NEAR Intents Omni Deposit Exploit
An attacker abused a bug in NEAR Intents' Omni cross-chain deposit and withdrawal system to drain roughly $3.8 million in USDT from a BNB Chain hot wallet.
- Date
- Victim
- NEAR Intents
- Chain(s)
- Status
- Funds Stolen
On October 1, 2026, NEAR Intents — the cross-chain settlement layer promoted by NEAR co-founder Illia Polosukhin — was drained of roughly $3.8 million, after an attacker abused a bug in its Omni deposit and withdrawal system to pull stablecoins out of a hot wallet.
What happened
NEAR Intents lets users express a desired outcome — a swap or a transfer — and have solvers fulfil it across many chains, with the Omni component handling the deposits and withdrawals that move value on and off each network. The attacker exploited a flaw in the way Omni's deposit and withdrawal flow interacted with the NEAR Intents smart contract, which let them withdraw more value than they were entitled to. The theft centred on USDT on BNB Chain, drained from a protocol-controlled hot wallet. NEAR Intents' AI-driven monitoring layer, SHIELD, flagged the anomalous activity and triggered an automatic pause; the team said it patched the underlying vulnerability within roughly an hour of detection. While it investigated, deposits and withdrawals were suspended across eleven networks — BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. The core NEAR protocol, the NEAR token and other applications were unaffected.
Aftermath
On-chain investigator ZachXBT traced the stolen funds from the BNB Chain hot wallet to the KuCoin exchange, where they were swapped into bitcoin. NEAR Intents said it had reported the incident to law enforcement and was working with security and blockchain-analytics firms to follow the money. The team brought near.com and the Intents service back online once the fix was confirmed, though some chains stayed restricted, and pledged to reimburse every affected user in full. The incident weighed on the market: the NEAR token slid about 7.5%, falling from roughly $5.5 to $4.7.
Why it matters
NEAR Intents joins the run of 2026 losses that struck not a user's own contract but the cross-chain plumbing that custodies and moves value between networks — the same class of failure seen at Across Protocol, Symbiosis and Allbridge. The rapid detection-and-patch cycle shows the value of automated monitoring, but the attacker still cashed out through a centralized exchange before funds could be frozen — the same KuCoin-to-bitcoin laundering route traced days earlier in the Bitget breach. In a year already defined by nine-figure infrastructure exploits, it is a reminder that an intents layer is only as safe as the deposit-and-withdrawal code sitting beneath it.
Sources & on-chain evidence
- [01]coindesk.comhttps://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues
- [02]crypto.newshttps://crypto.news/near-intents-resumes-service-after-3-8m-exploit/
- [03]u.todayhttps://u.today/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75
- [04]cryptoticker.iohttps://cryptoticker.io/en/near-intents-exploit-withdrawals-halted/
- [05]coincentral.comhttps://coincentral.com/near-intents-hacked-for-3-8-million-in-latest-crypto-exploit