NEAR Intents says it has recovered the full 3.8 million dollars stolen in last Thursday’s security breach — after publicly identifying the hacker and giving them just 48 hours to return the money.
By Priya Sharma | October 5, 2026
The Hook: A Hack That Ended With a Handback
Most crypto heists end one of two ways: the funds vanish into mixers and are never seen again, or a negotiated bounty returns a fraction of the losses. What makes the NEAR Intents case remarkable is the outcome — everything came back. General manager Alex Shevchenko announced the complete return of funds on Friday.
“The funds from the 3.8M NEAR Intents hack were sent back in full,” Shevchenko wrote on X. “We are stopping the investigation. Please use bug bounties instead of disrupting the services.”
On-Chain Evidence: How the Breach Unfolded
The timeline moved fast. NEAR Intents paused services after detecting what it described as “a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.” In plain terms: the plumbing that moves user deposits in and out of the protocol did not talk to the smart contract securely, and someone found the gap before the team did.
- 3.8 million dollars — user funds stolen in the Thursday breach
- 48 hours — the deadline NEAR Intents gave the attacker to return funds under “responsible disclosure”
- Full recovery — announced by NEAR Intents general manager Alex Shevchenko on Friday
- Full compensation pledged for all affected users regardless of the outcome
NEAR’s preliminary investigation found that 3.8 million dollars in user funds had been stolen, and the team pledged from the start to compensate affected users in full. Blockchain investigator ZachXBT reported that the stolen funds were transferred to the KuCoin exchange and bridged to Bitcoin along the way.
The Core Conflict: Ultimatum or Bounty — What Stops the Next Hacker
NEAR Intents’ aggressive play — identifying the individual behind the breach and demanding the money back within two days — is a gamble that does not always pay off. It worked here, but security veterans will note that Shevchenko’s own closing line points at the better long-term answer: “Please use bug bounties instead of disrupting the services.”
A bug bounty is an open invitation for security researchers to report flaws for a reward instead of exploiting them. Protocols that fund generous bounty programs give talented hackers a legal, profitable alternative to theft. The NEAR episode is a reminder that DeFi platforms are software built by humans, and every complex piece of software has cracks — the question is who finds them first, and what incentive they have to come forward.
Market Implications: A Rare Win for DeFi Trust
For a sector whose reputation has been battered by billion-dollar exploits, a full recovery is more than a footnote. It signals three things investors rarely get to see at once: a team that detected the breach quickly, investigators capable of tracing and identifying the attacker, and a resolution that left users whole. NEAR Intents also committed to compensating users in full, meaning the incident was designed from the start to end without retail losses.
The competitive stakes are real. Cross-chain services like NEAR Intents — which let users move and deploy assets across different blockchains — live and die by trust. One bad exploit can send users to rivals permanently. Handling a breach this cleanly may be the strongest marketing the platform could ask for.
The Verdict: What This Means For You
If you used NEAR Intents and were affected, the pledge of full compensation means your balance should be restored — watch official NEAR Intents channels for the claim or refund process. If you are a general DeFi user, the lessons are older than this hack: keep only the funds you actively use in any single protocol, prefer platforms with audited code and funded bug bounties, and remember that even a happy ending like this one started with a bug nobody knew about.
The broader takeaway is cultural. “Responsible disclosure” only works when projects make honesty pay better than theft. Every full-recovery story strengthens the norm — and every user who gets paid back in full is a small vote of confidence in DeFi’s ability to police itself.
The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.
full 3.8M returned and the investigation stopped the same day. the 48 hour ultimatum worked better than most bug bounty negotiations ever do
^ the fact they named the hacker publicly first probably did more than the deadline. nobody wants that heat with 3.8M sitting traceable onchain
agree with ivan, though the funds came back before any real legal pressure. mixers exist. this was the hacker blinking, plain and simple
shevchenko saying use bug bounties instead of disrupting services is the politest way ive ever seen someone say dont make us doxx you again
3.8M back in full within 48 hours of naming the attacker, and users compensated on top. the Omni interaction bug cost a week of downtime and zero net loss, wild ending
full 3.8m returned AND they named the hacker publicly first. shevchenko basically dared the guy to keep the money with that 48h deadline lol
Doxxing the attacker only works when it is one scared solo dev. Try that playbook against a state group and the ultimatum means nothing. Still, credit where due, full recovery is rare.
right, the doxx only works on a sloppy solo operator. still, stopping the investigation the same day funds landed is faster than any frozen fiat recovery process I have watched
the bug was in the omni deposit and withdrawal plumbing talking to the contract. integration layer, the boring part nobody audits hard until it costs 3.8m
the boring integration layer again. same lesson as every bridge incident, the contract itself was fine, the glue between Omni deposits and the intents contract wasnt
Agreed, and this is exactly why bug bounties pay off. Cheaper to hand someone 100k for finding the gap than to pause services and chase funds for a week.