Skip to main content
Blockfront

Crypto markets, protocols and policy

NEAR Intents halts service after $3.8M exploit, pledges repayment

NEAR Intents paused its cross-chain service after a flaw tied to Omni deposit and withdrawal infrastructure led to about $3.8 million in losses; it pledged full repayment.

Blockfront Editorial

2 min read

Abstract cover artwork

NEAR Intents halted its cross-chain service on Thursday, Oct. 1, after a bug linked to its Omni deposit and withdrawal infrastructure led to a preliminary loss of about $3.8 million, and pledged to compensate users in full. The team said it had patched the contract-side flaw, according to Unchained’s report on the exploit.

What part of NEAR Intents failed?

The team traced the incident to an interaction between Omni’s deposit and withdrawal infrastructure and the NEAR Intents smart contract. It did not name the affected contract or say whose funds were lost, Unchained reported.

Blockchain data reviewed by Unchained showed about 3.87 million USDT leaving a BNB Chain contract that NEAR Intents’ documentation lists as the HOT Bridge treasury address. The withdrawals happened over about six hours: two transfers of 10 and 11 USDT, followed by five ranging from $35,000 to $1.5 million.

In those seven withdrawals, the receiving address triggered the payout, Unchained reported. Other withdrawals it reviewed from the contract were processed by a different address. The team’s preliminary loss estimate was about $3.8 million; the difference from the on-chain total reflects separate reported figures, not a final accounting.

Which services were paused, and what was patched?

NEAR Intents said it paused the protocol when it detected the incident and fixed the flaw on the contract side. The team expected the protocol to resume within an hour, while deposits and withdrawals on 11 networks would remain unavailable for roughly 12 more hours as it repaired the Omni infrastructure.

The affected networks included BNB Chain, Polygon, TON, Optimism and Avalanche, Unchained reported. Users with assets from those networks in HOT Wallet or on near.com could convert them to other assets once the protocol itself was running, according to the team’s post.

That distinction left a temporary gap between the core protocol’s expected restart and the return of cross-chain deposit and withdrawal routes. The team gave an estimated outage window for those routes, but the reports did not confirm when all 11 networks were restored.

What happens to the stolen funds?

NEAR Intents said it would compensate affected users in full, without giving a payment schedule. It also said it had notified law enforcement and brought in security and blockchain analytics firms to trace the funds and try to recover them.

On Friday, general manager Alex Shevchenko said the team had identified the individual behind the breach and gave them 48 hours to return the funds under “responsible disclosure,” Cointelegraph reported. The report did not say whether the funds had been returned; NEAR Intents said it would publish a fuller account in the following days.