0x4fecbfa84fec…4fecbfab
NEAR Intents Recovers $3.8M From Exploit, Closes Investigation
Cross-chain protocol NEAR Intents recovered the full $3.8 million drained from its BNB Chain treasury after issuing a 48-hour ultimatum, closing its probe on October 4.
Outputs
Attacker drained approximately $3.87 million USDT from a NEAR Intents treasury contract on BNB Chain via multiple withdrawals between September 30 and October 1
The protocol's SHIELD AI security layer flagged the activity; services were paused and the vulnerability patched within an hour
GM Alex Shevchenko issued a 48-hour ultimatum on October 2 with return addresses across BTC, EVM and Solana; the full amount was returned and the investigation closed October 4
Deposits and withdrawals on 11 networks, including BNB Chain and Polygon, stayed paused for around 12 hours during remediation
Days earlier, NEAR Intents had blocked transfers linked to the Bitget hack, stopping nearly $50 million and freezing $503,000 in attempted transactions
NEAR Intents has recovered the full $3.8 million drained from its treasury contract in a late-September exploit and formally closed its investigation on October 4. The suspected exploiter returned the entire amount after General Manager Alex Shevchenko issued a public 48-hour ultimatum, according to statements from the cross-chain trading and settlement protocol.
The incident began between September 30 and October 1, when a critical bug in the protocol's smart contracts allowed an attacker to withdraw USDT from a treasury contract deployed on BNB Chain. The drain was executed through multiple withdrawals spread across the two days, totaling approximately $3.87 million in USDT.
NEAR Intents' internal detection systems caught the attack in progress. The protocol's SHIELD AI security layer flagged the anomalous withdrawals, and the team responded by pausing services and patching the vulnerable contract within an hour of detection, according to the protocol's account of the incident.
Shevchenko said the team had identified the suspected exploiter. On October 2, he set a 48-hour deadline for the return of the funds and published specific return addresses across Bitcoin, EVM-compatible chains and Solana. The suspected entity returned the full $3.8 million, and the protocol closed its investigation two days later. NEAR Intents has also committed to compensating users affected by the incident.
The operational recovery took longer than the code fix. Deposits and withdrawals on 11 networks, including BNB Chain and Polygon, remained suspended for roughly 12 hours while the team repaired infrastructure affected by the exploit. Operations resumed on those networks after the remediation was completed.
The exploit landed at an awkward moment for the protocol. Just days before the incident, NEAR Intents had blocked fund transfers connected to a separate hack of the Bitget exchange, reportedly stopping nearly $50 million in potentially affected funds and freezing $503,000 in attempted transactions.
Operational implications for cross-chain infrastructure
The attack surface was a single treasury contract on BNB Chain, but the blast radius extended across the protocol's entire deployment footprint. The subsequent pause covering 11 networks illustrates a core structural risk in cross-chain settlement systems: a vulnerability in one chain's contracts can force a multichain halt because treasury and liquidity operations are interconnected across deployments.
A critical contract bug reached production and drained approximately $3.87 million before intervention. The protocol's own tooling detected the flaw, engineers patched it within an hour, and the funds returned within days after the protocol publicly named a suspect and set a firm deadline — an outcome that relied heavily on the attacker's cooperation rather than formal recovery mechanisms.
The incident will likely sharpen scrutiny of treasury contract architecture across cross-chain protocols, particularly the concentration of USDT liquidity in single-contract treasuries deployed on third-party chains. NEAR Intents says its investigation is closed and affected users will be compensated, but the episode demonstrates how quickly a single production bug can propagate operational risk across an 11-network footprint.
via Crypto Briefing (Source)