0x10f00cb410f0…10f00cb1
NEAR Intents Loses $3.8M to Smart Contract Exploit at Omni Gateway
NEAR Intents lost $3.8M in a smart contract exploit on October 2, 2026, after attackers targeted the handoff seam between its Omni gateway and core contract. The team patched the bug and pledged full user reimbursement.
Outputs
NEAR Intents lost $3.8 million in a smart contract exploit disclosed on October 2, 2026
Vulnerability was located at the handoff seam between Omni multi-chain gateway and NEAR Intents contract
The exploit affected token deposit and withdrawal operations across external blockchains
The NEAR Intents team patched the underlying bug following the incident
The team pledged full reimbursement to affected users, with no public reimbursement timetable yet
The NEAR Intents protocol suffered a $3.8 million exploit on October 2, 2026, after attackers exploited a smart contract vulnerability at the integration point between its Omni multi-chain gateway and the NEAR Intents contract, according to a disclosure indexed by CryptoRank and authored by Ikemefula Aruogu for CoinEdition. The breach affected token deposit and withdrawal operations, and the team has since patched the underlying bug and pledged full user reimbursement.
What Happened on NEAR Intents?
The exploit was triggered by a vulnerability at what the disclosure described as the "handoff seam" between two core components: the Omni infrastructure and the NEAR Intents Smart Contract. Omni serves as the protocol's underlying multi-chain gateway, managing how token deposits and withdrawals traverse external blockchains such as Ethereum.
That interface is the operational boundary where external chain deposits become NEAR Intents operations and where withdrawals exit back to originating networks. A flaw at that boundary allowed attackers to drain approximately $3.8 million from user balances. The disclosure did not specify the precise code path used, the number of attacker addresses, or whether any funds have been bridged out to other networks.
How Did the Team Respond?
The NEAR Intents team patched the bug and committed to fully reimbursing affected users, per the disclosure. As of the report, the protocol had not released a comprehensive postmortem identifying the exploited function, attacker wallets, or a remediation timeline. The team also had not disclosed whether reimbursements would be sourced from protocol treasury reserves, recovered funds, or future token issuance. NEAR Intents has not stated whether law enforcement has been notified or whether on-chain tracing efforts are underway.
How Does This Fit the DeFi Risk Picture?
The incident highlights recurring protocol risk at cross-chain gateway and bridge layers. Handoff interfaces between messaging systems and destination contracts have historically produced the largest single-incident losses in decentralized finance, and the NEAR Intents event sits squarely in that category. Multi-chain protocols concentrate risk at gateway contracts because a single integration bug can affect deposits and withdrawals across every supported network. NEAR Intents users should refrain from new deposits and limit exposure on existing positions until independent third-party audits confirm the patch.
What Should Affected Users Do?
Users who held deposits or pending withdrawals on NEAR Intents at the time of the exploit should review the protocol's official communications for reimbursement instructions and avoid re-depositing funds until audits conclude. Until the postmortem and audit results are public, deposit and withdrawal activity on NEAR Intents carries elevated protocol risk, and users interacting with the gateway should size positions accordingly.
What's Next?
Affected users await a full technical postmortem, a reimbursement timetable, and independent audit verification of the patched contract. The protocol's near-term operational priorities are postmortem publication, reimbursement distribution, and third-party audit work. The next material disclosure from the team — a full postmortem with audit results and a concrete reimbursement schedule — will determine whether the incident becomes a contained operational loss or a longer-term trust issue for the protocol.
via cryptorank.io (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles