
A blockchain cross-chain swap service called NEAR Intents disclosed on October 1, 2026, that it suffered a security breach after attackers exploited a bug linking its Omni infrastructure to the platform’s smart contracts. The NEAR Intents security breach drained more than $3.8 million from a BSC hot wallet before the team moved to contain the damage, patch the flaw and promise full reimbursement to affected users.
Key takeaways
NEAR Intents confirmed a security incident caused by a bug in how its Omni deposit and withdrawal infrastructure interacted with its smart contracts.
Over $3.8 million was stolen through irregular outflows from the platform’s BSC hot wallet.
Stolen funds were quickly routed to KuCoin and bridged into Bitcoin.
The vulnerability has been patched, with core services expected to resume within an hour of the announcement.
Deposits and withdrawals across EVM, BSC, Polygon and TON will stay suspended for roughly 12 hours while security partners and law enforcement assist with recovery.
NEAR Intents Confirms Security Breach and Immediate Response
NEAR Intents moved fast once the exploit was detected, patching the underlying flaw and setting a recovery timeline within hours rather than days. The team publicly attributed the loss to a technical breakdown between its Omni infrastructure and its smart contracts, rather than a broader compromise of the protocol itself.
Cause of the exploit and affected infrastructure
According to NEAR Intents, the root cause traced back to a bug in the interaction between Omni deposit and withdrawal infrastructure and smart contracts. Omni handles how assets move in and out of the platform across different blockchains, and a flaw in that connective layer allowed attackers to siphon funds without authorization. The company confirmed the vulnerability has since been patched.
Timeline and scope of suspended services
NEAR Intents said core services would resume within an hour of its announcement, a relatively tight window meant to limit disruption for users. At the same time, the company kept a wider net of protections in place: deposits and withdrawals across EVM-based chains along with BSC, Polygon and TON will remain suspended for approximately 12 hours. That longer freeze gives the team and its partners room to monitor for further irregular activity before fully reopening the platform.
Financial Impact and Flow of Stolen Assets
The exploit hit NEAR Intents’ BSC hot wallet specifically, and the stolen crypto didn’t sit still for long. Attackers moved quickly to cash out before defenses could catch up, a pattern common in on-chain exploits where speed determines how much, if any, of the loss can be clawed back.
Details of the stolen funds and wallet affected
The BSC hot wallet tied to NEAR Intents showed irregular outflows totaling over $3.8 million. Hot wallets, which stay connected to the internet to process transactions quickly, are frequently the weak point in exchange and protocol security because they trade some safety for operational speed.
Routing of stolen assets to KuCoin and Bitcoin
Once drained, the funds were swiftly routed to KuCoin and then bridged into Bitcoin. This kind of rapid cross-chain movement is a familiar tactic among crypto thieves, since converting stolen tokens into a widely held asset like Bitcoin makes tracing and freezing the funds harder the further they travel from the original wallet.
Recovery Efforts and Reimbursement Commitment
NEAR Intents has pledged to make affected users whole, a commitment that puts the protocol’s own balance sheet or reserves on the line rather than leaving losses with individual traders. That pledge, paired with an active recovery effort, is the clearest signal of how the team is handling the fallout.
Collaboration with security partners and law enforcement
NEAR Intents said security partners and law enforcement are now assisting in tracking and attempting to recover the stolen assets. Bringing in outside investigators alongside internal teams reflects a now-standard playbook for crypto platforms responding to breaches, especially once stolen funds cross into exchanges or get bridged to another chain.
Full reimbursement pledge by NEAR Intents team
The team confirmed that all lost funds will be fully compensated, regardless of whether the stolen $3.8 million is ultimately recovered. This matters for users watching the NEAR Intents security breach unfold in real time: it shifts the financial risk away from individual depositors and onto the platform itself, at least for this incident.
Role of onchain analyst ZachXBT in identifying the exploit
The exploit first surfaced publicly through onchain analyst ZachXBT, who flagged the ongoing attack after spotting the irregular outflows from the BSC hot wallet. Independent onchain sleuths like ZachXBT have become a recurring early-warning layer in crypto security, often surfacing suspicious activity before official statements catch up.
The combination of a quick patch, a firm reimbursement promise and outside help from law enforcement suggests NEAR Intents is treating this as a contained technical failure rather than a systemic flaw in its broader architecture. Whether that framing holds will depend on how much of the $3.8 million gets recovered once the 12-hour suspension lifts and full operations resume.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.
