NEAR Protocol Platform Recovers Stolen $3.8 Million Following Hacker's Voluntary Return

A hacker returned $3.8 million in stolen USDT to the NEAR Intents crypto exchange protocol on October 2nd, meeting the deadline imposed by platform leadership who claimed to have identified the attacker. The theft occurred between September 30th and October 1st through a vulnerability in the interaction between the Omni deposit-withdrawal layer and the main smart contract, allowing five separate withdrawals totaling 3.865 million USDT from a vault on BNB Chain. On-chain analysis revealed that roughly 76 percent of the stolen funds had been converted to Bitcoin and 21 percent had reached KuCoin exchange before being returned.
The vulnerability exploited in this incident stemmed from a flaw in how NEAR Intents' withdrawal layer communicated with its core smart contract managing vault assets on BNB Chain. The attacker executed a methodical approach, first testing the system with minimal amounts before conducting five substantial withdrawals over approximately six hours. The speed of fund recovery—completed within 48 hours—suggests either the threat of public identification proved effective or the attacker independently determined that proceeding further carried unacceptable risk. The partial conversion to Bitcoin and movement through KuCoin indicated an attempt to obscure the trail, though on-chain transparency ultimately enabled complete tracking.
This incident may influence user confidence in decentralized finance protocols, particularly regarding the adequacy of smart contract auditing and operational safeguards. The voluntary return could be perceived positively as demonstrating accountability mechanisms work, or negatively as revealing that vulnerability disclosure threats rather than technical security prevented losses. Broader implications may extend to regulatory scrutiny of DeFi platforms and insurance requirements, potentially affecting development costs and accessibility of emerging financial infrastructure.