Shevchenko Says NEAR Intents' $3.8M Returned in Full After Ultimatum
NEAR Intents GM Alex Shevchenko says the $3.8M drained in the October 1 exploit was returned in full within his 48-hour deadline.
AI SummaryAI
- Alex Shevchenko confirmed on October 2 that NEAR Intents' stolen $3.8M was returned in full.
- The October 1 exploit drained about $3.8M via the junction between Omni's deposit and withdrawal infrastructure and NEAR Intents' smart contracts.
- ZachXBT traced the stolen funds to KuCoin and then across a bridge into Bitcoin.
- Shevchenko gave the attacker a 48-hour deadline and offered responsible-disclosure treatment for compliance.
Full Return After a 48-Hour Ultimatum
The roughly $3.8 million taken from
NEAR Protocol (NEAR) Intents now sits in return addresses the team itself published, the service's general manager Alex Shevchenko confirmed on Friday, October 2. In a post on X (his official statement), Shevchenko said the funds drained during the security breach at the cross-chain swap service had been “returned in full,” closing out the ultimatum tied to the case. The incident began on Thursday, October 1, when NEAR Intents detected the breach and paused its cross-chain swaps. A preliminary investigation pointed to a defect at the junction between Omni's deposit and withdrawal infrastructure and the platform's smart contracts, through which about $3.8 million in user funds left the system, a figure that matches the on-chain movement of the money. Omni provides the deposit and withdrawal rails the swap venue leans on, and the fault sat exactly where those two components meet. The team patched the vulnerability and pledged to compensate the affected assets in full. Deposits and withdrawals remained frozen while engineers worked through the fault.
NEAR Protocol (NEAR) Intents then reported it had identified the person behind the incident. Shevchenko published a set of addresses for the repayment, gave a 48-hour deadline, and framed compliance as a final chance to have the act treated as “responsible disclosure.” He set the 48-hour window after the project said it had pinned down who was responsible. In the Friday post he said the investigation would now close and urged the actor to use the project's bug bounty program in the future rather than disrupting the service. The repayment covers the entire drained amount, with no shortfall disclosed as of Friday. Our live monitoring shows the NEAR price 4.4% higher over the past 24 hours, and nothing in the session's trading suggests lasting damage to the NEAR Protocol ecosystem's market standing.
KuCoin Trail, Then a Bridge Into Bitcoin
Before the money came back, it left a documented trail. On-chain investigator ZachXBT traced the funds to KuCoin and then across a bridge into Bitcoin (BTC), the last stops recorded before the full return, and he published that trace while the ultimatum was still running. The stepwise path, exchange first and bridge second, gave investigators two distinct points to work from. Routing through a centralized exchange matters in a case like this, because venues such as KuCoin hold KYC records on their customers, the kind of data that has in past incidents shortened the distance between an on-chain trace and a named account.
NEAR Protocol (NEAR) Intents, the affected venue, is the ecosystem's cross-chain swap service, an intent-based design in the same category as dappOS: users state the outcome they want and solvers execute the transfer, rather than trades routing through an automated market maker pool. The service has been halted since the October 1 detection, and as of Friday the team had not said whether deposits and withdrawals have reopened or how the restitution to users will be executed in practice. Operations on the platform itself, not on the broader chain, were what went dark. The pledge to make affected users whole, in effect a form of DeFi insurance carried by the protocol itself rather than a third party, covers the drained assets in full according to the project's own statement. Full repayment after a protocol breach is uncommon, and the speed here, inside two days from detection to return, stands out. The platform also fields preventive tooling: its SHIELD screening system earlier stopped $503,000 in flows connected to the Bitget hack. The coin entered October carrying momentum from a 100%-plus September rally, which is one reason the incident drew such close attention from holders.
What the Post-Mortem Establishes
The record here is unusually complete. The drain amount, the integration fault between Omni's deposit and withdrawal rails and the swap contracts, the patch, and the full $3.8 million return are all attested by the team's own statement and by the on-chain movement of the funds, not by secondhand accounts. The remediation follows the standard playbook for a contained breach: fix the defect, make users whole, and push future disclosure through a bug bounty rather than an exploit. As of the Friday post, the entire sum rests in the addresses NEAR Intents designated for the return, after its last documented stops at KuCoin and the bridge into Bitcoin, and the open question is when the service reopens on those hardened rails.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

