Advertisement

Watch four AI agents manage money in public.

Subscription opening soon. Not financial advice.

Hack Database

NEAR Intents: $3.87M Drained, Then Handed Back After a 48-Hour Ultimatum

A bug let someone drain $3.87M in digital dollars from NEAR Intents. An AI alarm shut it down, and a 48-hour ultimatum got all of it back.

NEAR Intents: $3.87M Drained, Then Handed Back After a 48-Hour UltimatumLogo: NEAR (GitHub)
NEAR Intents, the cross-chain trading system on NEAR Protocol.

Key numbers

  • $3.87M

    Stolen

  • $3.87M (all)

    Returned

  • Identified, not named

    Attacker

  • Under 1 hour

    Bug fixed in

On Thursday 1 October 2026, a piece of software watching NEAR Intents noticed money leaving in a pattern it did not like. NEAR Intents is a trading service that lets people swap one digital currency for another across dozens of separate blockchains, and it handles more than $4 billion a month. The watchdog, an AI monitoring layer called SHIELD, raised the alarm and the whole service was switched off.

By then about $3.8 million was gone. PeckShield, a blockchain security firm that tracks hacks, put the figure at $3.865 million. All of it was Tether (USDT), a "stablecoin" that works as a digital dollar, and all of it came out of a single account on BNB Chain, a blockchain closely tied to the Binance exchange.

At 12:53 UTC the NEAR Intents team posted that "services were stopped after a security incident was detected", blamed "a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract", and promised the losses "will be compensated in full". Three hours later Illia Polosukhin, co-founder of NEAR Protocol and one of the eight authors of the 2017 Google paper that introduced the "transformer" behind today's AI chatbots, confirmed it on X:

Advertisement

Powered by Cyntri AI

The technology behind this newsroom. Built by Cyntri AI.

AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.

Powered by Cyntri AI

"Earlier today, NEAR Intents was exploited for $3.8m. SHIELD, the AI security layer on Intents, detected outlier behavior and Intents were temporarily paused. All of the affected users will be compensated in full."

About a day after that, the money was back. The return came with a note written into the blockchain, which Coin Bureau shared: "We've returned all the funds, we were in the wrong. Thank you to the Near team for being respectful, constructive, and cordial during the return process. Remember to always use bug bounties!" Nobody had been arrested, no reward had been announced, and the investigation was closed.

What NEAR Intents does

Most crypto trading works like an order on a stock exchange: the buyer picks the venue, the route and the price. An "intent" system turns that around. The customer states only the outcome they want, such as "swap 1,000 digital dollars on BNB Chain for bitcoin and send it to this address", and a crowd of professional market makers, called solvers, compete to deliver it. It is close to a fund manager telling several brokers what to buy and letting them fight for the order. Whoever offers the best price does the work, across whichever blockchains are needed.

NEAR Intents is one of the biggest of these systems. It runs on NEAR Protocol, and wallets and apps plug into it rather than building their own links between blockchains. Part of that plumbing is called Omni: the deposit and withdrawal machinery that takes coins in from other networks such as BNB Chain, Polygon or TON and pays them back out.

To pay customers quickly, that machinery keeps a "hot wallet" on each network. A hot wallet is an account that is connected to the internet and run by software, the crypto version of the cash drawer at a bank counter. It is never meant to hold everything, only enough to cover the day's withdrawals, which is why the damage stopped at a few million dollars.

How the money got out

The fault sat at the seam between two pieces of software. Omni handled deposits and withdrawals. The NEAR Intents smart contract, code that moves money by itself according to fixed rules, kept the books. Somewhere in the way the two talked to each other, the attacker found a way to make the BNB Chain hot wallet pay out Tether it should not have paid. Polosukhin said the flaw was "isolated to USDT on BSC", BSC being the older name for BNB Chain.

Neither NEAR Intents nor anyone else has yet published the promised technical report, so the exact mistake is not public. The trail is. ZachXBT, a pseudonymous investigator who follows stolen crypto through public blockchain records, reported that the protocol's BNB Chain hot wallet showed irregular outflows, and that the money was sent to KuCoin, a large crypto exchange, and then bridged into bitcoin. A bridge is a service that moves value from one blockchain to another, much as a currency desk swaps pounds for dollars.

The team said the contract bug was fixed "within an hour of detection", and swapping resumed about an hour after the shutdown. Deposits and withdrawals stayed closed for roughly 12 more hours on 11 networks: BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. The NEAR blockchain itself, its NEAR token and the other apps built on it were not touched.

The NEAR token still took the hit. It fell about 7 per cent, to around $4.96 according to The Block, two days after Bitwise had launched the first US exchange-traded fund holding NEAR on NYSE Arca.

The alarm that caught it, and the week before

SHIELD had been in the news days earlier for a different reason. After thieves took $387.5 million from the Bitget exchange on 24 September, they tried to launder part of it through NEAR Intents, swapping stolen coins into other currencies to break the trail. Alex Shevchenko, general manager of NEAR Intents and a co-founder of Aurora Labs, said on 29 September that SHIELD had blocked more than $50 million of those attempts and frozen $503,000 mid-transaction, while about $166,000 got through. "Refusing to help launder stolen assets is one of ours," he said of the choices the builders of these systems make.

Within a week the same system had been tested from both sides: first as a gate the Bitget thieves wanted to walk through, then as a building someone was emptying from the inside. In the second case it did its job, but only after $3.8 million had already left. SHIELD watches for unusual behaviour and pulls in warnings from compliance and analytics firms. It is a burglar alarm, not a lock.

Polosukhin framed the incident as an arms race. "The crypto space is entering a new era of far more sophisticated cyber attacks," he wrote, naming Bitget, MetaMask and Lido as recent targets of "criminals equipped with AI systems". He said NEAR would add formal verification, a mathematical proof that code does exactly what it claims, to its software "as part of the release process". It was, he wrote, "the first major exploit on Intents".

The 48-hour letter

Bar chart of hours after the exploit was confirmed: fix at 3.0, ultimatum at 11.4, full return at 25.6CMZ chart. Source: NEAR Intents, Polosukhin and Shevchenko on X
From the exploit to the full refund, in hours.

At 00:18 UTC on 2 October, Shevchenko posted a message on X aimed at one reader. "We have identified you, sir," it began, followed by three addresses, on Bitcoin, BNB Chain and Ethereum, and Solana, where the money could be sent. "You know better than most how responsible disclosure works," he wrote, adding that "this is the last window to use it. After 48 hours, that window closes."

"Responsible disclosure" is the security world's term for finding a flaw and reporting it privately instead of using it. Companies often pay for such reports through a bug bounty, a published reward for researchers who come forward. The words "better than most" suggested the team believed it was dealing with someone from that world, not a faceless gang. NEAR has not named the person or explained how they were found. Polosukhin credited SHIELD "along with some aggressive detective work". The money had passed through KuCoin, an exchange that normally checks its customers' identities, but neither NEAR Intents nor KuCoin has said whether that played a part.

The reply came on the blockchain itself. According to the news account Coin Bureau, the recovery address received 1 BNB carrying a short note: "Willing to cooperate, reply with your Signal so contact is possible." Signal is an encrypted messaging app.

Polosukhin said the funds came back in full at 14:30 UTC that day. An analyst posting as Kuncoro checked the published addresses and found 34.59 bitcoin, worth about $2.95 million, had landed at the Bitcoin address, which meant the rest had come back by some other route. Shevchenko replied: "You are right. It did indeed."

At 15:52 UTC Shevchenko posted: "The funds from the $3.8M NEAR Intents hack were sent back in full. We are stopping the investigation. Please use bug bounties instead of disrupting the services." Polosukhin added: "for security researchers looking for exploits, we encourage you to use bug bounties. They exist for a reason."

For the attacker, the arithmetic was simple. Once identified, keeping traceable money meant the risk of prosecution in exchange for $3.8 million that every exchange would now be watching for. Handing it back meant the investigation stopped. NEAR has not said whether anything was promised in return, and no reward has been announced.

The aftermath

Every dollar came back, so the compensation NEAR Intents had promised its users was never really tested. The team said the money was returned in full on 2 October, about a day after it disappeared, and Alex Shevchenko closed the investigation the same afternoon. No arrest, charge or reward has been announced, and the person responsible has not been named.

The full post-mortem that NEAR Intents promised "in the following days" had not been published by 4 October, so the exact bug in the Omni deposit and withdrawal system remains private. What has changed is policy. Illia Polosukhin said NEAR would build formal verification into its release process for contracts, and invited other projects to join SHIELD and share warnings faster.

The episode lands in a bad stretch for the industry. PeckShield counted 55 major hacks in September 2026 with $766.49 million lost, the worst month of the year, led by Bitget at about $387 million and Liquid Network at about $320 million. Less than two weeks earlier, an attacker printed tokens with a headline value of $16.77 million through SingularityNET's bridge and cashed out about $2.29 million. NEAR Intents got its money back without announcing any payment at all.

It is also the second large hack on NEAR this year, after Rhea Finance, a trading and lending app on the same blockchain, lost $18.4 million in April. For NEAR the timing was awkward: the hack came two days after Bitwise launched the first US exchange-traded fund holding the NEAR token, and the token fell about 7 per cent on the news.

What this teaches

  • The weak point is often the seam between two systems. Each piece can be sound on its own and still fail where one hands money to the other.
  • A hot wallet caps the damage. Keeping only a day's float online is why a service moving $4 billion a month lost $3.8 million, not hundreds of millions.
  • Monitoring is an alarm, not a lock. SHIELD stopped the bleeding but only after the money had already left.
  • Money sent through a large exchange leaves a trail. Within a day the team said it knew who it was dealing with.
  • Bug bounties exist so researchers can be paid without breaking anything. Both NEAR leaders ended by asking people to use them.
Advertisement

AI agents and automation

Could AI answer your customers from your own documents?

Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.

AI agents and automation