ZachXBT Reports $3.8 Million Exploit Involving NEAR Intents
Key Takeaways
- •ZachXBT, a pseudonymous on-chain investigator known for tracing stolen crypto funds, has reported a $3.8 million loss linked to NEAR Intents, a cross-chain transaction system on NEAR Protocol.
- •The exploit method, the identity of affected parties, and any remediation efforts have not been publicly confirmed, and NEAR Protocol has not issued an official statement alongside the report.
- •NEAR Intents uses an intent-and-solver architecture in which users state desired asset actions, such as cross-chain token swaps, and automated solvers execute them across multiple markets.
- •Cross-chain systems have been frequent attack targets, with bridges including Ronin, Wormhole, and Nomad losing hundreds of millions of dollars in exploits during 2021 and 2022.
- •The reported $3.8 million figure should be treated as an early estimate that may change as more complete on-chain analysis becomes available.

On-chain investigator ZachXBT has reported a3.8 million exploit involving NEAR Intents, a cross-chain transaction system built on the NEAR Protocol blockchain. The report is still developing, and key details — including how the funds were taken, who was affected, and whether any recovery is underway — have not yet been publicly confirmed.
What ZachXBT Reported
ZachXBT, a pseudonymous blockchain investigator known for tracing stolen crypto funds, flagged a reported loss of $3.8 million linked to NEAR Intents. His initial report named the figure and its connection to NEAR Intents but did not, at the time of publication, include a confirmed exploit vector or the identity of affected parties.
The exploit vector — the specific technical method used to drain the funds — has not been publicly confirmed in the information available at the time of writing. No official statement from the NEAR Protocol team has been confirmed alongside the initial report.
What NEAR Intents Is
NEAR Intents is a component of the NEAR Protocol ecosystem. It lets users express what they want to do with their assets — such as swapping tokens across different blockchains — and uses automated solvers to carry out those actions. The system works like placing an order at a counter: the user states what they want, and the system determines how to execute it across multiple markets at once. NEAR Protocol itself is a proof-of-stake layer-1 blockchain, and intent-and-solver designs of this kind have become a common architecture for cross-chain execution across the industry.
The category also carries a well-documented security history: cross-chain bridges were among the most heavily attacked systems in crypto during 2021 and 2022, when exploits at protocols including Ronin, Wormhole, and Nomad each drained hundreds of millions of dollars. Security researchers have frequently linked that pattern to the large pooled balances such systems hold as they move assets between networks.
ZachXBT's Track Record
ZachXBT has a history of surfacing on-chain exploits early. He previously traced $120.2 million in USDT flows that preceded a Tether freeze action, and his early alerts often prompt responses from project teams shortly after publication. He has also flagged projects with misleading valuations and suspicious activity, including warning traders about Rain Protocol's $8.8 billion valuation claim. His reports have consistently served as early signals ahead of fuller investigations.
What the Report Could Mean for NEAR Intents Users
Users of NEAR Intents, or those holding assets through it, are advised to monitor official communications from the NEAR Protocol team directly and to avoid relying on unverified social media speculation about what to do with their funds.
The NEAR Protocol ecosystem's total value locked (TVL) — a measure of how much money is held across its applications — can be tracked in real time on DeFiLlama's NEAR chain overview. A significant drop there would signal broader impact beyond the initial reported figure. For live NEAR token price data, CoinMarketCap's NEAR page provides up-to-date market information.
Several details remain unconfirmed and should be treated with caution until verified by the NEAR team or independent on-chain analysis: the specific contracts or wallets involved, whether user funds are at direct risk, and whether any remediation or protocol pause has been enacted.
What to Watch Next
Key follow-up items for anyone tracking the story include an official response from NEAR Protocol, an independent on-chain breakdown of the affected transactions, and any announcement about whether the exploit has been patched or user withdrawals restricted.
Until those details emerge, the $3.8 million figure should be treated as a reported estimate rather than a confirmed final loss. Exploit amounts reported in the early stages often shift as more complete on-chain data is reviewed.
Cross-chain infrastructure like NEAR Intents sits at the junction of multiple blockchains, meaning a confirmed exploit there could have implications beyond the NEAR network alone. Watching for official project communications remains the most reliable way to stay informed as the story develops.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.