NEAR Intents Hacker Returns $3.8 Million in Full
The attacker who drained about 3.87 million USDT from a NEAR Intents vault on BNB Chain sent it all back on 2 October. What happened and what to check.
The attacker who drained about $3.8 million in USDT from a NEAR Intents vault on BNB Chain returned the money in full on Friday, 2 October 2026, a day after the cross-chain swap service disclosed the exploit. The return transaction on BNB Chain was confirmed at 16:15 UTC (9:45 pm IST), and NEAR Intents general manager Alex Shevchenko then said the team was stopping its investigation. The NEAR token trades at ₹469.13 on our NEAR Protocol price in INR page.
Key takeaways
- About 3.87 million USDT, roughly ₹37 crore, was taken from a single vault on BNB Chain between 30 September and 1 October. The loss was confined to that vault.
- The cause was a bug in how the Omni deposit and withdrawal system worked with a NEAR Intents smart contract, not a stolen private key.
- Deposits and withdrawals were paused on 11 networks for about 12 hours while the flaw was fixed.
- NEAR Intents promised on 1 October to compensate affected users in full, before any money came back.
- On 2 October Shevchenko gave the attacker 48 hours to return the funds. The money, including about 34.6 BTC, came back the same day.
What happened
NEAR Intents is a service that lets users swap tokens across many blockchains by stating what they want and letting solvers fill the order. On the afternoon of Wednesday 30 September, US time, an attacker began pulling USDT out of a treasury vault on BNB Chain through several withdrawals. The flaw sat in the link between the Omni bridge system, which handles deposits and withdrawals on other chains, and a NEAR Intents contract. The service's AI-based monitoring layer, called SHIELD, flagged the unusual activity and services were paused.
The attacker moved the stolen USDT through the CoW Protocol settlement contract and several fresh addresses, sent some to the KuCoin exchange, and swapped roughly three-quarters of it into about 34.6 BTC. On 2 October Shevchenko said the team had identified the person responsible and gave a 48-hour window for a return, publishing recovery addresses for Bitcoin, EVM chains and Solana.
| When (UTC) | What happened |
|---|---|
| 30 September to 1 October | About 3.87 million USDT withdrawn from the BNB Chain vault |
| 1 October | NEAR Intents discloses the exploit, pauses 11 networks and pledges full compensation |
| 1 October | Bug fixed; services resume after about 12 hours |
| 2 October | 48-hour deadline issued to the attacker |
| 2 October, 16:15 | Return transaction confirmed on BNB Chain; about 34.6 BTC also sent back |
| 2 October | Investigation stopped after full recovery |
The numbers
| Measure | Figure |
|---|---|
| Amount taken | About 3.87 million USDT (about ₹37 crore) |
| Amount returned | All of it |
| Networks paused | 11, including BNB Chain, Polygon, TON, Optimism and Avalanche |
| Pause length | About 12 hours |
| NEAR price at 14:28 UTC, 3 October | $4.643, about ₹447 at ₹96.37 per dollar, down 5.2% in 24 hours |
NEAR has slipped from about $5.34 at the start of 1 October (UTC), but the wider market has also fallen this week, so the move cannot be pinned on the exploit alone.
Why it matters for Indian investors
A full return is unusual. Most stolen crypto is laundered and never recovered, and September 2026 was the worst month for hacks this year, as we reported in crypto hacks hit $766 million in September. Shevchenko urged researchers to use bug bounty programmes instead of disrupting services, a reminder that some attackers are opportunists who can be persuaded to give funds back.
The bigger lesson is about bridges and cross-chain tools. Each extra link between chains adds code that can fail. If you hold USDT, keep it on the network your Indian exchange supports and move it as few times as you can. Our guide to USDT on TRC20, ERC20 and BEP20 explains the networks, and BEP20 is the BNB Chain version involved here. Our explainer on how crypto hacks happen covers simple safety steps.
SHIELD has a track record: last month the same layer helped block swaps linked to the Bitget hacker, as we covered in NEAR Intents blocks $50 million in Bitget hacker swaps.
What to watch next
- Incident report: NEAR Intents called its loss figure preliminary, so a fuller report may follow.
- Compensation: with the money back, check that any affected balances are restored.
- Bounty terms: the team has not said whether the attacker received any reward.
FAQ
Did NEAR Intents users lose money in the hack?
NEAR Intents promised on 1 October to compensate affected users in full, and the entire stolen amount was returned on 2 October 2026. The loss was limited to one USDT vault on BNB Chain.
Was the NEAR blockchain hacked?
No. The bug was in how the Omni deposit and withdrawal system interacted with a NEAR Intents contract, and the loss was confined to a vault on BNB Chain.
Is NEAR Intents safe to use now?
The flaw was fixed within about 12 hours and services resumed. No cross-chain service is free of risk, so use amounts you can afford to lose and avoid leaving funds parked in bridges.
This article is AI-assisted, educational and general in nature. It is not financial advice and never a guarantee of profit. Every trade is at your own risk on your own exchange. See our risk disclosure and editorial policy.