0x47a08c7547a0…47a08c72

ConfirmedSecurity722 vB81 sat/vB4 min decode

NEAR Intents Attacker Returns $3.8M Exploited From BNB Chain Vault

NEAR Intents lost ~$3.8M in USDT to an Omni custody integration bug on Oct 1, 2026, froze 11 networks, and the attacker returned all funds within 24 hours of contact.

Outputs

  1. NEAR Intents lost ~$3.8M in USDT (Bitquery: $3.87M) to an exploit on October 1, 2026.

  2. The attacker returned all stolen funds ~24 hours after the team made contact, per co-founder Illia Polosukhin.

  3. The protocol froze deposits and withdrawals across 11 blockchains, including BNB Smart Chain, Polygon and TON.

  4. Root cause: an authorization bug between Omni's custody/withdrawal system and a NEAR Intents smart contract.

  5. September 2026 saw $766M–$768M lost across 99 crypto security incidents, per CertiK, PeckShield and CoinDesk tallies.

The attacker who drained roughly $3.8 million from NEAR Intents on October 1, 2026 returned all of the stolen assets roughly 24 hours after the protocol's team established contact, according to NEAR co-founder Illia Polosukhin, who announced the return on X on October 2.

The exploit targeted a vault tied to the protocol's BNB Chain operations, draining approximately $3.8 million in USDT. Bitquery's on-chain analysis put the figure slightly higher, at $3.87 million, and traced the withdrawals to the overnight hours between September 30 and October 1. On-chain investigator ZachXBT was among the first to flag the irregular outflows from the protocol's BNB Chain hot wallet.

What was the root cause?

NEAR Intents attributed the loss to a bug in how its Omni deposit-and-withdrawal infrastructure interacted with a NEAR Intents smart contract — an authorization failure at the boundary between two systems rather than a flaw in NEAR's base-layer consensus. The team said cold wallets and core custody keys were never touched.

The protocol has not published a full technical post-mortem as of October 3, so the precise exploit primitive remains unconfirmed. The failure pattern resembles an authorization gap between two individually audited systems that were never fully tested together under adversarial conditions — not a stolen private key, as in the 2022 Ronin Bridge attack, and not a forged signature, as in Wormhole's 2022 breach.

How did the protocol respond?

NEAR Intents halted cross-chain services across 11 blockchains within hours of the exploit:

  • BNB Smart Chain, Polygon, TON, Optimism, Avalanche
  • Stellar, Monad, X Layer, ADI, Scroll and Plasma

Core website and swap functionality returned within about an hour, while deposits and withdrawals on the affected networks stayed frozen for roughly 12 more hours while the team patched the Omni-side infrastructure. The direct financial loss was confined to the BNB Chain USDT vault; the other ten networks were disabled defensively. The team reported the incident to law enforcement and pledged full reimbursement on October 1 — a pledge rendered moot when the funds came back.

Where did the stolen funds go before the return?

Bitquery's tracing shows the attacker tested the exploit with small transactions before executing five major withdrawals — a common pattern among experienced on-chain attackers probing for detection. Roughly 76% of the stolen value was converted into 34.69 BTC. Bitquery separately reported about $802,000 moved toward KuCoin deposit addresses, and another trace put roughly $1.5 million of the stolen USDT through CoW Protocol's settlement layer.

What does the incident say about the broader market?

The exploit landed in what CoinDesk and analytics firms CertiK and PeckShield have called the worst month for crypto security in 2026: between $766 million and $768 million disappeared across 99 incidents in September alone, and Q3 losses reached roughly $1.26 billion across 247 incidents. NEAR Intents, which had processed more than $30 billion in cumulative volume across 35 chains before the breach, is small in dollar terms next to Bitget's $350 million–$388 million loss or the Liquid Network's $320 million breach.

There is an added irony. Days before its own breach, NEAR Intents' internal monitoring had blocked approximately $50 million in suspicious transactions connected to the Bitget hack, disclosed by the exchange on September 24 after attackers exploited a zero-day in a third-party security product. Security researchers note the episode illustrates that detecting laundering attempts and preventing integration-level bugs are different disciplines that do not automatically come bundled together.

NEAR's native token fell roughly 6% in the 24 hours after disclosure, touching a local low near $4.76 before recovering to about $4.84, and had stabilized but not fully returned to pre-exploit levels as of early October.

What happens next?

NEAR Intents has said it will share further technical details, and a full post-mortem naming the failed contract function and validation step would follow the precedent set by Wormhole and Nomad after their bridge incidents. With cross-chain infrastructure now moving more than $1.3 trillion in assets annually, expect expanded bug-bounty programs and third-party audits of custody-to-contract integration layers across the intents ecosystem as protocols absorb the lesson that the seam between systems is now the attack surface.

via coindesk.com (Original)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles