All $3.8 million drained from NEAR Intents was fully returned on October 2, ahead of the 48-hour deadline set by the project after announcing it had identified the exploiter. The incident stemmed from a bug between the Omni deposit/withdrawal infrastructure and smart contracts on BNB Chain, forcing cross-chain services to temporarily pause before the vulnerability was patched and systems resumed operation.
NEAR Intents Traces Exploit to Omni Infrastructure Bug
NEAR Intents identified the preliminary cause as a bug in how the Omni deposit/withdrawal infrastructure interacts with the protocol’s smart contracts. According to NEAR co-founder Illia Polosukhin, the incident only affected USDT in a vault on BNB Chain; NEAR Protocol, the NEAR token, and other applications within the ecosystem were not compromised.
Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.
The preliminary report indicates the total loss of…
— NEAR Intents (@near_intents) October 1, 2026
NEAR Intents is an intent-based cross-chain trading infrastructure. Users specify the assets they want to send and receive, while execution parties known as solvers compete to find and complete the transaction route. Omni supports bringing assets into and out of the system across multiple blockchains, saving users from having to select bridges manually or handle individual steps themselves.
The vault on BNB Chain pays out assets upon receiving a signed withdrawal message from the system side. On-chain analysis by Bitquery shows that the attacker’s withdrawals used the same message format as regular transactions, but blockchain data cannot explain why those requests were issued or approved. NEAR Intents has not yet disclosed the source-code level root cause and stated that a detailed post-mortem report will be released later.
Attacker Drained $3.87 Million in Five Major Withdrawals
Five withdrawals over six hours removed a total of 3,865,000 USDT from the BNB Chain vault, according to transaction data reconciled by Bitquery. Most of the damage was concentrated in under an hour, as the first three transactions removed a total of $3.5 million USDT from the system.
The first major withdrawal transferred 800,000 USDT at 23:54 UTC on September 30. Two subsequent transactions worth 1.2 million and 1.5 million USDT followed within the next 56 minutes. The vault continued to payout 330,000 USDT at 01:46 and 35,000 USDT at 06:08 on October 1.
Prior to the sequence above, the associated address executed two test withdrawals worth 10 USDT and 11 USDT on the evening of September 30. An address linked to this wallet had also deposited 10 USDT into the vault two days earlier. These small transactions show that the system successfully processed requests from the linked address group before large sums were withdrawn.
The scale of these transactions was also significantly different from recent vault activity. In the two days prior to the incident, the largest stablecoin payout was valued at under $400,000.
Most Stolen Funds Were Converted to Bitcoin
Approximately 76% of the stolen funds were converted into 34.69 BTC and distributed into four Bitcoin wallets. These wallets had not transferred the BTC away when inspected at 14:30 UTC on October 1. Another roughly $802,000 went into deposit addresses labeled KuCoin, while nearly $90,000 was recorded in a Monero-linked asset on Hyperliquid.
These three asset groups accounted for about 99% of the total value tracked by Bitquery. On-chain labels indicate that funds reached KuCoin’s infrastructure, but the controller of the receiving accounts could not be identified. The above figures reflect the state of assets before NEAR Intents announced that the entire $3.8 million had been returned on October 2.
Services Restored After Contract Patch
NEAR Intents paused operations after detecting the incident and patched the contract-side vulnerability within one hour, according to NEAR co-founder Illia Polosukhin. NEAR Intents and near.com subsequently resumed operation, while certain cross-chain deposit and withdrawal routes required additional time to complete Omni infrastructure updates.
In its initial announcement, the project stated that deposit and withdrawal functions across 11 networks would experience further disruption for about 12 hours. This list included BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. The NEAR Intents status page currently marks core services, cross-chain infrastructure, integrated blockchains, and websites as operating normally.
NEAR Intents initially committed to fully compensating affected users. The project did not disclose the number of impacted accounts or a payout plan prior to announcing that all stolen funds had been returned on October 2.
Funds Returned Before 48-Hour Deadline
On October 2, Alex Shevchenko, general manager of NEAR Intents, announced that all $3.8 million had been returned and the project would halt its investigation. The funds arrived before the 48-hour deadline he established after claiming the team had identified the party behind the exploit.
The funds from the $3.8M NEAR Intents hack were sent back in full.
We are stopping the investigation.
Please use bug bounties instead of disrupting the services.
— Alex Shevchenko 🇺🇦 (@AlexAuroraDev) October 2, 2026
The associated address initially sent 0.295 ETH and 1 BNB alongside a request to communicate via Signal. Subsequently, a Bitcoin address published by Shevchenko received approximately 34.59 BTC across five transactions, valued at nearly $2.95 million. The remainder was returned via another route, but NEAR Intents has not released a full breakdown.
The project has also not disclosed the identity of the party involved or the tracking methods used. NEAR co-founder Illia Polosukhin stated that the team identified the responsible party in under 24 hours with support from SHIELD and internal investigative efforts.