NEAR Intents says the attacker behind its October 1 exploit has returned the full $3.8 million that was stolen, ending the incident days after it began and without any disclosed ransom or bounty payment.

General Manager Alex Shevchenko confirmed on October 2 that the funds had come back in full and that the team was stopping its investigation. The recovery closed out an unusual sequence: the protocol identified the attacker within roughly 24 hours of the theft, publicly named a 48-hour return deadline, and published designated return addresses on Bitcoin, BNB Smart Chain/Ethereum and Solana — and the money arrived hours into that window rather than at its end.

A BNB Chain transaction linked to the return carried an on-chain message back to the protocol, as reported by The Crypto Times.

How the incident unfolded

The exploit hit NEAR Intents' Omni deposit and withdrawal infrastructure on October 1, draining about $3.8 million from a BNB Chain hot wallet. The platform paused services across eleven networks, patched the contract-side bug, and pledged full reimbursement of any affected user funds.

On October 2, Shevchenko said the attacker had been identified and gave them 48 hours to return the funds to the listed addresses, warning that the deadline would not be extended. The full amount was back within roughly a day of that announcement, according to multiple outlets tracking the on-chain movements.

NEAR Intents has not publicly detailed how the attacker was identified, what the return message said, or whether any conditions were attached to halting the probe. A promised post-mortem of the underlying vulnerability has not yet been published.

A quiet end to a loud week

The resolution closes, for now, the smallest of the week's security incidents — but one loaded with irony. In the days after the $387.5 million Bitget theft, NEAR Intents' SHIELD risk system had rejected more than $50 million in swap attempts linked to the stolen funds and froze roughly half a million dollars mid-execution. The protocol then lost $3.8 million through a bug in its own deposit plumbing, and recovered it by negotiation rather than by freezing addresses.

Full voluntary returns remain rare. In most major incidents of 2026 — Bitget, KelpDAO's April bridge exploit, the September protocol cluster — stolen funds have been laundered across chains rather than returned. The NEAR Intents outcome hinged on a fast identification and a cooperative counterparty, factors that do not reliably exist in state-linked attacks.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.