Invest3 publishers3 min readPublished
NEAR Intents recovers all $3.8 million lost to a bug in its deposit-and-withdrawal layer
NEAR Intents got back all $3.8 million drained through a bug between its Omni deposit-and-withdrawal layer and its contract, after encrypted talks. Whether that layer is safe now rests on the patch, since every user who lets the protocol choose a bridge depends on it.
The Investor · Invest desk

What happened
- Co-founder Illia Polosukhin said the damage was limited to USDT on BNB Smart Chain, with the NEAR token, the core protocol and other network apps untouched.
- Eleven networks, among them BSC, Polygon, TON and Scroll, stayed restricted for roughly another 12 hours while repairs finished.
- General manager Alex Shevchenko posted recovery wallets for Bitcoin, BNB and Solana and gave the attacker 48 hours to send the funds back.
- The NEAR token slipped about 6% in the hours after the news, trading near $4.95 before settling around $4.81.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- exposure A user who hands NEAR Intents the bridge choice cannot price or avoid the Omni layer separately, so a defect in that layer becomes the user's own exposure.
- constraint Repairs to one shared layer kept 11 of the protocol's 35 reported chains, about 31%, restricted for half a day, though the loss touched one token on one chain.
- cost NEAR Intents promised full reimbursement before any money came back, so an attacker who kept the $3.8 million would have left the protocol to pay it.
NEAR Intents' product removes a choice from the user. A user states the outcome of a trade, independent market makers called solvers fill it, and the user never picks a bridge or an exchange [4]. The design has reportedly carried more than $30 billion of volume across 35 blockchains [5]. According to the protocol's posts on X, Thursday's bug sat in how its Omni deposit and withdrawal infrastructure interacted with its smart contract, and the fault has since been patched [2].
Against volume, the loss looks small. $3.8 million [1] over $30 billion is about 0.013%, roughly one dollar in every 7,900 that has passed through [1]. Or rather, it is small against cumulative volume, a denominator that grows every day the layer works and tells a user little about how far a single bug can reach.
The terms of the return are harder to read. "We have identified you, sir," general manager Alex Shevchenko wrote [10]. He later thanked the attacker "for your willingness to cooperate" and pointed to messages that could be decrypted with the private key of an Ethereum address [11]. After the money came back he wrote: "We are stopping the investigation. Please use bug bounties instead of disrupting the services." [12] A protocol that said it knew who the attacker was has now stopped looking [10][12]. The source does not report whether the attacker kept a bounty. The GMX exploiter returned about $37.5 million in July 2025 after accepting a 10% white-hat bounty [16]. Euler Finance recovered more than $177 million of a $197 million hack from March 2023, about 90% [15][3].
One reading is that the patch holds and 0.013% is the right size for the risk [1]. A second is that a full return in exchange for a dropped investigation becomes the template the next attacker expects [12]. A third is that co-founder Illia Polosukhin's account of damage confined to USDT on BNB Smart Chain [6] describes luck, and the next bug in the same layer reaches further.
I think the first reading is too generous. The protocol has shown it can police tainted money: before the hack it turned away more than $50 million tied to the September 24 Bitget breach and froze about $503,000 through its SHIELD risk system [13]. Shevchenko has said builders cannot run infrastructure designed to "help launder stolen funds" [14]. That record concerns other people's stolen money. Thursday's loss came through the protocol's own deposit-and-withdrawal code [2]. The attacker's refund paid for this incident, and whether the code is safe now rests on the patch alone.
This view is wrong if a NEAR Intents post-mortem shows the Omni layer caps what any one bug can withdraw, so that confinement to one token on one chain was the design working and not chance.
What to watch
- A NEAR Intents post-mortem stating whether the Omni deposit-and-withdrawal layer limits what one bug can withdraw per token or per chain.
- Any disclosure of whether the attacker kept a bounty or got other terms in the encrypted negotiation.
- Volume across the protocol's 35 chains after the halt, as a test of whether users have repriced the Omni layer risk.