0x6b1a6b876b1a…6b1a6b84
NEAR's New US ETF Faces First Stress Test as $3.8M Exploit Hits
NEAR fell 10% after a $3.8M exploit hit NEAR Intents, testing Bitwise's NRR ETF less than 48 hours after its NYSE Arca debut drew over $50M in inflows.
Outputs
A $3.8 million exploit hit NEAR Intents' Omni infrastructure, isolated to USDT on BSC; NEAR's base chain operated uninterrupted.
Bitwise's NRR ETF launched on NYSE Arca on Sept. 29, drawing $35.5M on day one and over $50M cumulative inflows by Sept. 30, with $52.8M in net assets.
NEAR Intents processes over $4 billion per month in trading and payments volume; ZachXBT and TRM traced 3.87M USDC from the breach to KuCoin.
NEAR's first US exchange-traded fund is facing its earliest credibility test less than 48 hours after launch, after a $3.8 million exploit hit NEAR Intents, one of the ecosystem's core cross-chain applications.
NEAR Intents disclosed the security incident on X, saying it had temporarily halted services after detecting a bug in the interaction between its Omni deposit-and-withdrawal infrastructure and the Intents smart contract. Preliminary losses stand at about $3.8 million, and the project said it will fully compensate affected users. A fund-flow map published by on-chain investigator ZachXBT, in collaboration with TRM Labs, traced 3.87 million USDC from Near Intents through multiple wallets, with a portion of the funds reaching KuCoin.
The token fell roughly 10% to $4.86 on the news. That selloff landed less than two days after Bitwise opened NEAR to US ETF investors through its NEAR ETF, trading under the ticker NRR on NYSE Arca since Sept. 29. The fund attracted $35.5 million in net inflows on its first day, according to SoSoValue data. By Sept. 30, cumulative inflows had surpassed $50 million and total net assets reached $52.8 million — about 0.76% of NEAR's market capitalization.
The ETF spares buyers the operational burden of wallets, private keys and direct staking, but its net asset value still tracks NEAR spot. Shareholders remain exposed when failures elsewhere in the ecosystem dent confidence in the underlying token.
What happened at NEAR Intents
NEAR co-founder Illia Polosukhin said the exploit was isolated to USDT on BNB Smart Chain and that the NEAR Intents SHIELD security system flagged unusual activity before services were paused. He said the team identified and patched the vulnerability within an hour.
NEAR Intents and near.com resumed operations after the suspension, though some deposit and withdrawal routes stayed offline longer while engineers completed fixes to the Omni infrastructure across multiple networks, including BSC, Polygon, TON, Optimism, Avalanche, Stellar and Scroll.
The base NEAR blockchain kept producing blocks and processing transactions throughout the incident. NEAR Protocol said the exploit did not involve a vulnerability in the network itself or the native NEAR token. That separation limits the direct operational impact on Bitwise's fund, which holds NEAR exposure rather than assets routed through NEAR Intents. The market reaction nonetheless shows how quickly an application-level failure can propagate to an asset newly packaged for traditional investors.
The scale of the Intents business makes this more than a peripheral ecosystem problem. Polosukhin said the service now processes more than $4 billion per month in trading and payments volume, making it one of NEAR's principal connections to other chains and applications.
The team has reported the incident to law enforcement and is working with blockchain analytics and security firms to trace the stolen funds. A fuller postmortem is expected within days. Polosukhin also said the ecosystem will expand its use of formal verification and related security tooling, including work already underway on a verification system for NEAR smart contracts.
He warned:
"The crypto space is entering a new era of far more sophisticated cyber attacks. Recently, we have seen BitGet, Metamask, Lido all being targeted by criminals equipped with AI systems that are continuously trying to hack all infrastructure. As a space, we need to be far more vigilant and raise the bar on both onchain contract standards and offchain monitoring and proactive prevention."
Leverage was already thinning before the launch
The post-exploit price decline landed in a market where speculative positioning had already shifted before NRR began trading. According to blockchain analytics firm Santiment, NEAR-denominated futures open interest peaked at roughly 215 million NEAR on Sept. 21, eight days before the ETF launch. By Sept. 29, that figure had fallen about 21% to 169 million NEAR — even as the token's price rose roughly 86% from Sept. 16.
Dollar-denominated open interest kept climbing for several days and reached approximately $1 billion by Sept. 27. But the declining quantity of NEAR committed to derivatives indicated leverage was thinning before the ETF opened. Santiment's reading: spot demand strengthened into the launch while speculative positioning was being reduced, giving ETF inflows a more prominent role in NEAR's market structure.
The first two sessions demonstrated that institutional demand exists. The harder test comes now, after the breach. Sustained inflows despite a 10% drawdown would signal that investors can separate an application-specific exploit from the investment case for the underlying network. A reversal would show how fast an ecosystem security event can interrupt demand for a product that has traded for only a handful of sessions.
With the postmortem expected in the coming days and law enforcement engaged, the near-term question is whether NRR's early inflows survive contact with the ecosystem's first major security incident.
via sosovalue.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles