Skip to content
Est. MMXXVIVol. VI · № 344RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 344Bridge Exploit

NEAR Intents Omni Deposit Exploit

An attacker abused a bug in NEAR Intents' Omni cross-chain deposit and withdrawal system to drain roughly $3.8 million in USDT from a BNB Chain hot wallet.

Date
Chain(s)
Status
Funds Stolen

On October 1, 2026, NEAR Intents — the cross-chain settlement layer promoted by NEAR co-founder Illia Polosukhin — was drained of roughly $3.8 million, after an attacker abused a bug in its Omni deposit and withdrawal system to pull stablecoins out of a hot wallet.

What happened

NEAR Intents lets users express a desired outcome — a swap or a transfer — and have solvers fulfil it across many chains, with the Omni component handling the deposits and withdrawals that move value on and off each network. The attacker exploited a flaw in the way Omni's deposit and withdrawal flow interacted with the NEAR Intents smart contract, which let them withdraw more value than they were entitled to. The theft centred on USDT on BNB Chain, drained from a protocol-controlled hot wallet. NEAR Intents' AI-driven monitoring layer, SHIELD, flagged the anomalous activity and triggered an automatic pause; the team said it patched the underlying vulnerability within roughly an hour of detection. While it investigated, deposits and withdrawals were suspended across eleven networks — BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. The core NEAR protocol, the NEAR token and other applications were unaffected.

Aftermath

On-chain investigator ZachXBT traced the stolen funds from the BNB Chain hot wallet to the KuCoin exchange, where they were swapped into bitcoin. NEAR Intents said it had reported the incident to law enforcement and was working with security and blockchain-analytics firms to follow the money. The team brought near.com and the Intents service back online once the fix was confirmed, though some chains stayed restricted, and pledged to reimburse every affected user in full. The incident weighed on the market: the NEAR token slid about 7.5%, falling from roughly $5.5 to $4.7.

Why it matters

NEAR Intents joins the run of 2026 losses that struck not a user's own contract but the cross-chain plumbing that custodies and moves value between networks — the same class of failure seen at Across Protocol, Symbiosis and Allbridge. The rapid detection-and-patch cycle shows the value of automated monitoring, but the attacker still cashed out through a centralized exchange before funds could be frozen — the same KuCoin-to-bitcoin laundering route traced days earlier in the Bitget breach. In a year already defined by nine-figure infrastructure exploits, it is a reminder that an intents layer is only as safe as the deposit-and-withdrawal code sitting beneath it.

Sources & on-chain evidence

  1. [01]coindesk.comhttps://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues
  2. [02]crypto.newshttps://crypto.news/near-intents-resumes-service-after-3-8m-exploit/
  3. [03]u.todayhttps://u.today/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75
  4. [04]cryptoticker.iohttps://cryptoticker.io/en/near-intents-exploit-withdrawals-halted/
  5. [05]coincentral.comhttps://coincentral.com/near-intents-hacked-for-3-8-million-in-latest-crypto-exploit

Related filings