My experience exiting shielded ZEC from Zodl to NEAR Intents: $589k USDT still held 50 days despite a written compliance clearance

Hi everyone,

I want to share my experience because I believe it raises an issue that matters to anyone holding shielded ZEC who may eventually want to use an integrated exit path. The issue is what “integrated” really means when the shielded pool, the wallet and the exit rail are presented as one seamless experience, but the trust model changes once the funds leave the shielded pool.

As of 8 September, approximately $589,000 USDT derived from swapping 1,120 shielded ZEC has been held by NEAR Intents for 50 days. That is despite a written compliance clearance on 23 July and a confirmed refund request raised the same day. One month of silence later, the same matter was put back under an “ongoing” review.

I want to be precise about what happened, because three separate layers are involved here and they behaved very differently.

Separating the three layers

1. The Zcash shielded pool

The shielded pool did exactly what it is designed to do.

My ZEC remained shielded and private while I held it. When I decided to move 1,120 ZEC from my shielded balance, it moved as expected. I still hold a larger ZEC balance shielded in the same wallet today.

Nothing in this post is a criticism of Zcash’s core privacy technology or the operation of the shielded pool.

2. Zodl

Zodl is the wallet through which I hold my shielded ZEC. At the time this happened, Zodl’s own support documentation described NEAR Intents this way:

“Swaps leverage our integration with the NEAR Intents decentralised exchange, so your swaps are trustless and don’t depend on a centralised third-party.”

I saved a copy on the Wayback Machine on 7 August: Swapping into ZEC - Zodl Support

On 17 August, while my case was still unresolved and after I had contacted them for help on 6 August, that wording was changed to:

“Swaps leverage our integration with NEAR Intents, where independent market makers compete to fill your order at the best rate and settlement is enforced on-chain by smart contract – no account or signup required.”

The page Swapping into ZEC - Zodl Support now also includes: “Important notes: Swaps are subject to NEAR’s Terms of Service.”

That distinction matters to me because the way NEAR Intents was presented and integrated into the wallet materially influenced how much I trusted it with size.

3. NEAR Intents

NEAR Intents is the swap rail integrated into Zodl.

What happened

On 20 July, I sent 1,120 shielded ZEC from my Zodl wallet to NEAR Intents and swapped it into ~$589k USDT. I withdrew the USDT to a new MetaMask address, then straight to a new Ledger address.

About eight hours later, I sent the exact same USDT from that Ledger address to a new Ethereum deposit address generated by NEAR Intents for another swap.

The transaction confirmed on-chain, but the deposit was never credited.

The USDT came only from those shielded ZEC to USDT swaps executed on NEAR and touched only the two newly created ETH addresses. It never went through any exchange, bridge, mixer, DeFi protocol, or any other third-party service. No other funds and no other transactions ever entered or left those two addresses. The exact same USDT amount left NEAR and returned to a NEAR-generated deposit address. The ETH gas itself came from NEAR, from those same shielded ZEC swaps.

MetaMask address: 0x85e5e691B99AEa7b0D42a493C12f78bc077E38f4

Ledger address: 0x22E62aeD6696a1f089e98e63A35b63d6fDC2f287

NEAR Intents deposit address: 0x47c3646e7fe6d619293602E9cD8bD1CF4127fDBe

Deposit transaction hash: 0x1366d07f63a18719a674840d02a84d5b830d8c26186afb28bb050401d3038f8d

I am sharing these addresses and the transaction hash so anyone who wants to can independently verify the on-chain flow.

Initially, support described the problem as technical. They attempted to push the deposit manually, confirmed it was stuck, and escalated it.

Around twenty hours later when I asked for an ETA, I was told there was a “temporary withdrawal restriction applied to your funds to facilitate a necessary administrative review.”

I voluntarily supplied the addresses, transaction hashes, swap history, screenshots, proof that the ZEC originated from my Zodl wallet, and an explanation of the entire flow. I also offered to prove ownership of the addresses by signing a verification message.

23 July: compliance review “successfully concluded”

On 23 July, NEAR Intents wrote:

“We are pleased to notify you that the compliance review concerning your recent deposit has been successfully concluded.”

They also stated:

“All associated funds will be released and accessible for use.”

And:

“All administrative restrictions on your account have been fully removed.”

They then asked me to confirm the address and chain so they could credit the funds back to my wallet: “Could you please confirm the refund address and chain so we can credit the funds back to your wallet?”

I provided the same Ledger address from which the USDT had been sent.

Their response was:

“Thanks for confirming the address, Tim! I have raised the refund request to the team and will let you know as soon as it’s processed.”

At that point, I understood the matter to be resolved subject only to execution of the refund.

It was not executed.

What happened after the clearance

My follow-ups on 24 July, 27 July, 31 July, 11 August and 17 August all were ignored and produced no execution of the refund.

On 29 July, after the ticket had gone quiet, I asked through NEAR’s public Telegram channel. I was told that manual refunds normally take around two weeks and that I would receive a transaction hash when the refund was processed.

That two-week period expired on 6 August.

That morning I politely asked support for an escalation. An admin replied that they would escalate the matter again. One minute later I was muted from the Telegram channel for 24 hours.

Also on 6 August, I contacted the Zodl team with the full documentation.

Neal from Zodl replied the following day that they were speaking with their contacts at NEAR and later requested a status update regarding the refund.

On 18 August he told me that NEAR said a “status update” had been sent to me on 7 August, and that he was escalating further. I never received that update.

No refund followed from either escalation. I followed up with Zodl again, but they did not reply.

26 August: one month of silence then back under compliance review

On 22 August I emailed NEAR’s legal contact requesting execution of the refund. No reply.

On 24 August, I published a public article about the case on X.

A day and a half after the publication, the support ticket suddenly moved.

On 26 August, after one month of silence without any refund, and for the first time since 23 July, NEAR Intents replied to the support ticket and said:

“Please be advised that your pending transaction has been paused subject to ongoing standard regulatory compliance reviews.”

They also said they were:

“unable to provide a definitive timeframe for release.”

This raised an obvious question…

On 23 July, I had been told that the compliance review had been successfully concluded, that all associated funds would be released, and that all administrative restrictions had been fully removed.

On 26 August, I was being told that the transaction was once again subject to an ongoing compliance review with no release date.

I therefore asked NEAR three specific questions:

  1. Does the 23 July confirmation that the compliance review was successfully concluded remain accurate?
  2. If a new review was opened, when was it opened and what transaction or event triggered it?
  3. What is the status of the refund request confirmed on 23 July?

On 27 August, they replied.

“While an initial determination was communicated on July 23, subsequent administrative and compliance verification required returning the matter to a pending review status. As a result, the review has not been fully concluded and remains actively under evaluation."

They said that:

“This is a continuation of the initial review, which was returned to pending review status.” And that “The refund request raised on July 23 remains on record, but execution is contingent upon final compliance clearance. The refund cannot be processed while the review remains pending.”

They did not identify a new transaction or event that caused the change.

They did not provide a date on which the review was returned to pending status.

They did not provide a date for a final determination.

On 27 August I asked in the ticket on what date the status had changed from “successfully concluded” to pending. That question has not been answered.

Where things stand today

Today is 8 September.

It has been 50 days since the deposit.

The funds have not been returned.

There is no refund transaction hash.

There is no release date.

I still haven’t heard back from Zodl about the explanation they promised regarding what caused this issue in the first place.

And the compliance review that NEAR told me in writing had been “successfully concluded” is now described as an “initial determination,” with the same review once again pending indefinitely.

Why I think this belongs on the Zcash forum

I am not posting this because the Zcash shielded pool failed. It did not.

I am also not asking the Zcash community to adjudicate NEAR’s compliance procedures or recover the funds for me.

I am posting because this experience changed how I think about the practical exit path from shielded ZEC.

The Zcash protocol layer, the wallet layer and the exit layer are distinct parts of the user experience, with different roles and trust assumptions.

Products like Zodl want to make the power of Zcash zero-knowledge encryption simple enough for ordinary people to use and, ultimately, simple enough to reach billions of users. That means abstracting away complexity where possible. But simplifying the experience should not blur a change in the trust model or leave users with an understanding of the integrated path that does not match how it actually works in practice.

Technically, the three layers are distinct. But to the user, they are integrated into one interface and experienced as one continuous path from holding Zcash, shielding it, sending it, and exiting into funds they expect to be able to use freely. The UX is unified, but the trust assumptions are not.

Zcash itself says: “Zcash is a decentralized protocol, which means your money is yours — not the bank’s.” Yet a swap rail integrated into that same user experience can put the resulting funds under a third-party compliance review, clear that review in writing, and then put the same funds back under review a month later.

The Zcash protocol can work exactly as intended, yet the user can still face a very different trust model further along what feels like the same product path.

That boundary was not obvious to me when the wallet I trust integrated the exit and described it as a “decentralised exchange” providing “trustless” swaps that “don’t depend on a centralised third-party.” I trusted this route because I trusted Zcash’s zero-knowledge encryption to protect my privacy, and I trusted the wallet enough to hold a much larger shielded ZEC balance there.

Because the swap rail was integrated into that same wallet experience, I treated it as part of a product path I could rely on at comparable scale, not only to exit shielded ZEC into USDT, but later to use that same USDT again, including swapping it into another asset.

That was my mistake. But users cannot reasonably be expected to understand where the trust model changes if the whole path is presented as one integrated experience without clearly marking those boundaries.

Zcash wallets that integrate a swap rail should make it clear to users that the swap provider has its own compliance process, refund process and ability to restrict access to funds. That information should be visible in the wallet interface itself before a user interacts with the rail, not left only in support documentation or terms that may never be seen during the actual user journey.

And there is also a bigger privacy issue here. To recover what left the shielded pool I had to give my email to a ticket support system that stopped replying, chase the case across Telegram, emails and public channels, and now post this publicly, creating the exact digital trail the shielded pool exists to prevent. When the exit fails, the price of recovery is paid in the privacy the shielded pool was built to protect.

I chose to provide that information because I wanted the funds returned. I also wanted to share my experience because the way the integrated path had been presented did not match the trust model I encountered in practice. Shielded users should understand that recovering funds after a failure outside the shielded pool can come at a practical cost to their privacy.

This experience left me with a question I’d like other shielded holders’ views on. How far can we rely on the integrated exit path from shielded ZEC at size? And once shielded ZEC has been swapped into USDT, how far can we rely on being able to use that USDT freely afterwards, including spending it or swapping it again into another asset?

Thanks to Shawn for bumping my account so I could post this thread.

14 Likes

who exactly is censoring this? is it the 1Click backend operators?

NEAR has never told me. From how they’ve communicated, it sounds like an internal compliance or administrative process somewhere within the NEAR Intents flow, but that’s just my reading of it, not something they’ve actually said.

Hmmm.
This is a serious issue that calls into question the integrity of NEAR Intents being one of the available options of moving ZEC. I hope you do get back your funds quickly. This can be discouraging.

5 Likes

This is (unfortunately) not very surprising to me.

The post where I brought up concerns about NEAR’s terms can be found here. The thread concludes with me asking NEAR reps (again) to respond, without any reply.

These kinds of systems aren’t put into place to never be used, and interoperability of such systems into Zodl (ex Zashi) wallet was decided by that team (around early 2025), and development around this ‘feature’ was prioritized.

Maybe it stemmed from a desire to both have a ‘pristine’ private core chain while also being connected with the mainstream surveillance / censorship friendly financial network…? I’m not certain of the exact reasoning, but it may turn out to be an historically relevant question.

I am quick to respond here because I’m working on a follow up for Threads - part I, and this is tangentially related. In fact, the exact link I’m sharing here will appear in that post.

Good luck!

3 Likes

shocking!

Nothing in their terms would explain who or how they have taken your funds away for so long, simply by depositing on Near. They conduct aml screening during quote generation, but there is no description of any further compliance auditing or excuse for holding your funds to ransom without due legal process.

Near is too heavily relied on by multiple wallets, now that Maya has shutdown.

You’re right about the terms. I cannot find anything that clearly addresses what happened in my case: the compliance review was declared successfully concluded in writing, the refund was raised, and then the same matter was put back under review without any new transaction, deposit, or event from my side.

On 23 July they told me:

“the compliance review concerning your recent deposit has been successfully concluded”

“All associated funds will be released and accessible for use."

and “all administrative restrictions on your account have been fully removed, granting you unrestricted access to the protocol’s full range of services.”

Then on 27 August they said:

“While an initial determination was communicated on July 23, subsequent administrative and compliance verification required returning the matter to a pending review status,”

and that “the review has not been fully concluded and remains actively under evaluation.”

Those statements directly conflict on the status of the same review. One says the review was successfully concluded and all restrictions removed. The later one describes that earlier conclusion as an “initial determination” and says the review was not fully concluded and had been returned to pending status.

I asked what changed between “successfully concluded” and “ongoing,” and on what date. After 20 July there was no new transaction, deposit, or event from my side. That is visible on-chain. They never replied.

you might want to loop in @chronear to this thread

1 Like

Thanks for raising this, Tim. We understand the seriousness of the matter and the frustration caused by the time it has remained unresolved.

Zodl does not hold or control the assets involved in the transaction and cannot itself release or return them. We have raised the matter with the team supporting our integration with NEAR Intents and remain actively engaged with them. Because the review remains ongoing, we cannot comment publicly on the specific circumstances of the transaction.

We recognize that communications received during the process have contributed to the confusion and frustration.

Separately, Zodl has updated its support documentation and public-facing language to describe the NEAR Intents integration more precisely.

We will continue to engage with the relevant parties and share any substantive update that we are able to communicate.

10 Likes

Just another reason why we need truly decentralized ways of swapping ZEC to other coins, including privacy stablecoins… there should be no middleman who can stop the swap. Hopefully thorchain and others can solve this for everyone.

2 Likes

Thank you @Zodl for responding here, and for acknowledging the communication issues. I appreciate that.

On the documentation change, since you mention it: you updated the support documentation and public-facing language to describe the NEAR Intents integration more precisely. That was the right change to make.

But that earlier description was part of what carried my trust from the wallet across to the rail, and Zodl users who read it previously, as I did, were never told or notified that it had changed.

When Zodl ships a new version of its mobile applications, adds a feature or fixes a bug, it communicates that publicly through release notes, social media, and other user facing channels.

A change in the stated trust model of the main integrated swap rail is at least as important, and arguably more important, because it affects how Zodl users understand who can control their funds.

If the integration was previously described as a “decentralised exchange” providing “trustless” swaps that “don’t depend on a centralised third-party,” and Zodl no longer considers that description accurate, Zodl users deserve to be notified about that change, especially when the revised page now states that swaps are subject to NEAR’s Terms of Service, reflecting a trust model in which a third party can restrict access to user funds. They should not discover that only when their own funds are held for compliance.

Would Zodl consider communicating that change to users publicly, which addresses the disclosure gap for existing users, and making the trust boundary clearly visible in the app before someone uses the rail, which addresses it for everyone who comes next?

That would be a real and positive outcome from all this, whatever happens with my own case.

2 Likes

Thank you for taking the time to share and document this important issue. The amount involved is enormous, and the situation is alarming. It would be helpful to hear a response from NEAR to better understand what happened.

This also raises an important concern for ordinary users: funds can become inaccessible during conversion. Clear best practices for safely converting shielded ZEC to other assets are needed so users understand the risks and how to protect themselves.

Does the Zcash ecosystem currently recommend or support any alternatives to NEAR Intents for converting shielded ZEC into stablecoins?

I’m learning about Maya, Zwap, Khalani, and other approaches, but I’m curious what is actually mature and available to an ordinary user today. Given the concerns raised here, having more than one trusted conversion path seems important

3 Likes

But the swap from zodl worked and you got your funds, the issue seems to be more from trying to swap again from your ledger (not zec related) , the zec and the swap to usdt worked, its the steps you then took after which have cause you pain by the sounds of it……

2 Likes

I think one thing that is often missing from this discussion is the balance that becomes increasingly important when dealing with a privacy asset like Zcash, especially now that ZEC is trading above $1,000. At these prices, the amounts involved are becoming much more significant. 500 ZEC is no longer the price of a bicycle, as Zooko and Vitalik once discussed.

To me, one reasonable compromise is that even decentralized services, and I would put NEAR Intents in that category, should be able to offer automated AML screening as part of the swap process. I am not trying to judge this particular case because I simply do not have enough useful information to know what actually happened. I hope the topic starter gets the situation resolved successfully.

But consider a simple example. You swap ZEC for USDC and receive $500,000 into your self custody wallet. Imagine that somewhere in the liquidity path, $1,000 of that USDC can be traced back to funds stolen from Bybit. Depending on how compliance providers assess the transaction, that association could cause the transfer or your wallet to be flagged as higher risk.

Would you want to discover that only later, when trying to deposit the funds to an exchange, use another service, or transact with a regulated counterparty? I certainly would not. Most major counterparties already use some form of blockchain AML screening.

So I think giving users access to automated AML screening at the point where private ZEC is converted into transparent assets is a reasonable balance. This does not mean introducing AML or censorship into Zcash itself. It means giving the recipient some protection against unknowingly receiving transparent coins with problematic provenance.

And that is only the perspective of an ordinary user. Developers and infrastructure providers face an entirely different category of legal and regulatory risks as well, including the kind of situation Roman Storm found himself in.

FYI

1 Like

@artkor, I see the point about 500 ZEC becoming much more valuable today, but I think the causality should run in the opposite direction. Zcash should become more valuable because its privacy, self sovereignty and usability become more valuable to people. Its core properties should not depend on how much 1 ZEC is worth.

If 500 ZEC can move one way when it is worth $10,000, but the same 500 ZEC attracts more gatekeepers, more approvals and more control when it is worth $100,000, then the issue is not the transaction itself, but the fact that the same amount of ZEC is treated differently once its market value becomes larger. That suggests the surrounding infrastructure has not matured at the same pace as the value it is now expected to carry.

A system is not really scaling if it can support higher value only by adding more friction, more discretion and more dependence on intermediaries. Higher value should be a reason to make the system more robust, more usable and more capable of preserving its guarantees at size. It should not be a reason to dilute those guarantees.

Otherwise we create a contradiction: the technology becomes valuable because people trust its sovereign properties, and then, once that value materializes, we use the higher value as justification for taking some of that sovereignty away.

For me, that is backwards. Price should follow perceived utility and trust. Utility and trust should not be redesigned around price.

I also took some time to go through the links @aaal shared in his previous reply. I find the point about that feature being prioritized genuinely interesting, because it raises an important question about adoption and shifts it from “what more should we add?” to “what might we be adding that changes the thing we are trying to scale?”

If we make Zcash easier to use by integrating more wallets, swap rails and exit paths into the ecosystem, that is very good. But if those products and integrations introduce new gatekeepers, new approval points, or new ways for someone else to control whether funds can move without those boundaries being clearly disclosed, then we may be solving the usability problem by weakening the reason many people wanted Zcash in the first place. Including me.

@artkor, I also think your point about AML is valid. I’m not against AML controls. What matters to me is clear disclosure, clear boundaries, predictable refusal and refund behavior, and risk controls calibrated to privacy users.

If a swap provider does not want to process a transaction after screening it, it can refuse the transaction and automatically return the funds to a specific refund address rather than leave them inaccessible for an open ended period without a clear timeframe. Chainflip and Railgun are examples that use that model.

The risk signals used by those AML controls should be calibrated to the privacy users the rail is actually expected to serve. If a privacy focused product encourages fresh addresses, limited linkability and other privacy preserving behavior, those same behaviors should not automatically become risk signals against the user at the exit. Otherwise the user experience promotes, teaches and incentivizes one behavior, then punishes the user for following the best practices it recommends.

So one important thing, in my opinion, is that we should be careful not to treat convenience as automatically equal to progress. Mass adoption should be achieved by making self sovereignty easier to use, not easier to lose.

8 Likes

Your testimony really confirms that transparent blockchains have turned into kafkaesque nightmares.

You should be. AML was dumb 10 years ago, dangerous a few years ago, nowadays it’s just suicidal. Giving confidential informations to random strangers will appear in retrospect as a complete lunacy.

5 Likes

You’re right to point that out, and it deserves a clarification. To be more precise, when I say I’m not against AML controls, I’m specifically talking about AML screening at the transaction level. I’m not against a decentralised exchange screening a transaction, choosing not to process it, and automatically refunding it.

Screening is one thing, censorship of the funds is another. If a rail does not want to process my transaction, that is its choice. Refuse it and return the funds automatically to the refund address. Then the user remains free to choose another rail.

I completely agree with your point about giving confidential information of any kind to third parties during compliance reviews. That is a separate and more serious privacy problem, and I’m strongly against it.

3 Likes

Reading this reminds me of what Osmosis did with my ZEC. Please refund me :zcash:

As a long-time independent NEAR supporter and a community NEAR validator, I’m sorry you are going through that with NEAR Intents.

I don’t agree with how the team is dealing with it (lack of communication, ghosting, lack of clarity, etc).

This is not the treatment I would expect for a $500 crisis and even less for a $500K crisis.

Hope you can get your money back ASAP.

(FWIW, i have zero connections with the team and NEAR Intents runs on its own permissioned network, which I also do not have access to as a validator – the permissionless NEAR network is a different thing).

6 Likes

Thank you @vinibarbosa it really means a lot, especially coming from a long-time NEAR supporter and community validator.

It is easy to support a project when everything is going well. It takes real integrity to speak up when something does not look right, especially when doing so may go against your own financial interest. That kind of support is not always comfortable, but it is often more valuable because it points to the painful things that need to be fixed and helps the project improve.

I appreciate you taking the time to reply.

5 Likes