0x6b8758826b87…6b875885
NEAR Intents Confirms $3.8 Million Exploit, Patches Contract Flaw
NEAR Intents confirmed a $3.8 million exploit traced to an Omni custody integration bug, freezing bridges on 11 chains and pledging full treasury compensation for users.

Outputs
NEAR Intents confirmed a $3.8 million exploit on October 1, 2026, caused by a bug in its smart contract's interaction with Omni's custody architecture.
Attackers drained the platform's hot wallet on BNB Chain, moved funds to KuCoin and converted them to Bitcoin via cross-chain bridges.
The NEAR token fell 7.5% to a local low of $4.76 before rebounding to $4.84.
Deposits and withdrawals across 11 blockchains are frozen for about 12 hours pending Omni's fixes.
Days earlier, the protocol's SHIELD system had blocked $50 million in laundering attempts after the Bitget hack.
NEAR Intents has officially confirmed a $3.8 million exploit of its infrastructure, acknowledging that a bug in the interaction between its smart contract and Omni's custody architecture allowed attackers to make unauthorized withdrawals from the platform's hot wallet on BNB Chain (BSC).
The confirmation, published in an official report on October 1, 2026, ended days of silence from the cross-chain protocol. The disclosure immediately hit the market: the native NEAR token dropped 7.5% within minutes, touching a local low of $4.76 before partially recovering to $4.84, according to TradingView data.
The timing is awkward for the project. Just days earlier, NEAR Intents reported that its SHIELD security system had blocked $50 million in transactions tied to laundering attempts following the Bitget exchange hack. That external defense proved powerless against an internal integration error.
What exactly went wrong?
NEAR Intents implements Chain Abstraction, one of the year's dominant infrastructure trends, with more than $30 billion in cumulative trading volume. The design lets a user or AI agent state an intention — for example, "swap Arbitrum USDT for native Bitcoin" — while the underlying infrastructure handles bridge selection, gas calculation and network routing.
That hidden complexity created the failure point. According to the team, the flaw sat at the interface between the NEAR Intents smart contract and Omni's custody architecture. Attackers exploited it to drain the hot wallet, moved the stolen assets to KuCoin, and converted them into Bitcoin through cross-chain bridges.
How did the team respond?
The protocol rolled out a crisis plan with three immediate measures:
- The vulnerability is patched. The smart-contract flaw has been fixed, and the main site along with core services was expected to return within an hour of the announcement.
- Bridges frozen across 11 chains. Deposits and withdrawals on networks including Polygon, TON, Optimism, Avalanche and Scroll remain suspended for roughly 12 hours until Omni completes its own fixes.
- Full compensation. The project's treasury will cover user losses in full. Assets held within the system, including hot-wallet balances, can be converted safely once service resumes.
NEAR Intents has also engaged law enforcement and blockchain analytics firms to trace the movement of the stolen Bitcoin across bridges and the KuCoin deposit trail.
Why does this incident matter beyond NEAR?
The case sets a precedent for the broader cross-chain sector. NEAR Intents positions itself as a financial layer for the AI agent economy, where autonomous agents must interact with Web3 without manual transaction signing. That use case depends entirely on the reliability of automated routing through bridges and custody integrations.
The exploit demonstrates that even a project with effective external threat defenses — as SHIELD's $50 million interception showed — remains exposed at integration points with conventional bridges. For protocols pursuing chain abstraction, the attack surface is not the headline architecture but the seams between components built by different teams.
The team's rapid patching and its commitment to absorb losses from the treasury averted an immediate reputational collapse. But the incident will force a reassessment of security standards for cross-chain gateways, particularly around hot-wallet custody arrangements with third-party operators like Omni.
With bridges frozen across 11 blockchains pending Omni's fixes, the protocol faces a roughly 12-hour recovery window — and a longer reckoning over how intents-based systems validate the integrations they abstract away.
via u.today (Original)