📈 Get daily crypto insights that make you smarter about your money

NEAR Intents Is Back Online After a 3.8 Million USD Exploit — and Every Affected User Will Be Compensated

NEAR Intents is back online roughly a day after a 3.8 million USD exploit hit USDT on BNB Chain, with NEAR co-founder Illia Polosukhin confirming the vulnerability was patched within an hour of detection and pledging that every affected user will be compensated in full.

By Amir Hassan | October 1, 2026

The Hook: An AI Security Layer Caught It First

In a public statement on October 1, Polosukhin said the team had restored NEAR Intents and near.com after temporarily pausing the service when its SHIELD security system detected unusual activity. SHIELD, described by Polosukhin as an AI-based monitoring and outlier-detection system, flagged behavior outside normal activity patterns — and that early warning is what turned a potential disaster into a contained incident.

According to his account, the attacker exploited a bug in the interaction between Omni’s deposit and withdrawal infrastructure and the NEAR Intents smart contract. The affected asset and network were limited to USDT on BNB Chain. The Intents team identified the exact vulnerability and fixed it within an hour of detection. A few affected chain connections on Intents remained unavailable at the time of the restart, though the core service was back online.

The Containment Playbook, Piece by Piece

  • 3.8 million USD — total losses from the exploit, all in USDT on BNB Chain
  • One hour — time from detection to a working fix, according to Polosukhin
  • Full compensation — every affected user will be made whole, the co-founder pledged
  • Core protocol untouched — NEAR Protocol itself, the NEAR token and other applications were unaffected

Polosukhin was careful to separate the affected infrastructure from the underlying blockchain. The exploit hit a bridging and intent-routing service, not the NEAR chain itself — a distinction that matters for anyone holding NEAR or using other applications in the ecosystem. For scale, he put NEAR Intents’ monthly trading and payments volume above 4 billion USD, and described the incident as the first major exploit on Intents since launch.

“At this scale, we have to hold ourselves to a higher security standard,” Polosukhin wrote, adding that the incident will be followed by a full review and postmortem, with findings feeding into additional security measures alongside work already underway on a formal verification system for NEAR contracts.

SHIELD’s Track Record: The Bitget Connection

This is not the first time the SHIELD system has made headlines. On September 29, crypto.news reported that NEAR Intents had blocked transfers of suspected stolen funds linked to the Bitget breach — more than 50 million USD worth of laundering attempts, according to NEAR Intents general manager Alex Shevchenko. During that intervention, the system froze approximately 503,000 USD, while roughly 166,000 USD in suspected stolen funds passed through before the activity was stopped.

The context matters: Bitget confirmed that attackers transferred approximately 387.5 million USD to addresses under their control during the exchange’s September 24 security breach — the same incident that helped make September the worst hack month of 2026. Shevchenko said the frozen funds would be returned through an appropriate legal process and that NEAR Intents would forgo Bitget’s recovery bounty. His description concerned transactions routed through NEAR Intents specifically, not an ability to freeze assets across entire blockchains.

In his October 1 statement, Polosukhin invited additional partners to share information and help identify and contain criminal activity — a signal that NEAR views cross-platform threat intelligence as the next frontier after this week’s events.

Why This Matters for Regular Investors

The incident lands at an awkward moment for American investors’ NEAR exposure. The Bitwise NEAR ETF began trading on NYSE Arca under the ticker NRR on September 29 — just two days before the exploit. The fund charges a 0.75 percent management fee, holds NEAR directly, and intends to stake its holdings through Bitwise’s institutional staking operation, with rewards accruing to shareholders through net asset value. At launch, Bitwise cited an annualized network staking reward rate of around 5 percent as of September 25, while stressing that rewards can change and are not guaranteed.

Because the exploit affected a cross-chain service rather than the base layer, the fundamental case for the protocol is largely intact — but the episode is a reminder that in cross-chain infrastructure, the weakest link is usually the bridge, the router, or the interaction between systems, not the chain itself. A 3.8 million USD loss on a service processing more than 4 billion USD monthly is a rounding error; a 387.5 million USD exchange breach in the same week is not. Investors should understand which layer of the stack each product they use actually exposes them to.

The Verdict

Fast detection, a one-hour fix, full compensation, and a public postmortem commitment — NEAR’s response is close to the textbook incident-handling script the industry keeps asking for after every major hack. Whether the promised formal verification system and expanded security measures materialize will determine if this was a near-miss that hardened the platform or just a lucky catch by SHIELD. For now, users of NEAR Intents can trade again, affected wallets will be made whole, and the rest of the industry got a live demonstration of why AI-based monitoring is becoming standard equipment on cross-chain rails.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

14 thoughts on “NEAR Intents Is Back Online After a 3.8 Million USD Exploit — and Every Affected User Will Be Compensated”

  1. SHIELD flagging the anomaly before anyone else noticed is the real story. 3.8m hit on a service doing 4b a month is about as good as exploits get

    1. great outcome unless you were one of the users stuck holding usdt on bnb chain. full compensation better mean days, not months of waiting

  2. patched within an hour is impressive, but the bug lived in the omni deposit interaction and shipped to production unnoticed. audits only catch so much

    1. every intent protocol has this weakness, the solver layer is where money gets lost lately. solvers are the new bridges

  3. SHIELD catching it within the hour plus full refunds is the best case script. but 3.8M out of a service doing 4B a month means someone found a working exploit, and attackers retry

  4. omnibug_watcher

    3.8M gone in an hour and back online the next day. the SHIELD catch is a good story but the bug was in the Omni bridge interaction, not their own code, lets be precise

    1. right framing. you can bolt an ai shield on top but if the counterparty integration ships the bug your users still eat the loss

  5. an AI monitoring system flagging a live exploit before any human noticed is the actual story here. patched in an hour, 3.8m contained, respect

  6. Katarzyna Nowak

    Full compensation is the right call, but this is another bridge-adjacent incident this year. The pattern keeps repeating across intents style designs.

    1. which others are you counting? genuinely asking, trying to keep a tally of intents and bridge incidents for a writeup

    1. pledged is doing heavy lifting there. ill believe the payouts when the txs show on chain, illia is good for it tho tbf

      1. agreed, pledged aint paid. clock starts now, if users are not whole within a week the goodwill story evaporates fast

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$84,751.00+1.4%ETH$2,701.18+1.0%SOL$118.35+0.7%BNB$769.54+0.5%XRP$1.50+0.9%ADA$0.2483+1.9%DOGE$0.0949+0.7%DOT$1.19-3.6%AVAX$11.00+0.9%LINK$14.44+1.2%UNI$9.12+2.7%ATOM$1.72-1.1%LTC$68.19+2.7%ARB$0.2012-0.8%NEAR$4.83-8.9%FIL$1.02-1.5%SUI$1.18+2.3%BTC$84,751.00+1.4%ETH$2,701.18+1.0%SOL$118.35+0.7%BNB$769.54+0.5%XRP$1.50+0.9%ADA$0.2483+1.9%DOGE$0.0949+0.7%DOT$1.19-3.6%AVAX$11.00+0.9%LINK$14.44+1.2%UNI$9.12+2.7%ATOM$1.72-1.1%LTC$68.19+2.7%ARB$0.2012-0.8%NEAR$4.83-8.9%FIL$1.02-1.5%SUI$1.18+2.3%
Scroll to Top