0x5a2de05d5a2d…5a2de060
NEAR Intents Suffers $3.8M Exploit Days After Bitget Breach Response
NEAR Intents lost $3.8M to a smart contract bug at its Omni bridge interface, patching the flaw and pledging full user reimbursement one week after assisting in the $388M Bitget breach response.
Outputs
NEAR Intents lost approximately $3.8 million to a smart contract exploit disclosed Thursday.
The vulnerability stemmed from a bug in the Omni bridge deposit and withdrawal infrastructure interacting with the NEAR Intents contract.
The protocol pledged to compensate affected users in full and reported the incident to law enforcement.
Blockchain investigator ZachXBT traced the stolen funds to KuCoin and then to bridged Bitcoin.
The exploit followed NEAR Intents' role in the Bitget $388 million breach response, where it blocked $50 million and froze more than $500,000 in related funds.
NEAR Intents lost approximately $3.8 million in user funds through a smart contract exploit disclosed Thursday, the cross-chain protocol said in a post on X.
The attack stemmed from "a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract," the team stated. NEAR said the vulnerability has been patched and committed to compensating affected users in full.
How did the exploit unfold?
The breach targeted the interface between NEAR Intents' smart contract logic and the Omni bridge infrastructure used for deposits and withdrawals. According to an analysis by blockchain investigator ZachXBT, the stolen funds were transferred to the KuCoin exchange and then bridged into Bitcoin. The identity of the attacker remained unconfirmed.
"The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery," NEAR Intents said. "A detailed report will be shared publicly in the following days."
What is the connection to the Bitget hack?
The exploit landed one week after NEAR Intents assisted in the response to a separate $388 million security breach at derivatives exchange Bitget. During that effort, NEAR Intents reported blocking $50 million and freezing more than $500,000 in funds tied to the Bitget incident. Bitget CEO Gracy Chen publicly speculated that North Korean state-linked hackers may have been responsible for that larger theft.
What does this mean for users and the protocol?
NEAR Intents' pledge to reimburse all affected users removes direct financial exposure from the incident, distinguishing it from bridge exploits where victims absorb losses. The reimbursement commitment raises a near-term operational question: how the protocol will fund the $3.8 million payout without drawing from its own treasury reserves.
Cross-chain bridge integrations continue to present structural risk. The Omni vulnerability reflects a recurring pattern flagged by security analysts, in which deposit and withdrawal logic interacts with external bridge contracts in ways that expand the attack surface.
What enforcement or recovery actions are underway?
NEAR Intents said it has engaged law enforcement and multiple blockchain analytics firms to trace the bridged Bitcoin. Recovery typically hinges on exchange cooperation at cashout points or on-chain identification of the receiving wallets.
A detailed post-mortem is expected within days, which should clarify the precise exploit path and any mitigations beyond the smart contract patch already deployed. KuCoin has not publicly addressed whether it will freeze the implicated deposits identified by ZachXBT.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles