NEAR Intents, the cross-chain swap service built on NEAR Protocol, lost about 3.8 million dollars Thursday after a bug in its Omni deposit and withdrawal infrastructure, and the platform paused services while it investigated. The team says the contract-side vulnerability has been patched and pledges to reimburse affected users in full.
The company said the flaw sat in how the Omni deposit and withdrawal system interacted with the NEAR Intents smart contract, the self-running code that records each swap. It is an infrastructure problem, not a breach of the NEAR Protocol blockchain itself, and the chain kept producing blocks throughout. The token still fell sharply, dropping 8.6 percent to 4.92 dollars within hours, as traders priced in the reputational hit to an ecosystem only two days after Bitwise launched the first US spot NEAR ETF, a launch the project had counted among its biggest 2026 milestones.
On-chain investigator ZachXBT flagged the incident first on Telegram, noting irregular outflows from the BSC hot wallet, an online wallet the service uses to pay out withdrawals. Several unusual withdrawals left the wallet before it stopped processing transactions. Per ZachXBT, the stolen funds moved to crypto exchange KuCoin and were converted into Bitcoin, the usual laundering route when an attacker wants to exit a compromised wallet quickly without leaving the proceeds parked in the original token.
What is paused and when it comes back
Deposits and withdrawals stay paused on 11 networks. The list covers BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. Core services were expected back roughly an hour after the patch, but the cross-chain rails stay down about 12 hours longer while the team verifies balances across all networks and checks its own books against what one investigator called a pattern of repeated waves on the BSC side. The project also said it reported the incident to law enforcement, a step that gives the exchange one more lever for freezing the funds if they resurface on a KYC-identified account.
| Item | Detail |
|---|---|
| Total loss | About 3.8 million dollars |
| Cause | Bug in Omni deposit/withdrawal system interacting with NEAR Intents contract |
| Fund trace | Moved to KuCoin, converted to BTC |
| Status | Patch deployed, services resuming in stages, full reimbursement pledged |
| NEAR price | Down 8.6 percent to 4.92 dollars |
Context: rough year for crypto security
The exploit lands in a year that has already cost crypto more than a billion dollars in hacks. CertiK counted 247 security incidents in the third quarter alone, losses totaling 1.26 billion dollars, with September alone driving 768.5 million dollars, the worst month of 2026 so far. It is the second major exploit in the NEAR ecosystem this year. In April, Rhea Finance lost 7.6 million dollars through an oracle manipulation attack, another infrastructure-layer failure rather than a break in the chain itself.
The pattern in both NEAR incidents and the broader market remains the same. Layer 1 blockchains hold up far more often than they buckle, and the expensive attacks concentrate in the connective tissue: bridges, oracles, hot wallets, deposit systems, and off-chain components that manage access to on-chain funds. NEAR Intents sits squarely in that layer. The service has processed more than 25 billion dollars in lifetime volume, so the dollar loss is small relative to throughput, but the reputational cost lands on a platform whose pitch is frictionless cross-chain execution between nearly a dozen chains at once.
Bridge and cross-chain swap exploits have stayed the costliest category in crypto for years, in part because they manage pooled liquidity on one side while holding tokens in transit on the other, and in part because the code touchpoints multiply: a deposit contract here, an intent solver there, a chain-specific hot wallet somewhere else, each with its own upgrade path and key management. Every additional chain NEAR Intents connects adds another code path to audit and one more threshold for the same bug class to slip through. The 11 paused chains tell you how wide that surface is.
The reimbursement question
Pledges to make users whole are now standard practice but execution varies. Some teams pay out within days from their own treasuries, others raise recovery funds, and a few, especially older failed bridges, have taken years or never delivered. In this case the math favors a clean payout: 3.8 million dollars against a project backed by the NEAR Foundation and a token market cap around 6.4 billion dollars is a modest balance-sheet hit if the team decides to absorb it directly. The unresolved question is whether reimbursement comes from the treasury or from recovered funds if law enforcement freezes the KuCoin-linked wallet, an important difference for anyone reading the promise as a guarantee rather than an intent.
What happens next is mostly operational. The team has patched the contract, is monitoring for leftover exploit paths, and has promised reimbursement in full, which is a commitment it has made but not yet executed. Users with funds in transit should watch official communication about the claim process rather than community channels. Competing cross-chain services will be running the same class of audits on their own deposit systems in the meantime, since the exploit will now be studied by everyone running similar architectures, and one clean patch in public view helps the whole segment defend against the same trick next month.
