Key points
- NEAR Intents general manager Alex Shevchenko said the roughly $3.8 million taken in the breach was sent back in full.
- The project stopped its recovery investigation after the return, following a public 48-hour ultimatum to the alleged attacker.
- A detailed technical postmortem had not been published at verification time, leaving the exploit's full mechanics and remediation scope unresolved.
NEAR Intents says the roughly $3.8 million taken from its cross-chain service has been returned in full, sharply changing the financial outcome of a security incident that forced the platform to pause operations. General manager Alex Shevchenko announced the recovery on October 2, saying the project was ending its investigation and urging researchers to use bug-bounty channels rather than disrupt services. The statement followed a public warning in which he said the project had identified the alleged attacker and offered a 48-hour window to return the assets.
A rapid reversal after the service pause
The incident began on October 1, when NEAR Intents halted services after detecting a problem involving its Omni deposit and withdrawal infrastructure and the protocol's main smart contract. Independent reports from Decrypt and Cointelegraph put the amount taken at about $3.8 million. The project had pledged to compensate affected users while working with security specialists, blockchain analytics firms and law enforcement to trace the funds. Decrypt reported that the team later said the contract-side vulnerability had been patched and that core services were being restored in stages.
Related reporting: NEAR Intents restores service after $3.8 million cross-chain exploit
The recovery announcement closed the immediate asset-retrieval phase, but it did not amount to a full technical postmortem. Shevchenko's public statement did not identify the person involved, describe how the project attributed the activity or explain whether any conditions accompanied the return. Decrypt reported that an on-chain message appearing to come from the exploiter acknowledged wrongdoing and said the funds had been returned. That message and the project's statement support the recovery account, but they do not independently resolve every transaction path or the precise sequence of the breach.
Why the incident matters for cross-chain systems
NEAR Intents is designed to let users express a desired swap while market makers compete to fill it across multiple networks. That approach can simplify a fragmented market, but it also creates operational dependencies between contracts, deposit systems, solvers and the infrastructure that moves assets from one chain to another. In this case, the project described the issue as an interaction bug rather than a failure of the NEAR blockchain itself. That distinction matters because remediation must target the integration layer that failed, not just the underlying network.
A full return reduces the direct loss that users and the project might otherwise have absorbed. It does not erase the security failure, the interruption to service or the need to explain how controls broke down. Cross-chain systems remain attractive targets because they coordinate value across several technical environments, and an error at the boundary between components can expose pooled funds even when the individual chains continue operating normally. Users therefore need information about contract changes, service status and any limits imposed while the platform reopens.
What remains unresolved
The next important document will be the promised incident report. A useful postmortem would identify the vulnerable component, show when the flaw was introduced and detected, explain the affected assets and networks, and describe the tests or monitoring added after the patch. It should also clarify whether all user balances were reconciled and whether any residual restrictions remain. Until that report appears, the most defensible conclusion is narrow: NEAR Intents says the full amount was returned and the recovery investigation was stopped, while the deeper security lessons are still incomplete.
Sources
- Alex Shevchenko: NEAR Intents exploit funds returned in full
- Decrypt: NEAR Intents recovers $3.8 million after ultimatum
- Cointelegraph: NEAR Intents recovers stolen $3.8 million
AI-generated editorial image; not a photograph of the reported event. Prepared with AI assistance and source verification.
