NEAR Intents has ended its investigation into the October 1 exploit that siphoned $3.8 million from the cross-chain payments system, after the alleged exploiter returned the funds in full ahead of a 48-hour deadline — including a return transaction whose on-chain data carried an apology.
The resolution makes the incident one of the fastest full recoveries in a year otherwise running the other way: Q3 losses surged to roughly three-quarters of a billion dollars, led by the Bitget and Liquid Network exploits.
What Happened on October 1
The exploit targeted an integration bug in the Omni system that powers NEAR Intents, a system that lets users move funds across chains without bridges. The attack was isolated to BNB Chain, where the flaw let the attacker siphon $3.8 million, according to AMBCrypto.
The team's AI security layer, SHIELD, flagged the anomaly, and NEAR Intents was shut down for roughly an hour while engineers investigated. Within a day, NEAR Intents general manager and Aurora Labs co-founder Alex Shevchenko said the alleged exploiter had been identified, published three return addresses across Bitcoin, BNB/ETH and Solana, and set an October 4 deadline for the funds to come back.
The Return, On the Record
Shevchenko announced on October 2 that the funds had been "sent back in full" and that the investigation was being stopped. NEAR co-founder Illia Polosukhin said the team had identified the responsible party in less than 24 hours — crediting SHIELD and what he called "aggressive detective work" — established communication, and recovered everything by 14:30 UTC.
The on-chain record backs the announcement. A BNB Chain transaction marked successful at 16:15:28 UTC on October 2 was sent from an address labeled "Near Intents Exploiter 1" by BscScan, with input data reading: "We've returned all the funds, we were in the wrong. Thank you to the Near team for being respectful, constructive, and cordial during the return process. Remember to always use bug bounties!"
As The Crypto Times noted, the message does not independently establish who controlled the address, but the transaction is consistent with the reported return. Researcher Kuncoro separately traced roughly $2.95 million returning via 34.59 BTC to the published Bitcoin address, with the balance arriving through other routes.
Questions Left Open
The identity of the alleged exploiter has not been made public, and the team has declined to explain how it traced them. Asked how the attacker was found, Shevchenko replied, "No. We dropped the investigation already." Asked who did the tracing, he said "Internal team." Neither NEAR Intents nor Polosukhin has said whether law enforcement was involved.
Both closed with the same message to security researchers. "Please use bug bounties instead of disrupting the services," Shevchenko wrote — echoed by Polosukhin: "For security researchers looking for exploits, we encourage you to use bug bounties. They exist for a reason."
The incident is a reminder that full recovery is usually the exception, and it tends to happen when the attacker is a negotiable opportunist rather than an organized crew. In the same week, the Bitget trace showed stolen funds consolidating into Wasabi CoinJoins and Tornado Cash with no negotiation on offer. Teams drawing the lesson that identification plus a deadline equals recovery should note that NEAR's outcome depended on an attacker willing to talk — a variable no incident-response plan controls.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.