that allow instant redeployment, long-term holdings in self-custody, and on-chain protocol exposure sized to a loss the holder can absorb.
 

Risks, Scenarios and What to Watch

 

Unresolved Uncertainties

 
The leading technical risk is recurrence. A patched interaction between the Omni deposit and withdrawal layer and the main contract does not automatically mean other integration paths have been audited. The informational risk is the missing post-mortem, which leaves observers dependent on interim statements and secondary reporting rather than verifiable technical documentation. The governance question centers on SHIELD's discretion: when a protocol can both block another party's stolen funds and apply pressure after its own loss, questions about who sets the standard and who reviews it do not go away.
 

Three Paths From Here

 
In the constructive case, the protocol publishes a complete post-mortem, compensation is executed as promised, services resume across all affected chains, and SHIELD is adopted by other protocols as shared infrastructure, reinforcing the deterrence narrative.
 
In the neutral case, attention fades, technical detail stays partial, and the token tracks broader liquidity and macro conditions rather than anything specific to the incident.
 
In the adverse case, a comparable integration-layer failure or an escalation of the discretion debate erodes the trust premium that this recovery earned. The probability is low, but for position sizing it is the branch that defines where risk limits belong.
 

Concrete Items to Track

 
Worth monitoring from here: whether NEAR Intents publishes a full technical breakdown, how user compensation is executed, whether all paused chains return to normal operation, whether SHIELD is integrated by other protocols, and whether the protocol's related volume and locked value on DefiLlama recover to pre-incident levels. These are verifiable measures, and they say more about restored trust than any statement does.
 

Exclusive View from James Mitchell

 
For James Mitchell, the number that matters is not $3.8 million but the elapsed time. Under 48 hours from disclosure to full restitution implies that the attacker assigned a very low expected value to holding the proceeds. Among the 207 incidents TRM Labs logged in the first half of the year, almost no attacker reached the same conclusion, and the difference lies less in the sums involved than in the probability of being identified. When a protocol can locate a counterparty within a day and apply public pressure, the risk-adjusted return on the exploit falls below the bounty. That is the reusable part of this story.
 
The likeliest misreading is to treat a single outcome as a stable capability. With no public identification, there is no way to assess how repeatable the deterrent is. With no complete post-mortem, there is no way to verify how far the review of similar integration-layer risk has gone. Equally easy to overlook is that the compensation pledge preceded the recovery, which means the funds coming back primarily repaired the protocol's own balance sheet rather than user outcomes. Conflating "users lost nothing" with "security has been demonstrated" is the standard logical jump in narratives like this one.
 
From a risk management standpoint, the variables worth watching are verifiable rather than rhetorical. Whether the post-mortem lands, whether every paused chain resumes, and whether locked value and volume return to their prior range together form the evidence chain for restored trust. For traders carrying exposure, the disciplined approach separates event-driven sentiment repair from trend assessment, sizing positions off realized volatility rather than off the emotional intensity of the headline. In a widened-volatility window, oversizing usually costs more than being wrong on direction.
 
The longer lesson concerns how infrastructure competes. Cross-chain protocols used to be judged on reach and execution efficiency. Now they are also judged on whether they can recognize illicit flows passing through and recover value when breached. That mirrors how clearing institutions in traditional finance eventually built both risk screening and recovery functions: any system that becomes a conduit for money is eventually asked where it stands on abuse. SHIELD has now been tested in two different roles inside a single week, which is a useful data point. Turning a data point into a structural advantage requires repetition, published standards and processes that outsiders can examine. The answer will matter well beyond one ecosystem.
 

FAQ

 

Was all $3.8 million really recovered?

 
Yes. General manager Alex Shevchenko confirmed on October 2 that the funds had been returned in full and that the investigation was stopping. Crypto Economy's timestamps place the BNB Chain return transaction at 16:15:28 UTC that day, with full restoration around 14:30 UTC, ahead of the October 4 deadline. The published Bitcoin recovery wallet had already received roughly 34.59 BTC.
 

What caused the exploit?

 
Public reporting points to a flaw in how the Omni deposit and withdrawal infrastructure interacted with the protocol's smart contract, with roughly $3.8 million in USDT drained from a BNB Chain vault. The bug was caught by the protocol's own tooling and patched within an hour. As of October 3, however, no complete technical post-mortem had been released, so the specific failing function or validation step remains officially unconfirmed.
 

Will affected users lose money?

 
Based on the protocol's public commitment, users are to be compensated in full. That pledge was made before any funds were returned and was not contingent on recovery, which means the restitution mainly improved the protocol's own finances rather than determining whether users got their money back. The execution of that compensation should be tracked through NEAR Intents' own subsequent disclosures.
 

Why would the attacker return the funds?

 
The team traced the attacker within 24 hours, published recovery addresses across four chains and set a public 48-hour window, and that pressure is widely seen as decisive. The attacker acknowledged the act in an on-chain message and encouraged others to use bug bounty channels. The identity has not been disclosed, so the underlying motive and whether law enforcement was involved remain unverified.
 

What is SHIELD, and can it freeze assets on-chain?

 
SHIELD is the automated risk-intelligence layer NEAR Intents runs ahead of execution, checking public deposit addresses against stolen-funds intelligence shared across the industry and then declining to quote or halting execution. During the Bitget incident it blocked more than $50 million in attempted transfers. Its authority stops at the protocol's execution layer: it cannot freeze wallets on a blockchain or reverse completed transactions.
 

What does this mean for the NEAR token?

 
Full recovery removed the largest source of uncertainty, and market participants including analyst Michael van de Poppe have treated it as a positive signal. Sentiment repair and trend direction are separate questions, though. Effects from security incidents tend to front-load before broader liquidity and macro conditions take over, which makes the post-mortem and the full restoration of services the more meaningful medium-term variables.
 

What should an ordinary investor take away?

 
The practical lesson is that cross-chain risk does not live only in core contract logic. Integration layers and bridging steps can be just as fragile, and they are the hardest parts for an individual to evaluate. Tiering capital by purpose is the workable response: keep funds that need instant redeployment where liquidity and execution are strongest, and size on-chain protocol exposure to a loss that can be absorbed.
 

Disclaimer

 
The information above is provided for general market information and analysis only and does not constitute investment advice, financial advice, legal advice, tax advice or a recommendation to trade. Prices of crypto assets, equities and other related financial assets can fluctuate sharply, and past performance, technical indicators and on-chain data do not guarantee future results. The incident details, timestamps and figures cited reflect public information available at the time of writing, and both the investigation and any technical post-mortem may be updated, so the latest official statements from the project and relevant institutions should be treated as authoritative. Readers should conduct their own research and make decisions based on their own financial circumstances, investment objectives and risk tolerance, consulting a qualified professional where appropriate. The MEXC Crypto Pulse team accepts no liability for any direct or indirect loss arising from the use of this information.
 

About the Author

 
James Mitchell specializes in technical analysis, market trends, and trading strategies for both Bitcoin and altcoins. Based in London, he has over 10 years of experience in financial markets. Before joining MEXC Learn, James worked as a senior analyst at a leading European investment firm, where he developed expertise in risk management and quantitative trading. His transition to cryptocurrency markets began in 2017, and he has since become recognized for his data-driven approach. He holds a Master's degree in Financial Economics from the London School of Economics. His analytical approach combines traditional technical analysis with on-chain metrics to provide readers with actionable insights.
 
Areas of Expertise: Technical Analysis, Market Trends & Cycles, Trading Strategies, Bitcoin & Altcoin Analysis, Risk Management.
 

Research References

 
 
Want the fastest access to MEXC's latest updates? Join our official Telegram group now!
Join MEXC Community: X (Twitter) | Telegram | Discord
Account Verification: Understand KYC | How to Complete KYC
External Content Platforms: Substack | Medium | Paragraph | LinkedIn | X(News)
Market Opportunity
NEAR Logo
NEAR Price(NEAR)
$4.8891
$4.8891$4.8891
USD

The articles shared on this page are sourced from public platforms and are provided for reference only. They do not represent the position or views of MEXC. All rights belong to James Mitchell. If you believe any content infringes upon the rights of a third party, please contact [email protected] for prompt removal. MEXC does not guarantee the accuracy, completeness, or timeliness of any content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be interpreted as a recommendation or endorsement by MEXC. For expert insights and in-depth analysis, visit MEXC Learn.

Latest Updates on NEAR

View More
SpaceX Options Surge: Turning IPO Momentum Into a Volatility Test

SpaceX Options Surge: Turning IPO Momentum Into a Volatility Test

SpaceX’s post-IPO rally has evolved beyond a simple first-day demand story. After pricing its shares at $135, opening near $150, and quickly surging past the $200 threshold, the market is now entering a critical testing phase. The most significant shift is the entry of derivatives: the emergence of record first-day options activity has transformed SpaceX from a standard IPO momentum play into a complex, volatility-driven price-discovery narrative. In this new regime, round-number psychological levels, dealer hedging, and implied volatility often dictate short-term price action as much as the company’s long-term aerospace ambitions.
2026/06/17
Nvidia FY2027 Q1 Earnings Review: Data Center Revenue Hits $75.2B as AI Chip Margins Hold Near 75%

Nvidia FY2027 Q1 Earnings Review: Data Center Revenue Hits $75.2B as AI Chip Margins Hold Near 75%

Nvidia reported its fiscal 2027 first-quarter financial results on May 20, 2026, delivering an absolute powerhouse of a quarter. For the period ending April 26, 2026, the chip giant pulled in a record-shattering $81.6 billion in total revenue—marking an 85% surge year-over-year. The star of the show was once again the Data Center segment, which brought in $75.2 billion alone, jumping 92% from the same time last year. Even with massive scaling efforts, Nvidia kept its pricing power completely intact, with GAAP and non-GAAP gross margins landing at a remarkable 74.9% and 75.0%, respectively. This update proved that global AI demand isn't just an abstract narrative; it is translating directly into high-margin revenue at an unprecedented scale. For investors checking the latest market trends, this Q1 report sets a massive baseline for Nvidia's next earnings cycle, testing whether the AI infrastructure boom can keep moving at this pace without hitting supply limits or margin fatigue.
2026/07/09
Miden USDCx Brings Private Stablecoin Payments Onchain

Miden USDCx Brings Private Stablecoin Payments Onchain

Miden plans to introduce USDCx alongside its zero-knowledge blockchain mainnet near the end of August 2026. The stablecoin will be issued natively by Miden through Circle’s xReserve infrastructure and supported 1:1 by USDC deposited into an xReserve smart contract.
2026/08/13
View More