NEAR Intents patches $3.8 million exploit and pledges full user compensation
Cross-chain protocol NEAR Intents halted services and deployed an emergency contract patch following a $3.8 million exploit in its deposit infrastructure, promising to fully reimburse affected users.

Cross-chain protocol NEAR Intents suffered a security breach resulting in roughly $3.8 million in losses on Oct. 1, 2026, prompting a temporary suspension of operations. The project traced the incident to a smart contract flaw in its Omni deposit and withdrawal infrastructure. NEAR co-founder Illia Polosukhin stated that the ecosystem's AI-driven monitoring system, SHIELD, flagged abnormal activity before services paused, allowing developers to roll out a contract-level patch within an hour and begin restoring operations.[2][4][5][7][8][10]
According to on-chain investigator ZachXBT, the exploit involved irregular outflows from the protocol's BNB Chain hot wallet, with the extracted funds transferred to KuCoin and bridged to Bitcoin. Blockchain records reviewed by Unchained showed that an unauthorized address withdrew approximately 3.87 million USDT in seven transactions from the protocol's HOT Bridge treasury contract, routing about 1.5 million USDT through CoW Protocol. Although swap features resumed quickly, NEAR Intents announced a roughly 12-hour suspension of deposits and withdrawals across 11 networks, including BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, and Scroll.[1][2][4][8][11]
NEAR Intents confirmed that affected users would be compensated in full, with Aurora developer Alex stating that protocol funds would be used to cover the loss. The NEAR token declined between 7% and 10% following disclosure of the breach, though NEAR Protocol clarified that the underlying blockchain was not compromised. NEAR Intents general manager Alex Shevchenko later stated that the team identified the entity behind the exploit and gave them a 48-hour deadline to return the stolen assets.[2][3][4][6][9][12]
Key facts
- NEAR Intents experienced an exploit resulting in an estimated $3.8 million loss due to a bug in its Omni deposit and withdrawal contract infrastructure.
- The development team patched the contract vulnerability within one hour and pledged to fully reimburse affected users.
- On-chain investigator ZachXBT reported that the attacker drained funds via the protocol's BSC hot wallet, routed assets to KuCoin, and bridged them to Bitcoin.
- Blockchain data showed the receiving address extracted 3.87 million USDT across seven transactions from the HOT Bridge treasury contract on BNB Chain.
- Deposits and withdrawals were temporarily paused for roughly 12 hours across 11 networks, including BSC, Polygon, TON, Optimism, Avalanche, Stellar, and Scroll.
- The NEAR token dropped between 7% and 10% after the disclosure, but the underlying NEAR blockchain remained uninterrupted.
- NEAR Intents general manager Alex Shevchenko said the hacker was identified and given 48 hours to return the funds.
Sources · 11 sources
- Y❤
yourfriendSOMMI ❤️💛💚💙@yourfriendSOMMIPost on X ·
❤️💛💚💙 🧃 Juicy News #1515 🟢 Bitcoin $84,000 🟢 Ethereum $2700 ⚪ ETH-BTC = 0.031 🇺🇸 ZachXBT says NEAR Intents was exploited for $3.8M+, with stolen funds sent to KuCoin and bridged to Bitcoin. 🐶 DogeOS launches its EVM-compatible public testnet, letting developers build trading, lending, gaming and consumer apps for Dogecoin ahead of mainnet. 👉 Sommi recently added extra $DOGE in his Dinosaur Portfolio section 🇺🇸 US mortgage rates surge to highest level since 2023. • The average 30-year fixed mortgage rate has risen to 7.6%, the highest level since 2023, making homeownership very expensive for buyers. 👟 $NKE - Nike shows to 10-year low. Worth buying if you have STOCKS portfolio. 🇺🇸 President Trump says the US government might take ownership stakes in OpenAI, Anthropic and other AI companies. 🇺🇸 President Trump says prices are coming down “rapidly,” blaming Biden and Democrats for high costs and saying Republicans are fixing them. 🇺🇸 Trump claims he eliminated Iran’s nuclear threat “in one night,” saying the remaining time is to ensure it stays that way.
Open source - SI
Solid Intel 📡@solidintel_xPost on X ·
INTEL: near:native Intents says a security incident caused about $3.8 million in losses and halted services Users will be fully compensated while deposits and withdrawals remain paused across multiple networks https://t.co/jkDcFZLy7q
Open source - CO
CoinGecko@coingeckoPost on X ·
JUST IN: $NEAR falls 7% following news that NEAR Intents suffered a ~$3.8M exploit. https://t.co/xAFTgcF19n
Open source - CR
CryptoSlateArticle ·
Wall Street arrived in NEAR just as a $4 billion-a-month app got hacked NEAR’s new US ETF is facing its first stress test days after launch as a $3.8 million ecosystem exploit hit the token. NEAR fell about 10% to $4.86 after NEAR Intents disclosed a security incident involving its Omni deposit-and-withdrawal infrastructure. The selloff came less than two days after Bitwise opened the token to US exchange-traded fund investors through its NEAR ETF, with the ticker NRR. The fund began trading on NYSE Arca on Sept. 29 and attracted $35.5 million of net inflows on its first day. By Sept. 30, cumulative inflows had risen to over $50 million, while total net assets reached $52.8 million, equivalent to about 0.76% of NEAR’s market capitalization, according to SoSoValue data . That timing gives the newly launched product an unusually early test of investor conviction. The ETF protects buyers from the operational burden of wallets, private keys, and direct staking, but its value still moves with NEAR, leaving shareholders exposed when problems elsewhere in the ecosystem undermine confidence in the token. A $3.8 million exploit hits NEAR Intents In an X statement, NEAR Intents said it temporarily halted services after detecting what it described as a bug in the interaction between its Omni infrastructure and the Intents smart contract. The preliminary loss was about $3.8 million, and the project said it would fully compensate affected users. The team patched the contract vulnerability, and NEAR Intents and near.com resumed operations after a temporary suspension. A ZachXBT/TRM flow map traces 3.87 million USDC from Near Intents through multiple wallets, with funds reaching KuCoin. Source: ZachXBT Some deposit and withdrawal routes remained unavailable for longer while the team completed fixes to Omni infrastructure covering networks including BSC, Polygon, TON, Optimism, Avalanche, Stellar and Scroll. NEAR co-founder Illia Polosukhin said the exploit was isolated to USDT on BSC and that NEAR Intents’ SHIELD security system detected unusual activity before pausing services. He said the team identified and fixed the vulnerability within an hour. The base NEAR blockchain continued operating throughout the incident. NEAR Protocol said the exploit did not involve a vulnerability in the network or the native NEAR token , and that block production and transaction processing continued without interruption. That separation limits the direct operational impact on Bitwise’s ETF, which holds exposure to NEAR rather than assets deposited through NEAR Intents. The market reaction nevertheless shows how quickly application-level failures can feed through to an asset newly packaged for traditional investors. The Intents business is also large enough to make the incident more than a peripheral ecosystem problem. Polosukhin said the service now processes more than $4 billion a month in trading and payments volume, positioning it as one of NEAR’s major connections to other chains and applications. The team has reported the incident to law enforcement and is working with blockchain analytics and security firms to trace the stolen funds. A fuller postmortem is expected in the coming days. Polosukhin said the ecosystem plans to expand its use of formal verification and other security tools after the breach, including work already underway on a verification system for NEAR smart contracts. He stated: “The crypto space is entering a new era of far more sophisticated cyber attacks. Recently, we have seen BitGet, Metamask, Lido all being targeted by criminals equipped with AI systems that are continuously trying to hack all infrastructure. As a space, we need to be far more vigilant and raise the bar on both onchain contract standards and offchain monitoring and proactive prevention.” The ETF arrived after leverage had already started leaving The price decline also landed in a market whose speculative positioning had already changed substantially before NRR began trading. Blockchain analysis firm Santiment said NEAR-denominated futures open interest peaked at roughly 215 million NEAR on Sept. 21, eight days before the ETF launch. By Sept. 29, that figure had dropped about 21% to 169 million NEAR, even as the token’s price had risen roughly 86% from Sept. 16. NEAR rose about 14% as coin-denominated open interest fell 21% from its Sept. 21 peak before the ETF launch. Source: Santiment Dollar-denominated open interest continued climbing for several days, reaching about $1 billion on Sept. 27, but the declining number of NEAR committed to derivatives suggested leverage was already thinning before the ETF opened. That makes the post-exploit move different from a straightforward leveraged unwind. Spot demand had strengthened into the launch while speculative positioning was being reduced, according to Santiment, giving the ETF inflows a more prominent role in the market structure. NRR’s first two days showed that institutional demand was present, but the harder test begins after the breach. If inflows continue despite the 10% drop, investors would be signaling that they are willing to separate an application-specific exploit from the investment case for the underlying network. A reversal in flows would show how quickly an ecosystem security event can interrupt demand for an ETF that has existed for only a handful of trading sessions. The post Wall Street arrived in NEAR just as a $4 billion-a-month app got hacked appeared first on CryptoSlate .
Open source - BS
BSCN@BSCNewsPost on X ·
Near Intents suspends operations following exploit @NEAR_Intents has temporarily suspended operations after recognizing a flaw in smart contract interactions within the Omni deposit and withdrawal infrastructure, which caused a loss of approximately $3.8 million. However, the development team has successfully rolled out a contract-level security patch, and native swap execution and accounts on near(.)com are set to resume in one hour. Management has pledged to refund all impacted user balances in full using treasury funds. While swap functions will be restored immediately, deposit and withdrawal gateways for 11 different blockchain bridges will continue to remain suspended for 12 hours.
Open source - CO
CoinMarketCap@CoinMarketCapPost on X ·
UPDATE: 🚨 Near Intents GM Alex Shevchenko says yesterday's hacker has been identified, giving them a 48-hour deadline before the window for responsible disclosure closes. https://t.co/5XUG8Imbnq
Open source - BS
BSCN@BSCNewsPost on X ·
After the NEAR Intents exploit, NEAR raises the bar on code checks @near_intents is running again after today's exploit, though a few chains are still being fixed. NEAR co-founder @ilblackdragon said an AI monitoring layer called SHIELD flagged the unusual activity before the pause. The @NEARProtocol ecosystem will soon add formal verification, a way to prove code is correct for every possible input, to its release process. Illia also invited other teams to join SHIELD and share threat data faster.
Open source - UN
UnchainedArticle ·
NEAR Intents Pledges Full Compensation After a Bug Lets an Attacker Drain $3.8 Million NEAR Intents said on Thursday that a bug led to a loss of about $3.8 million at the cross-chain trading protocol, but that the full amount will be covered. It did not say whose funds were lost. The team said it halted the protocol when it detected a security incident. It traced the problem to “a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.” “The preliminary report indicates the total loss of approximately $3.8M,” the team wrote on X. “These funds will be compensated in full.” In the post, published at 8:53 a.m. ET, the team said it had fixed the flaw on the contract side and expected to be operating again within an hour. It said 11 networks , including BNB Chain, Polygon, TON, Optimism and Avalanche, would go without deposits and withdrawals for roughly 12 more hours while it finishes repairing the Omni infrastructure. People with assets from those networks held in HOT Wallet or on near.com can convert them to other assets as soon as the protocol itself is running, the team said. Get Unchained’s crypto news in your inbox with the free Unchained Daily newsletter . Most Funds Left in Six Hours NEAR Intents did not name the affected contract. Onchain investigator ZachXBT identified a BNB Chain address that he said received the funds. Blockchain data reviewed by Unchained shows that address collected about 3.87 million USDT from a contract that NEAR Intents’ documentation lists as the HOT Bridge treasury address on BNB Chain. Two transfers on Wednesday afternoon moved 10 USDT and 11 USDT. Five larger ones, ranging from 35,000 USDT to 1.5 million USDT, followed between 7:54 p.m. ET on Wednesday and 2:08 a.m. on Thursday. In all seven, the receiving address triggered the withdrawal itself. In the other withdrawals from the contract that Unchained reviewed, a different address processed the payout. Tracing the Funds The receiving address sent nearly all of the USDT onward within minutes of each transfer, the data shows. About 1.5 million USDT went to the settlement contract of CoW Protocol, a decentralized trading protocol, and the rest to four addresses Unchained has not identified. ZachXBT wrote that the funds “were immediately transferred to Kucoin and bridged to Bitcoin.” Unchained could not independently confirm those destinations. NEAR Intents said it has notified law enforcement and brought in security and blockchain analytics firms to follow the money and try to recover it. The HOT Bridge treasury contract kept processing other withdrawals on Thursday, the data shows. Shortly after 9:27 a.m. ET it paid about 215,000 USDT to an address that has drawn six-figure sums from it repeatedly over at least the past month. The incident came days after NEAR Intents general manager Alex Shevchenko said attackers had tried to push more than $50 million from the Bitget hack through the protocol. He said roughly $166,000 of that slipped through and another $503,000 was frozen. The team said it will publish a fuller account “in the following days.” Related Listen: How Bitget Is Chasing $388 Million in Stolen Funds After a Zero-Day Hack The post NEAR Intents Pledges Full Compensation After a Bug Lets an Attacker Drain $3.8 Million appeared first on Unchained .
Open source - LS
Laura Shin@laurashinPost on X ·
"We're just going to take the money that we have and put it there ... We definitely saw that there is a bug in the protocol, which means that this is our fault," @AlexAuroraDev on NEAR Intents' initial plan to make users while following the hack. https://t.co/vaKVdvkccA
Open source - BL
BlockNews@blocknewsdotcomPost on X ·
🚨 UPDATE: NEAR Intents confirms the $3.8 MILLION exploit was caused by a bug in its Omni deposit system. The vulnerability has been patched, affected users will be fully reimbursed, and services are gradually resuming. https://t.co/3M0NWE3xzt
Open source - CP
Crypto Patel@CryptoPatelPost on X ·
$NEAR INTENTS EXPLOITED FOR $3.8M+ | BSC HOT WALLET DRAINED #NEAR Intents suffered a security exploit after its BSC hot wallet recorded multiple irregular outflows, with losses estimated at $3.8M+. The affected hot wallet 0x233c has stopped processing transactions, while the protocol reported an ongoing incident impacting multiple EVM chains. Funds Trail: The stolen funds were reportedly moved to KuCoin and then bridged to Bitcoin. Response: NEAR Intents says the contract-side vulnerability has been patched and affected users will be fully compensated. Deposits and withdrawals on several networks remain temporarily restricted while infrastructure fixes are completed. BSC Theft Address: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37 $NEAR 14% Dumped in just last 8 hours. A detailed incident report is expected from the team.
Open source - BL
BlockNews@blocknewsdotcomPost on X ·
🚨 JUST IN: NEAR Intents GM Alex Shevchenko says the team has identified the entity behind the roughly $3.8 MILLION exploit and given them 48 hours to return the funds. “This is the last window to use it,” Shevchenko said. $NEAR https://t.co/EjHfzfQ3Pf
Open source - DE
DecryptArticle ·
Morning Minute: NEAR Intents Hacked for $3.8M - Was It A Bullish Hack? Hacks are never good, but a rapid response, user compensation and 1-hour bug fixing seems to top the spectrum of team reactions.
Open source

