On October 1, 2026, the NEAR ecosystem experienced one of the year's most significant security breaches when attackers exploited a vulnerability in the Omni Bridge contract, draining approximately $3.8 million in cross-chain assets. For affected users, the immediate panic has given way to critical questions: How do I file a claim? When will I receive my refund? What happens to my assets?
This is not just another headline. If you lost funds in the NEAR Intents exploit, understanding the recovery process—and what the latest September 2026 updates mean for your specific situation—could be the difference between recovering partial losses and losing everything. We've compiled the authoritative guide to navigating the refund landscape, complete with step-by-step claim procedures, recovery timelines, and verified resources.
At 14:32 UTC on October 1, 2026, an attacker identified only by a wallet address beginning with "0x7f2e..." executed a series of transactions that exposed a critical flaw in the NEAR Intents Omni Bridge architecture. The vulnerability allowed the attacker to craft malformed cross-chain messages that bypassed signature verification, essentially creating false proof-of-transaction for assets that were never actually transferred.
The exploit affected users attempting to bridge assets—primarily USDC, Ethereum, and NEAR tokens—between multiple blockchains. According to CoinDesk, the attacker drained funds across three distinct transactions within a 12-minute window, moving assets to multiple mixing services before law enforcement could freeze addresses.
NEAR Protocol responded within 90 minutes by pausing the Omni Bridge contract and alerting validators. The technical team patched the vulnerability within 6 hours. However, the damage was already done: 847 individual users lost funds, with the largest single loss being approximately $412,000.
Price Impact: The NEAR token dropped 8.6% within 24 hours of the exploit's public disclosure, closing at $3.24. This decline reflected broader market concerns about cross-chain bridge security—a pattern seen earlier in 2026 when Bitget's platform suffered a $50 million hack prevention incident that still shook investor confidence.
As of September 28, 2026, the NEAR Foundation has completed Phase 1 of its victim reimbursement program. Here's the official breakdown:
| Recovery Phase | Status | Timeline | Affected Users |
|---|---|---|---|
| Phase 1: Claim Verification | Complete | October 1 - October 18, 2026 | 847 verified victims |
| Phase 2: Asset Custody | In Progress | October 19 - November 10, 2026 | All phase 1 users |
| Phase 3: Distributed Reimbursement | Pending | November 11 - December 31, 2026 | Eligible claimants |
| Phase 4: Dispute Resolution | Pending | January 2027 onwards | Contested claims only |
The NEAR Foundation approved $5.2 million for immediate compensation, which covers approximately 68% of verified losses. Users with losses exceeding $50,000 will receive 70% of their loss amount; users with smaller losses receive 85% coverage. This tiered approach prioritizes protecting retail investors while maintaining the foundation's financial stability.
The NEAR Foundation's claims portal operates through a transparent, blockchain-verified system. Here's exactly what you need to do:
"The key difference between this recovery and previous exploits is transparency and speed. NEAR Foundation published real-time claim verification data, allowing victims to see exactly how many claims were processed and approved. This builds trust when the entire community can audit the process." — Pro Trader Daily Analysis Team
Not all assets lost in the exploit are eligible for recovery under Phase 1. Here's the official eligibility matrix:
If you lost assets in a flash loan or were using borrowed funds through lending protocols, your situation is more complex. You remain personally liable for repaying the lender, but NEAR Foundation covers your original loss amount. File a claim for the full asset amount; include documentation of any outstanding lending obligations for accuracy.
Navigating recovery after a crypto exploit can feel isolating. Here are verified support channels:
Contact the NEAR Foundation support team with your claim details. If you can verify ownership through transaction history, email associated with the wallet, or exchange withdrawal records, you can still file a claim. You won't need direct wallet access—documentation of ownership is sufficient.
Yes. All claims must be submitted by November 15, 2026. After this date, the portal closes and no new claims are accepted. Late submissions are not reviewed except in cases where documented medical or technical circumstances prevented earlier filing.
It depends on your loss amount and the total number of approved claims. Early estimates suggest victims will recover 70-85% of losses. Users with losses under $50,000 receive 85% reimbursement; users above $50,000 receive 70%. This tiered system ensures the $5.2 million fund equitably covers the most affected users.
Losses exceeding the proportional allocation trigger Phase 4 (dispute resolution) starting January 2027. NEAR Foundation will work with insurance partners and potential additional funding to address shortfalls. However, the foundation has made clear that 100% reimbursement of all losses exceeding $50,000 is not guaranteed.
The vulnerability has been patched and audited by external security firms. NEAR Foundation is conducting additional stress tests through November 2026. A phased reopening is expected in December 2026, initially with lower transaction limits and enhanced monitoring. No official reopening date has been announced.
NEAR Foundation is voluntarily reimbursing victims despite no legal obligation—the exploit targeted a user-facing bridge feature, not the core protocol. Users accepted risk when engaging with experimental cross-chain infrastructure. Legal action is unlikely to yield better outcomes than participating in the foundation's recovery program. Consult an attorney if you believe there was negligent security disclosure.
If you were affected by the October 1 exploit, your immediate action items are:
| Event Name: | Omni Bridge Vulnerability Exploit |
| Date: | October 1, 2026 |
| Amount Lost: | $3.8 million USD |
| Affected Component: | NEAR Intents cross-chain bridge (Omni Bridge) |
| Vulnerability Type: | Signature validation bypass in contract logic |
| Users Impacted: | 847 individual accounts |
| Recovery Fund: | $5.2 million allocated by NEAR Foundation |
| Claim Deadline: | November 15, 2026 |
| Compensation Rate: | 70-85% of documented losses (tiered) |
| Asset Classes Covered: | USDC, wETH, NEAR, wBTC, DAI, qualified LP tokens |
| Status as of Sept 28: | Phase 2 (Asset Custody) underway; Phase 3 reimbursement pending |
The NEAR Intents exploit is not an isolated incident. It reflects a systemic challenge in cross-chain bridge architecture that has plagued the entire crypto ecosystem throughout 2026. Earlier vulnerabilities affected multiple platforms, forcing developers to prioritize speed over security. The NEAR Foundation's transparent recovery approach sets a standard for responsible incident handling—but it also underscores the reality that users bear significant risk when engaging with cutting-edge infrastructure.
For traders and investors, this exploit serves as a reminder that decentralized systems, while revolutionary, require due diligence. Spreading capital across multiple wallets, using tested bridges with proven security track records, and maintaining emergency reserves in cold storage are no longer optional precautions—they're essential components of risk management in crypto.
The fact that NEAR Foundation allocated $5.2 million for victim recovery demonstrates institutional commitment to user protection. However, this recovery will likely cover only 68% of losses. That 32% gap represents real money—users' retirement savings, emergency funds, business capital—that will not be recovered. Understanding this reality is critical as you decide whether to re-engage with DeFi platforms or step back entirely.
For next steps, explore our complete crypto coverage to understand emerging bridge security solutions and safer alternatives for cross-chain asset transfers. If you're evaluating whether to continue using NEAR-based protocols, our DeFi risk assessment guide provides frameworks for evaluating protocol security and operational history.
Explore our trading strategy resources to develop risk management protocols that protect your capital across all platforms. For broader context on 2026's security landscape, our fintech analysis covers institutional responses to rising exploit frequency.
Start Your Refund Claim Now