NEAR Intents Exploit: $3.87 Million Drained and Recovered, Full Details Still Awaited
Just two days after NEAR Intents publicly distanced itself from laundering illicit assets (source), the protocol experienced a major breach: $3.87 million was illicitly withdrawn, with a portion of the funds cycled back through NEAR Intents' own infrastructure (Bitquery analysis).
Bitquery's investigation identified a sole prior deposit by the attacker on BNB Chain before the exploit: 10 USDT (link).

During a window of approximately six hours from September 30 to October 1, a vault on BNB Chain transferred 3,865,000 USDT to the attacker's wallet in five separate transactions, each backed by what appeared to be standard signed withdrawal authorizations (source).
While the exploit was ongoing, roughly $822,000 of the stolen assets passed through NEAR Intents' own service, with 750 BNB re-entering the vault under attack.
Thirteen hours after the initial major withdrawal, NEAR Intents released its first public statement regarding the incident (first large withdrawal).
Alex Shevchenko, NEAR Intents' general manager, then posted: “We have identified you, sir,” along with three addresses for asset recovery and a 48-hour deadline.
Well before that period expired, the attacker requested a Signal contact handle.
Shortly thereafter, Shevchenko announced that the stolen funds had been fully returned, and that the investigation would be halted (same post).
NEAR Intents confirmed the recovery of the assets, but the detailed post-incident report that had been promised was not released (source).
The incident raises a lingering question: if withdrawal requests were properly signed and processed, how did a deposit of just 10 USDT entitle the attacker to nearly $3.87 million in withdrawals?
References: Bitquery, NEAR Intents, Alex Shevchenko, ZachXBT, AMLBot, Unchained, Illia Polosukhin, Gracy Chen, NEAR, HOT Protocol, Veridise, Solidity, The Block, Rhea Finance, Vini B., Hackenproof
For the entire six-hour window, on-chain records indicate only the attacker's activity in the vault.
The initial transactions were small: 10 USDT withdrawn at 18:57 UTC on September 30, followed by 11 USDT at 20:05. Major withdrawals began at 23:54, when 800,000 USDT was taken, followed by 1.2 million and 1.5 million, all from the same wallet.
Bitquery's analysis shows that prior to the exploit, the vault's largest single stablecoin withdrawal over two days was less than 400,000 USDT. That limit was far surpassed in less than an hour across three transactions.
A further 330,000 USDT was withdrawn at 01:46, and the final withdrawal of 35,000 USDT occurred at 06:08, over six hours after the first significant payout.
No public warnings were issued as the theft was underway.
At 12:53 UTC on October 1, NEAR Intents disclosed that its services had been paused due to a bug in the interaction between its Omni-based infrastructure and the associated smart contract. The preliminary loss was reported at approximately $3.8 million, with a commitment to full reimbursement and a notice that deposits and withdrawals across 11 chains would remain suspended for about 12 more hours.
ZachXBT alerted his audience at the same time, noting irregular outflows from the BSC hot wallet (0x233c), the cessation of transactions, and an incident impacting multiple EVM chains as displayed on NEAR Intents' status page. According to his report, the stolen assets were already sent to KuCoin and bridged to Bitcoin.
AMLBot followed at 13:15 UTC, flagging close to $4 million in suspicious withdrawals across four transactions, but was unable at that point to determine whether it was an exploit or related to another event.
Unchained later identified another payout at 13:27: roughly 215,000 USDT was transferred to an address with a history of receiving large sums from the same vault during the preceding month.
At least one regular payout channel continued to function.
Illia Polosukhin, NEAR's co-founder, released a more comprehensive update at 15:50, stating that SHIELD, the platform's AI-powered security component, had flagged anomalous activity, prompting a temporary halt to Intents. The vulnerability, he said, was isolated to USDT on BNB Chain and resolved within an hour of detection. He also linked this exploit to a wider trend of AI-assisted attacks targeting various platforms, including Bitget, MetaMask, and Lido.
Although the fix was applied within an hour of discovery, NEAR has not clarified when it became aware of the breach, what withdrawal triggered the alert, or the exact time the relevant withdrawal path was closed.
Recent media coverage had highlighted SHIELD's earlier success: Shevchenko had shared SHIELD's results after the Bitget incident, citing over $50 million in flagged laundering attempts and $503,000 frozen, with public acknowledgment from Bitget’s CEO, Gracy Chen (source).
In this case, SHIELD is credited with detecting anomalous activity during the exploit, which consisted of five withdrawals over more than six hours.
If SHIELD did notice irregularities, what explains the continued payouts after multiple large withdrawals had already exceeded recent precedents?
The Withdrawal Process
NEAR Intents asserts that it identified and patched the vulnerability within an hour.
However, the specific nature of the bug was not publicly detailed.
On BNB Chain, the vault processed signed withdrawal instructions, while on other chains, a separate mechanism determined user entitlements.
This distinction is central to understanding the exploit.
NEAR’s documentation offers partial insight.
The exploited contract, 0x233c…b4cd, is identified as the HOT Bridge treasury (reference), one of three bridges available for Intents (overview). The HOT Bridge handles assets via HOT/Omni infrastructure for BNB, Polygon, Optimism, Avalanche, Scroll, Monad, TON, Stellar, LayerX, Adi, and Plasma — matching the 11 chains NEAR Intents temporarily suspended (source).
_HOT Bridge documentation describes the withdrawal process as cross-system: the HOT OMNI Balance contract on NEAR burns the user’s omni-token, records the withdrawal, and generates a nonce.**
The user then obtains an attestation from HOT Protocol’s MPC validator network, each node verifying the withdrawal’s existence in OMNI Balance.
The user submits the signature, nonce, and withdrawal details to the destination locker, which checks the signature and nonce before releasing funds. The system does not independently confirm balances — it only validates the signed withdrawal request and nonce (Bitquery).
Bitquery found the attacker's withdrawals used this standard authorization format.
One difference noted: in all seven exploit withdrawals, the recipient directly submitted the request, while other reviewed payouts were submitted by a distinct address (Unchained).
HOT’s design allows any account to submit a user-signed withdrawal intent, so this is not inherently a bug, but it does confirm the attacker had valid authorizations.
Prior to the exploit, only a 10 USDT deposit on BNB Chain is linked to the attacker; any balance the system credited on other chains isn't visible from BNB Chain. The system later authorized a 1.5 million USDT withdrawal, suggesting a critical failure or missing check in the off-chain logic controlling entitlements.
While NEAR's statement named the affected system interaction, it stopped short of explaining the technical pathway for the exploit.
A subsequent regression test in the public repository details the prevented condition: refund requests could exceed deposited amounts, and very large refund events could hit NEAR’s log-size limit, causing the callback to fail — “as happened to the deployed revision.”_
A late September 30 mt_resolve_deposit callback involved 98 token/amount pairs, most being one-unit entries for an unusually long token ID, plus a large sum in another token.
This callback failed due to a log message exceeding NEAR’s 16,384-byte limit.
Sample Deposit Transaction:
3mst2uZ32KPuCs7wc8rJqEtCrZqugCy4yDSZ3df8KPm3
The receipt logs the immediate failure: the callback was aborted due to an oversized log.
The regression test enforces that refund requests cannot exceed deposits.
It remains unclear how this failed callback led to inflated withdrawal authorizations for the attacker. Bitquery’s analysis similarly concludes it can track the outflows, but cannot fully explain the bug’s mechanics.
An external security report noted 21 issues (including critical and high-severity findings); 18 were reportedly fixed. The most serious included lack of access control and a double-spend vulnerability due to missing nonce checks — both addressed in the codebase reviewed._
The MPC also fetched configuration details from contracts outside the audit’s scope.
While these factors do not directly pinpoint the exploit's cause, they highlight validation boundaries that future reviews should address.
Polosukhin stated that the vulnerability was fixed within an hour and promised a thorough postmortem, with plans to add formal verification to NEAR contracts. Formal verification can only confirm the code matches its specification, not that the specification itself is complete or correct (Solidity docs).
Bitquery counted five major USDT withdrawals totaling 3,865,000 USDT, following two test withdrawals.
NEAR’s regression test addresses a specific upstream issue, but does not document the full exploit route that enabled multimillion-dollar withdrawals. Bitquery’s post-mortem can trace funds, but not the exact exploit mechanism.
The ultimate technical root cause is still only partially public. The asset trail, however, is well documented.
Where did the funds go after withdrawal?
Tracing the Funds
The stolen USDT was swiftly exchanged.
BscScan identifies the treasury and attacker wallets, making the flow unusually transparent (HOT Bridge: Treasury, Near Intents Exploiter 1).
Attack Wallet: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37
Drained Vault: 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd
- Withdrawal 1: 800,000 USDT
- Withdrawal 2: 1,200,000 USDT
- Withdrawal 3: 1,500,000 USDT
- Withdrawal 4: 330,000 USDT
- Withdrawal 5: 35,000 USDT
The attacker converted the stablecoins to BNB, split the BNB into mostly 100-250 BNB parcels, and distributed them to 32 new wallets). Bitquery observed these wallets being used briefly before falling silent.
Poisoning bots sent lookalike tokens to these wallets within minutes, with some transactions predating the public disclosure (Bitquery).
Seven main exit routes were used to drain BNB from BNB Chain. The largest, a cross-chain swap (unnamed), handled about 2,318 BNB (~$1.78 million) from 23 wallets, delivering ETH and Bitcoin to the attacker's network. MetaMask bridge moved 805 BNB to Ethereum, and 800 BNB was sent to a KuCoin route (0xcd87c2e1f53b7df97f1db56aec6c63cbd60bb262). Smaller amounts went through other platforms like LI.FI.
Router for Unnamed Swap Service: 0xadd2b3801d64905b4eebf67ef52cca63ee792d1d
Two of the exit pathways sent funds back through NEAR Intents).
About 80 minutes into the attack, the main attack wallet sent 650 BNB into two CoW Swap orders for ETH on Ethereum. CoW Swap records list NEAR Intents as the bridge, and the BNB was returned to the same vault being drained.
NEAR Intents’ Ethereum hot wallet then paid 185.5 ETH to the attacker’s Ethereum address.
On-chain payouts:
Later, a helper wallet sent 100 BNB back to the BNB vault; two subsequent Ethereum deposits (totaling 91.7 ETH) were also traced, with NEAR Intents paying out the resulting orders in Bitcoin to addresses already linked to the attacker.
Bitquery estimates about $822,000 of the stolen funds, approximately 20% of the total, was routed through NEAR Intents during the exploit, with 750 BNB returning to the exploited vault.
The attacker received two further payouts from the vault after the first of those deposits.
On-chain flows do not indicate what NEAR Intents knew or when: these are automated transactions, not direct evidence of intent or awareness.
A NEAR Intents post days before this event cited SHIELD's record as missing $166,000 in one prior laundering attempt, versus $50 million detected and $503,000 frozen (source). This time, about five times that amount passed through NEAR Intents during the exploit.
Bitquery tracked roughly 955 ETH to attacker-linked Ethereum wallets, all of which were subsequently routed to Bitcoin.
Chainflip processed 17 deposits to Bitcoin over two hours; subsequent swaps were rejected for undisclosed reasons.
Soon after, the attacker sent 1 ETH as a test swap on THORChain, followed by five more swaps, with the last near midday. Bitquery noted the same protocols were used by the Bitget attacker a week prior.
All traced Bitcoin payouts landed at two addresses, with the smaller consolidating into the larger.
Bitcoin Aggregation Address:
bc1qsyrcmlxj9kaglnmqetwghnvssqjezs6pqwtsn8
At 06:40 UTC on October 1, the address began distributing funds, first in two transactions (15.7675 BTC and 7.88375 BTC) to new wallets in a 2:1 split, repeating the pattern with smaller sums. Bitquery suggests this could signal a partner split, payment to a helper, or something else.
Distributions were traced to four wallets:
- bc1qzsrxkzwdah6343kj4rafr56v84xrzuzrlhvtn8
- bc1qjkdzyt845q0vte6sax2nn9j40zdalec3q4zmrc
- bc1qkm5d88p472cg73n7tgw8dpv243v36jjmmnzktz
- bc1q4kddgqsuqmwmzq3qgv0aq2jr9jgdwesx0wljen
These later transfers were part of the recovery. Funds from all four addresses ultimately ended up at the Bitcoin recovery address published by Shevchenko on October 2.
Bitcoin Recovery:
bc1qjhv3hu8rfteh5e8exfmalvx2z3pzlmjlgnzxey
The second most significant destination was KuCoin, reached by two distinct routes.
On BNB Chain, five new wallets deposited 800 BNB each to an address that then quickly moved the funds into KuCoin wallets. This address had been active since August 6.
KuCoin BNB Address: 0xcd87c2e1f53b7df97f1db56aec6c63cbd60bb262
On Ethereum, 70 ETH passed through intermediary wallets into three KuCoin deposit addresses, each with a history of multiple senders. Two intermediaries had received Gate withdrawals just before the exploit. Bitquery noted this resembled over-the-counter (OTC) activity, not a specific laundering setup.
KuCoin ETH Deposit Addresses:
- 0xecf2383f813de458857b092fba4059aa8caed7a8
- 0x1b181e14902bf94fd22c4c4656b71f7b6c4b8324
- 0x25b4826d04271e0bc5645c07faa022ab34abc2a5
Together, these channels handled about $802,000. Only KuCoin can link these deposits to user accounts.
The Block reported that KuCoin did not respond to requests for comment.
One early segment was different: about an hour into the exploit, 120 BNB was swapped and bridged to Arbitrum as USDC, quickly transferred to Hyperliquid and spent on the XMR1 token, representing Monero.
Hyperliquid Account: 0x0e77cbf891b90c73e2fc5dff6d78ec2e383c8616
No further movement was observed in this route during the analysis window. 165.3 XMR1 (then valued at about $90,000) remained untouched.
By October 1, Bitquery reported tracing 99% of the stolen USDT: 76% to Bitcoin, 21% to KuCoin, 2% to XMR1, and 1% lost to fees and slippage.
Shevchenko soon addressed the attacker with “We have identified you” but did not give specifics.
When a project claims to have identified an exploiter but withholds details, is it evidence, leverage, or a strategic move?
Alleged Attacker Identification
At 00:18 UTC on October 2, Shevchenko issued a statement and published three recovery addresses.
“We have identified you, sir.”
Recovery Addresses:
- Bitcoin: bc1qjhv3hu8rfteh5e8exfmalvx2z3pzlmjlgnzxey
- BNB/Ethereum: 0xB18a1aEDfde8B70FD67012C9E9c7a088B4d0C0e7
- Solana: AHTfKaeRcaK1sbSG8MFJS2uPxLBChfenigNtvbWEkhKD
[The language suggested an opportunity for the attacker to return the funds and treat the event as a white-hat disclosure. “You know better than most” implied security expertise but fell short of identification.
Shevchenko has used similar communication before: following the $18.4 million Rhea Finance breach (link), he alerted the attacker on-chain that they had been identified (message). Rhea later reported recovering millions in USDC and NEAR, with other assets frozen (details).
This time, the response came on-chain.

Sender: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37
Recipient: 0xB18a1aEDfde8B70FD67012C9E9c7a088B4d0C0e7
The attacker attached a request for a Signal handle with the transfer.
Vini B. publicized the message. Previously, he had criticized NEAR Intents for freezing Bitget-connected funds (link), advocating neutrality for permissionless systems.
This time, he called the arrangement obvious and speculated the attacker might keep a 5–10% bounty. This was only his estimate, not an official term.
Between 14:31 and 15:05 UTC on October 2, the recovery address received 34.58927254 BTC:
- 58c6487fe95c5fa51317eaa7ba2d327e80262c23ebb11e6c579d0c05c13d5665
- 45ad939aebb42044a3313eaa5eb363d65a9fd96ce20f4d546eea14089c033d8f
- 1f24b67e0135f4d7be6cfe1d450e42d2b5e16f147170ad85881cc96148695e73
- 767ac8c26443c85d91bd5d58759d4742480ab4b8fe737cde33d9ef60e3d44613
- 1205e8a86dfe8375a7ee5989524bfae63769e76d9db026f6931c0ba208dea216
At 15:52 UTC, Shevchenko posted that the funds had been fully returned and the investigation would be closed. He advised future white hats to use bug bounty platforms instead of disrupting live systems.
NEAR Intents’ official account confirmed: “The investigation is closed.”
While the team stated that all funds were recovered, the comprehensive technical explanation and a full audit report have yet to be released.
The incident statement attributed the loss to a bug involving Omni’s infrastructure and NEAR’s Intents contract, noting that a contract patch had been applied, further infrastructure fixes were ongoing, and law enforcement had been notified. A detailed public report was promised “in the following days.”
As of October 8, no such report has been published. The available statements outline the affected systems and the response, but do not clarify the exploit’s inner workings or future preventative measures.
Returning the funds addressed the recovery, but the technical specifics and law enforcement outcome remain unaddressed in public statements.
No breakdown of the returned assets or details of the arrangement have been published (Shevchenko’s post).
Although the Bitcoin return is visible, the fate of other assets such as the XMR1 tokens on Hyperliquid and the $802,000 sent to KuCoin is not clarified in the statements.
This does not necessarily mean those funds were unrecovered, but a full reconciliation is missing.
No bug bounty or other incentives have been disclosed in connection with the recovery.
Shevchenko had previously discussed bug bounty incentives publicly after the Bitget incident, but following the NEAR exploit, he simply encouraged the attacker to use bounties in the future, without clarifying if one was given here.
That program enforces responsible disclosure, not draining live funds.
There is ambiguity even in the published bug bounty maximum: the table lists $300,000, while written rules state $100,000; a 10% formula would have exceeded both caps for the $3.87 million loss.
Whether this bug was in-scope for the bounty program is not clear from public sources.
Shevchenko had previously offered to waive NEAR Intents' share of a bounty for Bitget (source), demonstrating willingness to discuss incentives in other contexts.
Here, the terms remain undisclosed.
The contrast is notable: researchers are directed to a formal, restrictive process, while an attacker who drained live funds was engaged for cooperation, and after the return, the investigation was declared closed.
This does not confirm the attacker was rewarded, but the public is left without clarity on any consequences or concessions.
The outcome is a successful recovery, but not a substitute for the technical postmortem that was promised.
The public timeline of the recovery is available. The specific terms and a detailed technical explanation remain absent.
At what point does the language of responsible disclosure shift into post-hack negotiation?
The bridge that once blocked stolen funds spent one night handling its own.
A BNB Chain vault disbursed $3.87 million based on signed authorizations, with Bitquery confirming signature verification but noting that the balance logic was handled elsewhere.
NEAR Intents announced a contract patch and further infrastructure fixes, attributing the exploit to the interaction between Omni and Intents, but did not provide a detailed technical breakdown in public statements.
The recovered Bitcoin is visible at NEAR’s published address. NEAR claims that all funds were returned, but whether any portion was retained by the attacker as a reward is not addressed.
The recovery has been documented; the technical narrative is incomplete.
The record includes an ultimatum, a 1 BNB transaction with a chat request, and a detailed report that was promised but never published).
Except, instead of a detailed report, NEAR’s next public message was simply: “the investigation is closed.”
SHIELD, NEAR Intents’ risk monitoring system for suspicious transactions, was praised for catching earlier laundering attempts. Yet, the exploit on a NEAR Intents-linked vault lasted over six hours, and public acknowledgment came about thirteen hours after the first major withdrawal.
Asset recovery is only half the equation. Transparency about what failed and how it was fixed is the other. Closing the investigation without a full report leaves that gap unaddressed.
When the funds are returned but the technical answers never arrive, what is truly restored?
Get new scam files the moment we publish them — usually 2–3 emails a week.