All $3.8 million drained from NEAR Intents was totally returned on October 2, forward of the 48-hour deadline set by the mission after asserting it had recognized the exploiter. The incident stemmed from a bug between the Omni deposit/withdrawal infrastructure and good contracts on BNB Chain, forcing cross-chain companies to quickly pause earlier than the vulnerability was patched and techniques resumed operation.
NEAR Intents Traces Exploit to Omni Infrastructure Bug
NEAR Intents recognized the preliminary trigger as a bug in how the Omni deposit/withdrawal infrastructure interacts with the protocol’s good contracts. Based on NEAR co-founder Illia Polosukhin, the incident solely affected USDT in a vault on BNB Chain; NEAR Protocol, the NEAR token, and different functions throughout the ecosystem weren’t compromised.
Earlier at this time NEAR Intents companies have been stopped after a safety incident was detected. The incident was attributable to a bug within the Omni deposit and withdrawal infrastructure interplay with NEAR Intents good contract.
The preliminary report signifies the full lack of…
— NEAR Intents (@near_intents) October 1, 2026
NEAR Intents is an intent-based cross-chain buying and selling infrastructure. Customers specify the belongings they need to ship and obtain, whereas execution events often called solvers compete to seek out and full the transaction route. Omni helps bringing belongings into and out of the system throughout a number of blockchains, saving customers from having to pick out bridges manually or deal with particular person steps themselves.
The vault on BNB Chain pays out belongings upon receiving a signed withdrawal message from the system facet. On-chain evaluation by Bitquery exhibits that the attacker’s withdrawals used the identical message format as common transactions, however blockchain information can not clarify why these requests have been issued or permitted. NEAR Intents has not but disclosed the source-code degree root trigger and acknowledged {that a} detailed autopsy report might be launched later.
Attacker Drained $3.87 Million in 5 Main Withdrawals
5 withdrawals over six hours eliminated a complete of 3,865,000 USDT from the BNB Chain vault, based on transaction information reconciled by Bitquery. Many of the injury was concentrated in underneath an hour, as the primary three transactions eliminated a complete of $3.5 million USDT from the system.
The primary main withdrawal transferred 800,000 USDT at 23:54 UTC on September 30. Two subsequent transactions price 1.2 million and 1.5 million USDT adopted throughout the subsequent 56 minutes. The vault continued to payout 330,000 USDT at 01:46 and 35,000 USDT at 06:08 on October 1.
Previous to the sequence above, the related handle executed two take a look at withdrawals price 10 USDT and 11 USDT on the night of September 30. An handle linked to this pockets had additionally deposited 10 USDT into the vault two days earlier. These small transactions present that the system efficiently processed requests from the linked handle group earlier than giant sums have been withdrawn.
The dimensions of those transactions was additionally considerably totally different from latest vault exercise. Within the two days previous to the incident, the most important stablecoin payout was valued at underneath $400,000.
Most Stolen Funds Have been Transformed to Bitcoin
Roughly 76% of the stolen funds have been transformed into 34.69 BTC and distributed into 4 Bitcoin wallets. These wallets had not transferred the BTC away when inspected at 14:30 UTC on October 1. One other roughly $802,000 went into deposit addresses labeled KuCoin, whereas practically $90,000 was recorded in a Monero-linked asset on Hyperliquid.
These three asset teams accounted for about 99% of the full worth tracked by Bitquery. On-chain labels point out that funds reached KuCoin’s infrastructure, however the controller of the receiving accounts couldn’t be recognized. The above figures mirror the state of belongings earlier than NEAR Intents introduced that all the $3.8 million had been returned on October 2.
Companies Restored After Contract Patch
NEAR Intents paused operations after detecting the incident and patched the contract-side vulnerability inside one hour, based on NEAR co-founder Illia Polosukhin. NEAR Intents and close to.com subsequently resumed operation, whereas sure cross-chain deposit and withdrawal routes required extra time to finish Omni infrastructure updates.
In its preliminary announcement, the mission acknowledged that deposit and withdrawal features throughout 11 networks would expertise additional disruption for about 12 hours. This checklist included BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. The NEAR Intents standing web page at present marks core companies, cross-chain infrastructure, built-in blockchains, and web sites as working usually.
NEAR Intents initially dedicated to totally compensating affected customers. The mission didn’t disclose the variety of impacted accounts or a payout plan previous to asserting that each one stolen funds had been returned on October 2.
Funds Returned Earlier than 48-Hour Deadline
On October 2, Alex Shevchenko, normal supervisor of NEAR Intents, introduced that each one $3.8 million had been returned and the mission would halt its investigation. The funds arrived earlier than the 48-hour deadline he established after claiming the group had recognized the occasion behind the exploit.
The funds from the $3.8M NEAR Intents hack have been despatched again in full.
We’re stopping the investigation.
Please use bug bounties as an alternative of disrupting the companies.
— Alex Shevchenko 🇺🇦 (@AlexAuroraDev) October 2, 2026
The related handle initially despatched 0.295 ETH and 1 BNB alongside a request to speak through Sign. Subsequently, a Bitcoin handle printed by Shevchenko acquired roughly 34.59 BTC throughout 5 transactions, valued at practically $2.95 million. The rest was returned through one other route, however NEAR Intents has not launched a full breakdown.
The mission has additionally not disclosed the identification of the occasion concerned or the monitoring strategies used. NEAR co-founder Illia Polosukhin acknowledged that the group recognized the accountable occasion in underneath 24 hours with assist from SHIELD and inner investigative efforts.








