NewsCryptoNEAR Intents Exploit Drains $3.8 Million; Deposits and Withdrawals Restricted Across 11 Networks

NEAR Intents Exploit Drains $3.8 Million; Deposits and Withdrawals Restricted Across 11 Networks

Author: CryptoMeter io·

Key Takeaways

  • •NEAR Intents lost $3.8 million in an Oct. 1 exploit tied to a bug in its Omni deposit and withdrawal infrastructure and a smart contract.
  • •Deposits and withdrawals remained unavailable across 11 networks, including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma, while remediation work continued.
  • •The project said it has patched the contract-side vulnerability and plans to fully reimburse affected users.
  • •Blockchain investigator ZachXBT said the stolen funds moved through KuCoin and were converted or bridged into Bitcoin, and the project filed a report with law enforcement while working with security and analytics firms to trace the funds.
  • •The exploit affected the NEAR Intents platform rather than the underlying NEAR Protocol blockchain, but the NEAR token still fell sharply after the disclosure.
NEAR Intents Exploit Drains $3.8 Million; Deposits and Withdrawals Restricted Across 11 Networks

NEAR Intents, a cross-chain trading platform, suffered a $3.8 million security exploit on Oct. 1, forcing the project to halt services and restrict deposits and withdrawals across multiple networks. The disclosure also pushed the NEAR token lower as investors assessed whether the attack exposed a broader weakness in the NEAR ecosystem.

According to CoinDesk, NEAR Intents attributed the loss to a bug involving its Omni deposit and withdrawal infrastructure and its smart contract. The project said it has patched the contract-side vulnerability and plans to reimburse affected users in full.

Based on the information available so far, the incident affected NEAR Intents rather than the underlying NEAR Protocol blockchain. The distinction matters because NEAR Intents operates cross-chain infrastructure that connects assets across multiple networks, separate from the layer-one blockchain itself. It also frames the response: the remediation so far — a contract-side patch and a full reimbursement plan — has come from the platform's operator rather than from any change to the chain itself.

What the exploit affected

NEAR Intents stopped services after detecting irregular activity involving the infrastructure used to process withdrawals. Blockchain investigator ZachXBT said the stolen funds moved through KuCoin and were later converted or bridged into Bitcoin.

CoinDesk reported that the project filed a report with law enforcement and is working with security and blockchain analytics firms to trace the funds.

The platform facilitates cross-chain swaps by allowing users to specify desired transactions while independent market makers compete to execute them. That architecture reduces the need for users to manage individual bridges and routes, but it also creates additional infrastructure dependencies. Assets moving between networks pass through the platform's own deposit and withdrawal rails and contracts, concentrating the flow through components the user does not directly control — the same Omni infrastructure and contract code the project identified in the bug.

Eleven networks remain restricted

Deposits and withdrawals remained unavailable across 11 networks while NEAR Intents continued its remediation work. The affected networks are:

  • BNB Smart Chain
  • Polygon
  • TON
  • Optimism
  • Avalanche
  • Stellar
  • Monad
  • X Layer
  • ADI
  • Scroll
  • Plasma

NEAR Intents said core services had been expected to resume sooner, while the affected deposit and withdrawal rails required additional work. For users, the list is the practical boundary of the incident: until a given network's rails reopen, funds cannot move into or out of the platform through it, regardless of conditions on that network's underlying chain.

NEAR fell sharply following the disclosure, adding to market pressure after a strong September rally and the recent launch of the first U.S. spot NEAR ETF. However, the available reporting does not establish that the NEAR blockchain itself was compromised.

The project has promised a fuller technical report in the coming days, and the fund-tracing work with law enforcement and the security and blockchain analytics firms remains ongoing. Until that report arrives, the key distinction remains between the NEAR Protocol blockchain and the cross-chain infrastructure operated by NEAR Intents. The exploit demonstrates risks in the latter, but current reporting does not show a direct compromise of NEAR's underlying blockchain. Readers tracking the story have two concrete markers to watch: the contents of that technical report, and the pace at which deposits and withdrawals come back online across the 11 restricted networks.