0x7d9d87017d9d…7d9d86fe

ConfirmedSecurity561 vB17 sat/vB3 min decode

NEAR Intents Loses $3.8M in Omni Bridge Validation Exploit

NEAR Intents lost approximately $3.8 million in May 2025 after an attacker exploited a flaw in Omni Bridge's cross-chain message verification, according to cyberkendra.com. Drained funds largely comprised USDC and wrapped ETH.

NEAR Intents Hit by $3.8M Exploit via Omni Bridge Bug - cyberkendra.com
WitnessNEAR Intents Hit by $3.8M Exploit via Omni Bridge Bug - cyberkendra.comAI-generated

Outputs

  1. Approximately $3.8 million in digital assets were drained from NEAR Intents in May 2025

  2. The exploit originated in the Omni Bridge's cross-chain message validation logic between Ethereum and NEAR

  3. Omni Bridge is maintained by Aurora, NEAR Protocol's EVM-compatible execution layer

  4. Drained assets primarily included USDC and wrapped ETH, according to on-chain tracking

  5. NEAR core contributors paused Omni Bridge cross-chain transfers after identifying the intrusion

NEAR Intents lost approximately $3.8 million in digital assets in May 2025, after an attacker exploited a vulnerability in the Omni Bridge's cross-chain message verification process, according to cyberkendra.com.

The exploit targeted the validation logic that Omni Bridge uses to relay signed messages between Ethereum and NEAR Protocol. Omni Bridge is the cross-chain infrastructure maintained by Aurora, an EVM-compatible execution environment aligned with the NEAR ecosystem and operated by the Aurora team.

What is NEAR Intents?

NEAR Intents is an intent-based swap system that aggregates liquidity and routes cross-chain trades on behalf of users. Rather than relying on direct automated-market-maker interactions, the protocol accepts signed user-defined intents, matches them against solver networks, and settles trades across chains.

For Ethereum and NEAR asset flows, settlement depends on Omni Bridge. That dependency placed the bridge's message verification at the center of NEAR Intents' cross-chain operations — and exposed any flaw at the bridge level to dependent applications above.

How the exploit worked

According to cyberkendra.com's reporting, the attacker manipulated the bridge's verification of cross-chain messages, authorizing withdrawals they did not legitimately own. The manipulation centered on control over validator roles within the bridge's relayer system.

The technique enabled the operator to bypass standard ownership checks when transferring assets out of NEAR Intents liquidity pools. The pattern is consistent with broader MEV-operator attack surfaces observed across multi-chain environments: rather than compromising keys, the operator exploits structural gaps in validation.

What was lost

On-chain tracking identified the drained value as approximately $3.8 million, largely composed of USDC and wrapped ETH, per cyberkendra.com. The funds were moved through multiple intermediary addresses following the initial unauthorized withdrawal.

Operational response

NEAR core contributors suspended Omni Bridge cross-chain transfer functionality shortly after identifying the intrusion. The pause halted further unauthorized withdrawals and allowed engineers to audit the verification path.

The NEAR core team and Aurora operators coordinated on a fix and redeployment. Partial recovery of assets was reported in the days following the exploit, though the protocol has not disclosed a finalized recovery percentage.

Bridge-level structural risk

The exploit highlights a recurring pattern in intent-based architectures: when a single bridge secures the settlement path for multiple downstream protocols, a validation flaw at the bridge propagates into every dependent application. NEAR Intents is one such dependent protocol.

Omni Bridge's standard design relies on a combination of optimistic verification and NEAR-native light-client checks. The current incident indicates residual attack surface in message-validation logic, prompting renewed requirements for tighter validator controls, shorter finality windows, and restricted relayer access before affected routes resume.

What changes next

NEAR governance contributors are expected to publish a full post-mortem including a per-pool breakdown of impacted assets and final recovery status. The protocol will likely reevaluate integration assumptions with Omni Bridge and require independent audits before re-enabling suspended cross-chain routes.

The incident also adds pressure on cross-domain MEV operators as bridge-message manipulation becomes a more visible class of attack. Bridge security audits have accelerated across the industry in 2025 following several high-profile incidents. The NEAR case is likely to be cited in subsequent cross-chain risk assessments and may inform how intent protocols configure bridge fallbacks and circuit breakers going forward.

via Google News - Crypto Hack Exploit (Source)

More from Tom Whitfield

Tom Whitfield

Show full bio

News editor covering media and advertising at Mempool Brief.

419 articles