TL;DR
- NEAR Intents halted its services following an exploit that caused losses of approximately $3.8 million.
- The flaw originated in the interaction between the Omni deposit and withdrawal system and the protocol’s smart contract, a vulnerability that has already been patched.
- ZachXBT detected irregular outflows from a hot wallet on BNB Chain; the stolen funds were sent to KuCoin and converted to bitcoin.
NEAR Intents, the cross-chain swap protocol operating on the NEAR ecosystem, suspended its services on Thursday, October 1, after detecting an exploit that resulted in losses of approximately $3.8 million. The team confirmed the incident through a post on X and stated that the affected funds will be fully reimbursed.
According to the team, the attack exploited a flaw in the way the Omni deposit and withdrawal system interacted with the protocol’s smart contract. The vulnerability was patched within hours, and both NEAR Intents and Near.com estimated they would resume normal operations in under an hour.
Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.
The preliminary report indicates the total loss of…
— NEAR Intents (@near_intents) October 1, 2026
However, deposits and withdrawals across 11 networks —including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma— would remain blocked for approximately 12 additional hours while the fixes are completed.
NEAR Intents: Tracking the Stolen Funds
On-chain investigator ZachXBT identified the origin of the exploit in irregular outflows from a BNB Chain hot wallet linked to the protocol. The stolen funds were transferred to the exchange KuCoin and subsequently converted to bitcoin. KuCoin has not issued a statement on the matter as of this writing.
NEAR Intents reported that it is already in contact with law enforcement agencies and blockchain analytics platforms to trace the assets, and anticipated the publication of a post-mortem report in the coming days.
Just a few weeks ago, the protocol reported having surpassed $25 billion in cumulative historical volume, and its statistics page indicates it has processed more than $30 billion across 35 blockchains. Its native token NEAR fell around 6% in the 24 hours following the announcement, although the vulnerability compromised the cross-chain infrastructure and not the underlying protocol itself.
The attack adds to a string of security incidents in the crypto industry throughout 2026. Just the previous week, the exchange Bitget suffered an exploit exceeding $350 million, while other notable cases included Liquid Network with $320 million, Drift with $295 million, and Kelp with $293 million, according to data from DefiLlama.




