What is going on

NEAR Intents, a popular cross-chain swap tool, recently became the target of a major security breach. An attacker successfully exploited a vulnerability in the protocol's Omni deposit and withdrawal system, siphoning off $3.8 million. The incident triggered a total pause of services across 11 networks, including major ones like Polygon, Optimism, and BNB Chain, as the team scrambled to secure the platform. While blockchain investigators like ZachXBT initially tracked the stolen assets being moved to exchanges, the situation took a positive turn when the NEAR Intents team identified the exploiter and issued a 48-hour ultimatum for the return of the funds. The tactic worked, and the hacker sent the assets back, allowing the team to call off their investigation and make users whole.

How we got here

  • September 24, 2026: A massive $387.7 million hack on Bitget leads to a philosophical clash between protocols, with NEAR Intents using its SHIELD security layer to block some hack-linked flows while others like THORChain refuse.
  • October 1, 2026: The Bitwise NEAR ETF launches.
  • October 2, 2026: NEAR Intents suffers a $3.8 million exploit due to a vulnerability in their fund transfer management layer and halts services.
  • October 3, 2026: The NEAR Intents team announces the full recovery of all stolen funds following their ultimatum to the hacker.

Why it matters

In the DeFi world, hacks are usually permanent losses for users, making the NEAR Intents recovery a significant outlier. This incident serves as a double-edged lesson: on-chain security can be incredibly fragile, yet rapid, transparent communication can mitigate disaster. It also highlights the ongoing debate within crypto regarding "permissionless" design versus active security intervention. While some purists argue that protocols should never interfere with transactions, the success of the SHIELD layer and the swift recovery suggest that active security measures may be necessary for protocols to earn long-term user trust.

What happens next

The protocol has patched the vulnerability in its contract and restored services, with the team promising a full report on the incident. While the price of NEAR saw a sharp dip following the news, the company’s commitment to reimbursing users has been framed by some as a sign of institutional maturity. Moving forward, the team has urged future attackers to use official bug bounty programs rather than disrupting services, emphasizing that professional disclosure is the only sustainable way to test infrastructure.

FAQ

Was any user money lost in the hack? No, the team successfully recovered 100% of the stolen funds and committed to making all affected users whole.

How did the team get the money back? They identified the exploiter and issued a 48-hour ultimatum, which prompted the hacker to return the funds in full.

Is the NEAR Intents platform safe to use now? The team patched the vulnerability that allowed for the exploit and has resumed standard operations across their supported networks.

Our latest coverage