NEAR Intents confirmed that the hacker responsible for draining $3.8 million has refunded the entire amount following a standoff initiated by the protocol’s suspension of services. The breach originated from a bug in the Omni deposit and withdrawal infrastructure interacting with smart contracts, affecting only USDT on the BNB Smart Chain. General Manager Alex Shevchenko identified the perpetrator and established a private, encrypted communication channel using an Ethereum address to negotiate the return of assets within a 48-hour window.
Prior to this incident, NEAR Intents had processed over $30 billion in volume across 35 blockchains and recently blocked $50 million linked to the Bitget breach. Co-founder Illia Polosukhin noted that the core NEAR token and other network applications remained unaffected, though the NEAR price dipped approximately 6% during the crisis. Blockchain investigator ZachXBT traced the stolen funds from a BNB Chain hot wallet to KuCoin before they were bridged into Bitcoin, marking one of the few full recoveries in recent crypto history.
This event highlights the evolving dynamics of post-exploit recovery in decentralized finance, where direct negotiation and technical tracing often yield faster results than traditional law enforcement channels. The successful retrieval of $3.8 million underscores the importance of rapid incident response capabilities, including the ability to freeze operations and identify specific wallet addresses quickly. By leveraging encrypted communication and public pressure through social media, NEAR Intents demonstrated a pragmatic approach to asset recovery that bypasses the lengthy timelines associated with legal proceedings.
From a market structure perspective, such recoveries may influence how institutional investors assess operational risk in cross-chain protocols. While the incident exposed vulnerabilities in the interaction between deposit infrastructure and smart contracts, the full refund mitigates immediate financial damage to users. However, it raises questions about the long-term sustainability of relying on attacker cooperation rather than robust preventive security measures. Stakeholders should monitor whether this precedent encourages more frequent negotiation-based resolutions or if it inadvertently signals that exploits can be monetized with minimal consequences if funds are eventually returned.


