Just as Bitget’s anti-hacker money-laundering channel was blocked with the help of the “front foot,” the company was robbed for $3.8 million right after—cross-chain protocol NEAR Intents turned “guarded the front door but not the back door” into a real-life scene.
On October 1, the official confirmation stated that there was a bug in the Omni deposit/withdraw system’s interaction with smart contracts. The attacker first tested the waters with a small $10 amount, then withdrew about 3.865 million USDT in roughly 5 installments from the BSC hot wallet. Of that, nearly 76% was converted into BTC (about 34.69 BTC), and some funds were transferred via KuCoin. $NEAR fell by about 8.6% that day.
The most painful part: just a few days before the hack, NEAR Intents’ SHIELD security system had successfully intercepted a money-laundering attempt involving hacked funds targeting Bitget. It kept out the outside thieves, only to fall due to an integration vulnerability in its own code. The official has now admitted that it has issued a 48-hour final notice to the hacker, demanding “responsible disclosure” and the return of funds, while also promising full compensation for affected users and stating that police reports have been filed.
My take: in recent years, cross-chain aggregators have been competing over “one intent that solves everything,” but the more layers of abstraction, the more layers of attack surface you add. What regular users can actually do is quite concrete—don’t leave assets sitting overnight in cross-chain bridges and aggregators; move them as soon as you’re done. Also revoke authorization lists periodically. That’s more reliable than putting all your hopes on the project team’s audit reports. The drop for $NEAR is the “security premium.” Whether it can rebound depends entirely on whether the compensation and the vulnerability post-mortem deliver. I’ll keep following these kinds of security incidents—follow me so you don’t get lost.
Data as of: 2026-10-02 12:00 UTC
Source: NEAR Intents official announcement; CCN (on-chain tracking: Bitquery/ZachXBT)
For information sharing only and does not constitute investment advice.
$NEAR $BTC $BNB
On October 1, the official confirmation stated that there was a bug in the Omni deposit/withdraw system’s interaction with smart contracts. The attacker first tested the waters with a small $10 amount, then withdrew about 3.865 million USDT in roughly 5 installments from the BSC hot wallet. Of that, nearly 76% was converted into BTC (about 34.69 BTC), and some funds were transferred via KuCoin. $NEAR fell by about 8.6% that day.
The most painful part: just a few days before the hack, NEAR Intents’ SHIELD security system had successfully intercepted a money-laundering attempt involving hacked funds targeting Bitget. It kept out the outside thieves, only to fall due to an integration vulnerability in its own code. The official has now admitted that it has issued a 48-hour final notice to the hacker, demanding “responsible disclosure” and the return of funds, while also promising full compensation for affected users and stating that police reports have been filed.
My take: in recent years, cross-chain aggregators have been competing over “one intent that solves everything,” but the more layers of abstraction, the more layers of attack surface you add. What regular users can actually do is quite concrete—don’t leave assets sitting overnight in cross-chain bridges and aggregators; move them as soon as you’re done. Also revoke authorization lists periodically. That’s more reliable than putting all your hopes on the project team’s audit reports. The drop for $NEAR is the “security premium.” Whether it can rebound depends entirely on whether the compensation and the vulnerability post-mortem deliver. I’ll keep following these kinds of security incidents—follow me so you don’t get lost.
Data as of: 2026-10-02 12:00 UTC
Source: NEAR Intents official announcement; CCN (on-chain tracking: Bitquery/ZachXBT)
For information sharing only and does not constitute investment advice.
$NEAR $BTC $BNB
