0x59919aba5991…59919abd
NEAR Intents Confirms $3.8 Million Exploit, Patches Flaw
NEAR Intents confirmed an exploit exceeding $3.8 million, says the vulnerability is patched and has pledged full reimbursement for all user losses from the incident.

Outputs
NEAR Intents confirmed an exploit with losses of more than $3.8 million, reported Oct. 1 via Cointelegraph
The protocol says it has deployed a patch for the vulnerability behind the incident
NEAR Intents has pledged to fully reimburse all losses caused by the exploit
NEAR Intents, the cross-chain transaction protocol built within the NEAR ecosystem, has confirmed that an exploit drained more than $3.8 million from the platform, according to a statement the project issued and which Cointelegraph reported on Oct. 1.
The protocol confirmed both the incident and the scale of the losses. In the same statement, NEAR Intents said its engineers had identified the underlying vulnerability and deployed a patch addressing it.
NEAR Intents also committed to fully reimbursing all losses caused by the incident. The pledge covers the entire verified loss figure of more than $3.8 million, though the project has not yet published a detailed timeline for when affected users can expect compensation payments to begin.
What NEAR Intents does
NEAR Intents operates as cross-chain infrastructure, allowing users to move assets and execute transactions across different blockchain networks through the NEAR protocol. That functional profile places it in a category of bridging and intent-based systems that have repeatedly drawn attacker attention, because pooled assets locked in cross-chain contracts present concentrated targets.
The disclosed loss figure of $3.8 million is modest relative to the largest cross-chain exploits on record, but the incident lands on a category of infrastructure that investors and auditors already scrutinize closely. Each breach of this kind tends to renew questions about how intent-based and bridge protocols custody assets, how quickly they can detect anomalous withdrawals, and whether treasury reserves are sufficient to make users whole without external insurance.
The operational picture
Three facts define the incident as currently disclosed. First, the loss exceeds $3.8 million. Second, the vulnerability that enabled the exploit has been patched, which addresses the immediate attack vector. Third, the protocol has pledged full reimbursement, shifting the financial burden of the incident from users to the project's own reserves.
What remains unknown at this stage is equally consequential. The protocol has not detailed the technical nature of the vulnerability, the mechanism of the exploit, whether any attacker-controlled funds have been traced or frozen on-chain, or the source of the capital backing the reimbursement commitment. Post-mortem disclosures and independent security reviews typically follow incidents of this type and would address those gaps.
Why the response matters
The decision to patch first and commit publicly to full reimbursement follows a well-established crisis playbook among protocol operators. A rapid fix limits repeat exploitation, while a blanket compensation pledge is designed to stem user outflows and preserve the protocol's operating base.
The approach carries real costs. Reimbursement obligations of this size compress a protocol's treasury, and the credibility of the commitment depends on reserves that NEAR Intents has not yet quantified publicly. Execution risk sits in the compensation process itself: if payments lag or verification of affected balances proves contentious, the initial goodwill from the pledge can erode quickly.
The incident also adds to a running tally of security failures in cross-chain infrastructure, a segment where exploits have repeatedly forced protocols to choose between socialized losses, treasury-funded bailouts, or insolvency. For counterparties and integrations that route volume through NEAR Intents, the patched vulnerability will need to clear renewed diligence before confidence fully returns.
Affected users and observers will be watching for the reimbursement schedule and a technical post-mortem, both of which will determine whether the protocol's rapid-response posture translates into restored operational trust.
via en.bloomingbit.io (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles