The cross-chain transaction protocol NEAR Intents suffered another security incident, with about $3.8 million in assets reportedly stolen.

The NEAR Intents team stated that the incident originated from a vulnerability that occurred when their Omni deposit/withdrawal infrastructure interacted with the NEAR Intents smart contracts. After detecting the anomaly, the team paused the service, and said the contract-side vulnerability had been patched within about an hour of discovery. Affected users will receive full compensation.

NEAR co-founder Illia Polosukhin also emphasized that the scope of this incident mainly affected USDT assets on the BNB Chain. The NEAR mainnet, NEAR tokens, and other applications were not directly impacted.

About 3.865 million USDT was withdrawn, sent out in 5 transactions

Blockchain analytics firm Bitquery further tracked and pointed out that between the evening of September 30 and October 1, the attacker withdrew about 3.865 million USDT in 5 transactions from a BNB Chain treasury address used by NEAR Intents. The entire process lasted about 6 hours.

After the funds were moved, they were converted into BNB and then split into dozens of new addresses. Bitquery indicates that, as of the afternoon of October 1, about 99% of the stolen funds have been traced to their destinations, including:

  • About 76% was converted into 34.69 BTC, distributed across 4 Bitcoin addresses;

  • About $802,000 flowed into KuCoin addresses;

  • About $90,000 was converted into Monero-related assets.

ZachXBT: abnormal funds flowed to KuCoin, then bridged to Bitcoin

On-chain investigator ZachXBT discovered early on that the BNB Chain hot wallet of NEAR Intents saw abnormal outflows, and pointed out that the funds were then sent to KuCoin and subsequently bridged to Bitcoin.

However, as of now, KuCoin has not publicly confirmed whether it has frozen the relevant accounts or funds. An overseas media report said it had contacted KuCoin for inquiries, but had not received an immediate response.

Today, on the 2nd, the incident saw new developments again. NEAR Intents General Manager Alex Shevchenko said the team has identified the attacker and publicly called out: “We already know who you are.” The team also provided repayment addresses such as BTC, BNB, and Solana for the attacker to return the funds within 48 hours through a “responsible disclosure” mechanism. If the deadline is exceeded, the team said this window will close.

NEAR Intents has been restored, but some cross-chain functions remain restricted

After NEAR Intents and near.com patched the vulnerability, their main services have been restored. However, at the beginning of the incident, deposit/withdrawal operations involving 11 networks were restricted, including BNB Chain, Polygon, Optimism, and others. The team originally estimated that it would take about 12 additional hours to gradually restore everything. As of October 2, NEAR Intents has partially restored services.

NEAR Intents also states that it has worked with law enforcement agencies and on-chain analytics companies to track the funds, and will publish a full incident report later.

NEAR Intents is a cross-chain trading system built on the NEAR ecosystem (intent-based trading system). Its main job is to enable users to exchange assets between different blockchains. It uses infrastructure such as Omni Bridge to handle deposits and withdrawals between different chains. NEAR’s official documentation shows that Omni Bridge is the primary cross-chain settlement bridge for NEAR Intents, responsible for the in-and-out flows of multi-chain assets including Bitcoin, Ethereum, Arbitrum, Base, Solana, and TON.

This vulnerability occurred in the Omni deposit/withdrawal layer and in interactions with the NEAR Intents smart contracts, not in the NEAR consensus layer or the NEAR mainnet itself being compromised.

The market response to the incident was quite direct. After the incident was exposed, NEAR fell by around 6.7% in a single day at one point, dropping to about $4.9. According to the latest CoinGecko data as of October 2, NEAR is about $4.98, with 24-hour trading volume of around $1.47 billion; over the past 7 days, it is still up about 12.8%.

The timing of this incident is especially sensitive. NEAR Intents only announced about a month and a half ago that the platform’s cumulative cross-chain transaction volume had surpassed $25 billion. Currently, the NEAR Intents Explorer shows the platform’s cumulative transaction volume has exceeded $30 billion, with 24-hour transaction volume in the range of $80 million to $160 million.

In other words, this is no longer a small test protocol. Once a cross-chain system handles assets worth billions or even hundreds of billions of dollars, even a small vulnerability in a deposit/withdrawal layer could quickly turn into a multi-million-dollar incident.

Bitquery’s tracking also found a rather ironic detail: after the attacker stole the funds, about $822,000 worth of the proceeds was again used to conduct cross-chain exchanges through NEAR Intents itself—meaning the hacker stole from NEAR Intents, then used NEAR Intents to move the stolen funds away.

This highlights the double-edged nature of “cross-chain.” It makes it easier for ordinary users to trade assets across different blockchains; but the same convenience may also allow attackers to more quickly split, cross-chain, and convert the stolen assets.

"NEAR Intents hacked for over $3.8 million! Funds were sent into KuCoin, exchanged for BTC; the team says it has identified the hacker and will repay within 48 hours". This article was first published on (Blockcast).