0x37d4707a37d4…37d4707d
NEAR Intents Loses $3.8M to Smart Contract Bug, Omni Integration at Fault
NEAR Intents confirmed a $3.8 million loss from a smart-contract vulnerability tied to its Omni bridge integration, pausing services and pledging full user compensation.
Outputs
NEAR Intents reported an approximately $3.8 million loss on Oct. 1 stemming from a smart-contract bug
The team attributed the exploit to a flaw in the interaction between Omni deposit/withdrawal infrastructure and NEAR Intents' smart contract
NEAR Intents pledged to fully compensate affected users from its own balance sheet
Deposits and withdrawals across 11 networks (BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll, Plasma) were offline for roughly 12 hours
The incident has been reported to law enforcement and a detailed post-mortem is expected in the coming days
NEAR Intents confirmed on Oct. 1 that a smart-contract vulnerability drained approximately $3.8 million from its platform, with the team attributing the loss to a bug in how the Omni bridge's deposit and withdrawal infrastructure interacted with its own smart-contract logic.
In a statement on X, the team wrote: "Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract." The platform pledged to fully compensate affected users and to publish a detailed incident report in the coming days.
What exactly was exploited?
According to the preliminary report cited by NEAR Intents, the exploit stemmed from an integration flaw between the Omni cross-chain infrastructure and NEAR Intents' smart-contract layer, rather than from a compromise of NEAR's base-layer protocol. The team stated the smart-contract vulnerability had been patched by the time services were paused, and operations on NEAR Intents and near.com were expected to resume within roughly one hour.
Which networks are still affected?
While core trading was set to return quickly, deposits and withdrawals across eleven connected networks were expected to remain offline for about 12 hours as Omni-related fixes were rolled out. The affected chains are:
- BNB Smart Chain (BSC)
- Polygon
- TON
- Optimism
- Avalanche
- Stellar
- Monad
- LayerX
- Adi
- Scroll
- Plasma
Will users lose their funds?
NEAR Intents said account holders with assets on the suspended networks would not lose access to them. Once the platform returns online, those users can swap the affected balances into other supported tokens, including assets held in the platform's hot wallet or on near.com. The company has committed to absorbing the full $3.8 million loss rather than passing it on to users.
What is the recovery plan?
The incident has been reported to law enforcement, and NEAR Intents is coordinating with blockchain analytics and security partners to trace the stolen funds and pursue their recovery. The team stopped short of identifying a specific address or exploit pattern, reserving technical details for the post-mortem expected within days.
What are the broader operational consequences?
The episode highlights a recurring risk pattern in the cross-chain sector, where third-party infrastructure such as Omni is integrated with destination-chain smart contracts without sufficient isolation between validation paths. NEAR Intents' decision to halt services before contagion could spread and to socialise the loss signals a measured incident response, but the breach is likely to draw renewed scrutiny of how intent-based architectures verify foreign deposit flows.
The forthcoming post-mortem will determine whether the flaw was a one-off integration error or part of a structural gap requiring protocol-level changes, with operational consequences for any protocol routing assets through Omni.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
439 articles