0x13645eb61364…13645eb9
NEAR Intents Loses $3.8M in Cross-Chain Exploit, Gets Funds Back
NEAR Intents lost about $3.8 million in a Thursday exploit traced to a bug in its Omni cross-chain system. The attacker returned all stolen funds within 24 hours, co-founder Illia Polosukhin said.

Outputs
NEAR Intents lost approximately $3.8 million in an exploit on Thursday, October 1, 2026
Exploiter returned all stolen assets within 24 hours, according to co-founder Illia Polosukhin
Vulnerability was traced to a bug in the Omni deposit system interacting with the NEAR Intents smart contract
On-chain investigator ZachXBT traced stolen funds to exchange KuCoin and then bridged into bitcoin
11 networks affected including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma
NEAR Intents, a cross-chain trading platform that has processed more than $30 billion in volume across 35 blockchains, lost about $3.8 million in a security exploit on Thursday, according to the project's own disclosure and on-chain investigator ZachXBT.
The attacker drained funds from a BNB Chain hot wallet linked to NEAR Intents, then sent the proceeds to crypto exchange KuCoin and bridged them into bitcoin, ZachXBT wrote in a Telegram post.
The platform paused its cross-chain services and disabled deposits and withdrawals on a series of networks. Its status page listed issues affecting BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma.
What caused the breach?
NEAR Intents attributed the incident to a bug in the way its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract. The contract-side vulnerability has been patched, the project said, and affected users would be reimbursed in full.
The reimbursement commitment became unnecessary. Illia Polosukhin, co-founder of NEAR Protocol, wrote on X on Friday that the exploiter returned all stolen assets one day after the team identified the attacker and opened a line of communication.
How does NEAR Intents actually work?
NEAR Intents abstracts the routing layer behind crypto trades. Users specify the swap they want rather than picking a bridge, exchange or path. Independent market makers called solvers then compete to fill the order behind the scenes.
The $30 billion-plus in cumulative volume points to broad institutional and retail uptake. It also concentrates operational risk in the Omni deposit system now at the center of the incident.
How does this fit the 2026 hack picture?
The exploit lands in a year already defined by large-scale crypto thefts. DefiLlama-tracked incidents include:
- Bitget: more than $350 million lost the week prior
- Liquid Network: roughly $320 million
- Drift: $295 million, attributed to a six-month North Korean intelligence operation
- Kelp DAO: $293 million in wrapped ether stranded across 20 chains
NEAR Intents ranks well below those events in dollar terms, but the return of funds sets it apart. Bitget has said user funds remain safe and is working with on-chain analysts, but the exchange has not publicly disclosed a recovery.
What is the on-chain trace showing?
ZachXBT's reconstruction tracks the stolen capital from a BNB Chain hot wallet to KuCoin, then across a bitcoin bridge. Bridging into BTC, rather than holding the proceeds in a stablecoin or ether, is a common laundering step because it forces investigators to follow coins through a different settlement layer with different tracing tools.
NEAR Intents said it reported the incident to law enforcement and is working with security and blockchain analytics firms on the trail.
What happens operationally next?
Core trading services were expected to resume quickly. Deposits and withdrawals on the 11 listed networks were set to remain offline longer while fixes are completed and audited.
The NEAR token traded near $4.91 at the time of writing, down roughly 6% over 24 hours. The disclosed vulnerability sits in the cross-chain infrastructure that runs on top of the NEAR Protocol base layer, not in the base-layer consensus itself, which limits reputational damage to the underlying chain.
The next concrete deadline is the staggered reopening of deposits and withdrawals across the 11 affected networks, which the project will signal through its status page once per-chain audits clear.
via data.coindesk.com (Original)