NEAR Intents lost about $3.8 million to a cross-chain bug
NEAR Intents says a bug in its Omni deposit and withdrawal system caused the loss. It patched the contract-side flaw and promised reimbursement, but eleven chain routes were still disrupted.
Article
NEAR Intents stopped services after detecting a security incident.
The team says a bug in its cross-chain deposit and withdrawal system caused about $3.8 million in preliminary losses. It says the contract-side flaw is patched and affected funds will be compensated in full.
That does not mean everything is back to normal. At our latest check, official status pages still showed a partial swap outage and open incidents across eleven chain routes.
The disclosed bug affected NEAR Intents infrastructure. It was not reported as an exploit of the NEAR blockchain itself.
What broke
NEAR Intents is meant to hide some of the work involved in trading across blockchains. A user says what asset they have and what they want. Market makers compete to fill that request, while deposit and withdrawal systems move assets into and out of the trade.
For assets on other blockchains, NEAR Intents relies on a bridge. Its main route is called Omni Bridge.
The team’s early explanation places the bug where that Omni infrastructure interacted with the NEAR Intents smart contract. It has not yet published the exact vulnerable code path or a full transaction-by-transaction account.
NEAR Intents announced the incident, the preliminary loss and its response in one statement:
NEAR Intents said a bug in its Omni deposit and withdrawal infrastructure caused about $3.8 million in preliminary losses. It said the contract-side flaw was patched and affected funds would be compensated in full.
NEAR Intents (@near_intents) · October 1, 2026
Where the money went
A hot wallet is a wallet kept online so a service can make routine transfers. It is useful, but it is also more exposed than funds kept offline.
BlockSec said the attacker drained assets from a NEAR Intents hot wallet on BNB Chain. The security firm said the funds then moved through KuCoin and were bridged into Bitcoin. CoinDesk separately reported the same route through an account from onchain investigator ZachXBT.
BlockSec said assets left a NEAR Intents BNB Chain hot wallet, moved through KuCoin and were bridged to Bitcoin.
BlockSec Phalcon (@Phalcon_xyz) · October 1, 2026
The team calls $3.8 million a preliminary figure. It has not published a final list of affected tokens, a reimbursement schedule or proof that repayments have been completed.
What is still unavailable
NEAR Intents said its main swap operations were expected back within about one hour of the announcement. It gave deposits and withdrawals on eleven networks a longer estimate of about twelve hours.
At our October 1 check, the official route-status page still listed incidents for:
- BNB Smart Chain
- Polygon
- TON
- Optimism
- Avalanche
- Stellar
- Monad
- X Layer
- ADI
- Scroll
- Plasma
The general status page also showed a partial outage for the 1Click Swap API.
The explorer was still displaying recent successful swaps and more than $30.5 billion in all-time volume. That shows the service is large and that some activity continued. It does not prove every route was healthy.
What traders and users should watch
- Route reopening: the practical recovery test is whether deposits, withdrawals and 1Click swaps return without another pause.
- The postmortem: the team still needs to explain the exact bug, when it began and why the fix prevents a repeat.
- Compensation: a promise to reimburse users is not the same as completed repayments. Watch for eligibility, timing and transaction evidence.
- The final loss: $3.8 million is preliminary. The amount can change after token-by-token accounting and any recovery.
- NEAR’s price: NEAR was near $4.87 at our check, down about 6.7% from the previous close. The timing matters, but it does not prove this incident caused the entire move.
The contract patch is the first response. Full recovery requires the routes to reopen, users to be made whole and a detailed explanation of how the failure happened.
Sources and reporting notes
Checked October 1, 2026. The preliminary cause, loss, patch and compensation commitment come from NEAR Intents’ official statement. Current service scope comes from its general status page and Shield route-status board. Product mechanics come from NEAR’s bridge documentation and NEAR Intents’ market-maker documentation.
CoinDesk independently reported the incident and cited ZachXBT’s hot-wallet trace. BlockSec published a matching short security summary. The detailed postmortem and completed reimbursement evidence were not available at review time.