Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,810▲ 1.09%ETH$2,701▲ 0.79%SOL$118.38▼ 0.38%TOTAL CRYPTO$2.9T▼ 2.27%S&P 5007,669.01▲ 0.49%NASDAQ26,919.22▲ 3.14%DOW50,914.15▼ 3.51%GOLD4,201.00▼ 4.44%WTI93.06▲ 3.15%BRENT102.54▲ 8.34%EUR/USD1.1233▼ 3.31%USD/JPY158.18▼ 0.98%DXY102.16▲ 2.50%
Crypto

NEAR Intents Pauses Services After $3.8 Million Exploit

A bug in the Omni deposit infrastructure drained a BSC hot wallet. NEAR fell 9 percent and the team pledged full reimbursement to users.

Pexels – Daniel Dan

NEAR Intents, the cross-chain swap service built on NEAR Protocol, halted operations Thursday after an exploit drained roughly $3.8 million from its hot wallet on BNB Chain. The NEAR token fell about 9 percent within hours, dropping to around $4.92, though the underlying blockchain itself was not named as the target and the team says the protocol’s core contracts on NEAR were untouched.

How the attack unfolded

On-chain investigator ZachXBT flagged the incident first, spotting irregular outflows from the platform’s BSC hot wallet, the online wallet used to pay out withdrawals to users. Several large transfers left the address in quick succession before the service stopped processing transactions entirely. The outflows stood out because they did not match any user withdrawal pattern, which is usually the first sign of a compromised key rather than a smart contract failure.The stolen funds did not sit still. Investigators tracking the flows report the crypto was routed to KuCoin within minutes and then bridged into bitcoin, the standard playbook for attackers trying to break the trail before exchanges can freeze deposits. Whether any of it gets recovered will depend on how quickly KuCoin acts and how the attackers handle the bitcoin after the bridge.The team traced the breach to a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract. “The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract,” the team said in a statement posted Thursday morning. “The contract-side vulnerability has been patched. The operations of the NEAR Intents and near(.)com are expected to resume within 1h.”

Services frozen across chains

Core swap operations were expected to resume within about an hour of the announcement, but deposits and withdrawals across EVM chains, BSC, Polygon and TON were set to stay suspended for roughly 12 hours while security partners and law enforcement assist with recovery efforts. In total, eleven networks had deposits frozen at the time of the first reports, leaving traders with orders stuck in transit.The company promised full compensation to affected users. That pledge matters because NEAR Intents sits in the middle of a large volume of cross-chain trading, routing swaps between dozens of assets and chains through an intents-based model where users sign one order and the system handles the rest. Any freeze leaves orders stuck in flight, and the reimbursement promise will be tested on exactly those in-transit funds, where ownership at the moment of the halt is hardest to establish.

Incident Date Loss Status
Rhea Finance oracle exploit April 2026 $7.6 million Partial recovery
NEAR Intents hot wallet drain Oct. 1, 2026 $3.8 million Reimbursement pledged
Industry total, Q3 2026 (CertiK) Jul-Sep 2026 $1.26 billion 247 incidents

A rough stretch for NEAR

Timing could hardly have been worse for the token. NEAR’s first US spot ETF had launched just two days earlier, and the price had been holding up on the news. The 8.6 percent drop on Thursday erased much of the week’s gains and pushed NEAR to around $4.92, its weakest level in recent weeks. Traders who bought the ETF news found themselves underwater within 48 hours.It is also the second major security failure in the NEAR ecosystem this year. Rhea Finance, a lending protocol on the network, lost $7.6 million to an oracle manipulation in April. Together, the two incidents have drained more than $11 million from projects built on or around the chain, and both hit infrastructure and pricing mechanisms rather than end-user wallets.The token’s sharp response contrasted with a pattern some traders have noticed this year: smaller ecosystems sometimes absorb exploit news with muted price action because trading is thin and few holders care enough to sell. NEAR’s 9 percent move shows a market with real liquidity reacting to a real event, not a thin book overreacting to noise.

The year of the hot wallet

The exploit lands in a year that has already been expensive for crypto users. CertiK counted 247 security incidents in the third quarter alone, with $1.26 billion lost across hacks, scams and exploits. September was the worst month of 2026 so far at $768.5 million, driven largely by a handful of large infrastructure breaches rather than thousands of small scams.Bitget’s $388 million breach, disclosed in recent days, and MetaMask Staking’s validator compromise on Wednesday both fit the same profile: attackers going after operational infrastructure, exchange hot wallets, staking middleware, bridge routers, rather than breaking consensus or cracking audited core contracts. The NEAR Intents incident is another entry in that list, and arguably the most instructive one, because the platform had passed audits on its core contracts while the plumbing around them failed.Cross-chain infrastructure has been a repeated target this cycle for a simple reason. Bridges and intent routers hold pooled liquidity in hot wallets that must stay online to serve withdrawals, which makes them the closest thing crypto has to a bank vault with the door left ajar. Every improvement in swap UX has added another pool of online funds for attackers to aim at.

What happens next

NEAR Intents said it expects to restore services progressively as fixes are validated, with the longest suspensions on the chains where fund flows are still being traced. The team has not published a compensation timeline. Recovery of the stolen bitcoin depends on KuCoin’s cooperation and on whether the funds can be traced through mixers before they are fully laundered.For the broader NEAR ecosystem, the calculus is uncomfortable. The ETF launch was supposed to mark the project’s arrival in US regulated markets and widen its investor base. Instead, the week’s headline is a seven-figure exploit on a flagship product. How quickly services come back, and whether the reimbursement is paid in full and fast, will do more for user trust than any listing. The platform’s next proof-of-reserves or security report will be read more closely than its last marketing push.

SourcesCoinDesk; The Block; BeInCrypto; Cryptonomist; CertiK (all Oct. 1, 2026 unless noted)
Share: X