0x1322b66c1322…1322b66f
NEAR Intents Hit by $3.8 Million Exploit Days After Blocking Bitget Hacker
NEAR Intents lost roughly $3.8 million in an exploit that hit days after the cross-chain protocol blocked funds tied to the Bitget exchange hacker.
Outputs
NEAR Intents lost approximately $3.8 million in an exploit.
The breach occurred days after the protocol blocked funds tied to the Bitget hacker.
Root cause and attacker fund-tracing remain subject to on-chain forensics and a pending post-mortem.
NEAR Intents, the cross-chain transaction protocol built on the NEAR blockchain, lost approximately $3.8 million in an exploit, according to reports of the incident — a breach that landed just days after the same platform moved to block funds connected to the hacker behind the September theft from crypto exchange Bitget.
The timing is uncomfortable. NEAR Intents had publicly positioned itself on the right side of the Bitget incident, implementing measures that prevented the attacker from routing stolen proceeds through its cross-chain infrastructure. That defensive action demonstrated that the protocol's operator could intervene transactionally when a threat was identified. The subsequent $3.8 million loss raises the inverse question: why the same operational capability did not prevent — or at least limit — a direct exploit of the protocol itself.
The reported loss figure, $3.8 million, makes this a mid-sized incident by 2025 standards, large enough to matter to affected users and counterparties but well below the nine-figure thefts that have dominated headlines this year. For a protocol that serves as bridging and intent-based swap infrastructure, however, the reputational calculation is different from that of a single-chain application. Cross-chain services live and die by the assumption that assets deposited on one chain can be reliably redeemed on another. Any break in that assumption, regardless of size, forces integrators and market makers to reassess exposure.
The mechanics of the exploit — which contract, which signature verification path, or which relayer component failed — have not been fully detailed in the initial reports. What is established is the loss amount and its proximity, measured in days, to the platform's blocking of the Bitget hacker's funds. That proximity will draw scrutiny from two directions.
First, security researchers will want to determine whether the two events are connected. A platform that publicly blocks an attacker's proceeds becomes a named adversary of that attacker. Whether the exploit represents retaliation, opportunism, or simple coincidence is a question that on-chain forensics may answer as the attacker's fund movements are traced. Second, the incident feeds an ongoing industry debate about the centralization of cross-chain infrastructure. The ability to block the Bitget hacker's funds implies a degree of administrative control over transaction flow. Users who value that control when it stops a thief must also weigh it as a potential attack surface, an operational dependency, or a point of failure.
For NEAR's broader ecosystem, the incident lands at a moment when intent-based architectures — systems where users declare desired outcomes and solvers compete to execute them — are competing with traditional bridges for cross-chain volume. Security incidents on flagship implementations give institutional integrators a reason to slow deployments and demand audited fallback mechanisms before committing treasury or customer flows.
Affected users and counterparties will now watch for the standard post-incident sequence: an official post-mortem from the NEAR Intents team, a decision on whether losses will be covered from treasury or insurance reserves, and any negotiation attempt with the attacker through on-chain messages or bounty intermediaries. Whether the protocol freezes affected components while the root cause is patched will also shape how quickly normal volume returns.
The coming days should clarify whether the $3.8 million loss remains an isolated contract failure or exposes a deeper structural weakness in how NEAR Intents handles cross-chain message validation.
via Google News - Crypto Hack Exploit (Source)