Skip to content

exploit

NEAR Intents drained for $3.8M via Omni deposit-layer bug

NEAR Intents paused cross-chain swaps on 11 networks Oct 1 after a bug in its Omni deposit/withdrawal layer let an attacker drain ~$3.8M. Contract patched; full reimbursement pledged.

by 3 min read

NEAR Intents, the cross-chain trading system built around the NEAR Protocol, halted deposits and withdrawals on eleven networks on Oct 1 after an attacker exploited a bug in its Omni deposit and withdrawal layer, draining roughly $3.8M. The team patched the contract-side flaw within hours, resumed core services, and said every affected user will be made whole.

What happened

The anomaly first surfaced as irregular withdrawals from a BNB Chain hot wallet. On-chain investigator ZachXBT flagged the flow early, tracing stolen funds to KuCoin and onward bridges to Bitcoin. The team confirmed the incident on X, pinning the root cause to how the Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract.

Services were paused across the full cross-chain surface: deposits and withdrawals went offline on 11 networks, including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, Scroll and Plasma. Core intent-matching came back within about an hour; the deposit/withdrawal rails on the affected networks stayed down for roughly 12 hours longer while Omni-side fixes rolled out.

Mechanism

NEAR Intents routes user intents across heterogeneous chains via the Omni bridge-and-settlement layer. Users deposit on any supported chain, the solver network competes to fill the intent, and funds settle through Omni on the far side. The flaw sat at the junction between Omni's deposit/withdrawal accounting and the NEAR Intents contract — the team has not published the full write-up yet but said the contract-side vulnerability has been patched and Omni-side mitigations were in progress on the same day.

That junction is the standard failure surface for intent-based bridges: the solver and settlement sides each hold accounting assumptions the other must honor, and a mismatch at the boundary becomes a withdrawal primitive.

Impact and response

  • Direct loss: ~$3.8M, routed through KuCoin and converted into bitcoin.
  • Users: NEAR Intents pledged full reimbursement; the exploit will land on protocol treasury rather than depositors.
  • Operational: 11 networks' deposit/withdrawal paths offline for several hours. Intent matching on resumed chains worked throughout.
  • Investigation: law enforcement contacted; a detailed post-mortem is promised "in the coming days."

Context

The hit lands days after NEAR Intents publicly disputed Decrypt reporting that linked it to money flow from the DPRK-attributed Bitget exploit — the team denied the attribution before the Omni bug was found. The two issues are separate: the Oct 1 drain is a vulnerability in NEAR's own stack, not an inflow from a sanctioned counterparty.

Intent-based cross-chain architectures — NEAR Intents, Across, UniswapX, deBridge DLN — all share the same brittle seam. 2026's bridge-hack pattern now includes four nine-figure or near-nine-figure incidents on bridge/solver layers; this one stays well short of that scale but exposes the same class of accounting-boundary bug.

What to watch

  1. The detailed post-mortem from NEAR Intents — specifically whether the bug was in Omni's reconciliation or in the Intents contract's trust assumptions about Omni messages.
  2. Whether other projects integrating Omni (NEAR Intents is the flagship, not the only consumer) deploy the same patch.
  3. ZachXBT's trace: funds went KuCoin → BTC. KuCoin's response window on freeze requests from a protocol operator (rather than law enforcement) is the practical ceiling on recovery.
  4. The named chains' own validator and bridge teams: TON, Monad and Plasma are the newer integrations on the list.

Related stories