Logo Daily Crypto Briefs
Open menu

NEAR Intents Says Full $3.8M Hack Loss Recovered

6 min read
Large official black and orange near Intents wordmark on an off-white stone plaque beside an unbranded greyscale open metal cashbox containing blank transaction receipts, against orange and slate-blue editorial panels.

TL;DR

  • General manager Alex Shevchenko says all of the approximately $3.8 million taken in the NEAR Intents exploit was returned on October 2.
  • The published Bitcoin return address received about 34.59 BTC; the remaining roughly $850,000 used another route, Shevchenko confirmed.
  • Recovery changes the loss outlook, but a complete transaction reconciliation and customer reimbursement record remain undisclosed in the reviewed sources.

October 4, 2026

NEAR Intents recovered the full approximately $3.8 million taken in its exploit, its general manager said on October 2, a material reversal of the cross-chain service’s loss outlook as NEAR traded near $4.83 on October 3.

Alex Shevchenko said the team had stopped investigating after the return. Bitcoin transfers support a substantial recovery, while a complete public accounting of the remaining assets and customer reimbursements was not established.

NEAR’s October 3 daily price was $4.8313, up 3.03%, with a $4.6101 to $4.8663 range, according to Investing.com’s historical table. It remained about 9.5% below September 30’s $5.34. The market move does not establish that recovery news caused the gain.

In his October 2 announcement, Shevchenko said the stolen funds were “sent back in full.” The statement describes recovered assets, rather than publishing a customer payment ledger.

Our October 1 report on the exploit and service restart documented an estimated loss, a compensation pledge and restrictions across 11 networks. The new development is the announced full return, not another revision to the initial loss estimate.

NEAR Protocol

NEAR
Sep. 4-Oct. 3, 2026
$4.83
+122.4%
Sep 4 - Oct 3 | High $4.89 • Low $2.17

Source: Investing.com, sampled daily prices. Token prices do not measure recovered assets or customer repayments.

NEAR Intents recovery includes 34.59 BTC

The Bitcoin address Shevchenko published received approximately 34.59 BTC on October 2. Daily Crypto Briefs independently checked the address’s confirmed transaction records through Mempool’s blockchain data.

The public address history places the relevant confirmations between 14:31 and 15:05 UTC. Those are block-confirmation times, which can differ from when a transfer was initiated or an operator considered the return complete.

Researcher Kuncoro valued that Bitcoin at approximately $2.95 million using $85,200 per coin. He estimated that roughly $850,000 had returned through another route, and Shevchenko confirmed that assessment.

That residual figure is approximate arithmetic against the team’s rounded $3.8 million estimate. It is not an independently verified sum of every non-Bitcoin repayment, and the reviewed reply did not supply the missing transaction hashes.

The distinction prevents a misleading conclusion from a single wallet: about $2.95 million visible at the Bitcoin address does not imply that the remaining amount was still missing. Conversely, management’s confirmation does not make the full recovery independently reproducible from that address alone.

Bitquery’s original tracing counted 3,865,000 USDT taken in five large withdrawals between September 30 and October 1. It located 34.69 BTC in four wallets and approximately $802,000 reaching KuCoin deposit addresses as of October 1 at 14:30 UTC.

Those figures describe the theft’s earlier destinations. They are not current unrecovered balances and should not be added to the later return as another loss. The difference between the team’s rounded estimate and Bitquery’s tally still calls for a final reconciliation.

As of October 4 at 01:10 UTC, the reviewed sources did not establish an affected-customer count, a customer-level repayment total or a separate new attack wave. The best-supported loss picture is an observed theft followed by a full-recovery claim with substantial Bitcoin corroboration.

Returned funds do not reopen every transfer route

The project’s initial disclosure attributed the incident to the interaction between Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. It said the contract-side flaw was patched and promised full compensation.

Its immediate response distinguished resumed swaps from continuing restrictions on deposits and withdrawals. That distinction remains relevant after an asset return: a restored balance inside a service and an available route to an external wallet are separate outcomes.

At this article’s live browser check, the SHIELD status page displayed ongoing chain incidents for Scroll, ADI, Stellar, Optimism, Avalanche, Polygon, BNB Smart Chain, TON, Monad and X Layer, alongside resolved entries.

The page’s entries are operational notices. Overlapping chain and intents entries cannot establish additional thefts, newly compromised wallets or a fresh attack wave, and a resolved entry does not necessarily cover every function on the same network.

The official bridge documentation describes multiple connections between external blockchains and the settlement contract, with different supported chains and trust models. Restoring one component therefore does not prove that every connection has reopened.

That differs from the network halt during Taiko’s bridge exploit. Here, the relevant customer checks concern the specific deposit or withdrawal route and its operating status, rather than assuming a service incident means the underlying blockchain stopped.

Recovered assets can reduce the operator’s funding burden if they replace the stolen value. Completed compensation still requires a record showing that affected balances were restored or payments delivered; no such consolidated record accompanied the reviewed recovery announcements.

NEAR closes probe as SHIELD details remain limited

Shevchenko’s earlier demand gave the alleged exploiter 48 hours to return the assets and supplied addresses on Bitcoin, BNB Chain or Ethereum, and Solana. The October 2 recovery announcement came before that window closed, changing the response from an outstanding demand to a reported settlement.

NEAR co-founder Illia Polosukhin credited SHIELD and the team’s investigative work with identifying the responsible party, establishing contact and getting the assets back. He placed the full return at 14:30 UTC on October 2 and said security hardening was underway.

That account attributes a role to the AI security layer, but does not disclose the identification method or isolate SHIELD’s contribution from other investigative work. It cannot independently establish which intervention prompted repayment.

The Crypto Times reported an on-chain return message in a BNB Chain transaction. Daily Crypto Briefs also decoded its transaction input through a public chain node. A message acknowledging repayment supports the narrative, but cannot prove the total returned or the sender’s identity.

The project’s security documentation directs vulnerability reports to its bug-bounty program. Encouraging disclosure through that channel does not establish that a bounty was paid in this incident; settlement terms were not disclosed.

The team’s decision to stop investigating also does not establish that any separate law-enforcement inquiry ended. The initial disclosure said the incident had been reported to authorities; the reviewed recovery statements did not supply a corresponding official disposition.

The recovery also concerns service assets rather than a return on NEAR investments. Bitwise’s NEAR ETF launch milestones concern a separate investment vehicle, whose shares and token exposure are distinct from a customer’s cross-chain transfer balance.

Alternative.me’s Bitcoin-focused Fear and Greed Index read 65, or Greed, on October 4, compared with 67 the previous day. It measures broader market sentiment, not the safety of a transfer route or the success of compensation.

Fear & Greed Index

October 4, 2026
65 Greed

The next substantive evidence is a final loss-and-return reconciliation, completed customer compensation and network-specific reopening notices. Under the team’s account, the stolen assets are back; the reviewed record does not yet resolve every operational or customer-accounting question.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

Has NEAR Intents recovered the $3.8 million hack loss?

General manager Alex Shevchenko said on October 2 that the funds were returned in full. About 34.59 BTC is visible at the published Bitcoin return address; a complete public reconciliation of all routes was not established.

How much Bitcoin was returned to NEAR Intents?

The published return address received approximately 34.59 BTC on October 2. Researcher Kuncoro valued it near $2.95 million using $85,200 per bitcoin; that historical valuation is not a current quote.

Did every affected NEAR Intents user receive reimbursement?

The team promised full compensation, but the reviewed sources did not establish a completed customer repayment total, affected-user count or customer-level reconciliation as of October 4 at 01:10 UTC.

Does recovered money mean every NEAR Intents transfer route is open?

No. Asset recovery and service availability are separate. The SHIELD status page still displayed ongoing chain incidents at the article's check, alongside resolved entries.

Was a new NEAR Intents attack wave confirmed?

The reviewed sources did not establish a separate new wave. Continuing or overlapping service incident entries should not be counted as additional thefts.