NEAR Intents says it patched a $3.8 million exploit hours after pausing services

Oct 08, 2026 09:08 Written by Newisty Editorial Team near intents hack bitget defi near
NEAR Intents says it patched a $3.8 million exploit hours after pausing services

NEAR Intents, a protocol that helps users move crypto across different blockchains, said it was hacked on October 1 and lost about $3.8 million. The team paused its services, patched the problem, and said trading had already restarted on most supported networks a few hours later.

An exploit is an attack that takes advantage of a flaw in the code running a protocol or platform. In this case, NEAR Intents said the flaw was in what it calls a "contract-side vulnerability" in its Omni deposit and withdrawal system, the part that handles crypto moving in and out of the protocol.

What the protocol said on October 1

NEAR Intents announced the incident at 2pm GMT+1 on October 1. It said services would restart within the hour once the vulnerability was patched.

The protocol also warned that deposits and withdrawals would stay unavailable on a long list of blockchains until the Omni system was fully fixed. The named networks were BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma. A blockchain is the shared ledger that records crypto transactions, and a protocol like this one lets users swap or transfer assets between them without using a central exchange.

A blockchain is the shared ledger that records crypto transactions, and a protocol like this one lets users swap or transfer assets between them without using a central exchange.

The team's later update

In a follow-up post on October 1, a NEAR account described as chronear wrote that the protocol had been "intensely battle-tested," that the exploit was quickly found, contained and patched, and that trading had already resumed across most networks.

What an independent tracker said

Crypto sleuth ZachXBT, who tracks on-chain activity for followers online, documented the exploit separately. He reported that NEAR Intents' hot wallet on BSC, the wallet holding funds the protocol uses to move assets, showed unusual outflows before transactions stopped processing.

ZachXBT said the funds were sent straight to Kucoin and then bridged to Bitcoin. A bridge is a service that moves an asset from one blockchain to another.

Key numbers

  • $3.8 million: the amount taken, according to the report on the incident
  • 2pm GMT+1 on October 1: when NEAR Intents disclosed the incident
  • Within the hour: the restart window the protocol gave at the time of disclosure
  • $5.1 to $4.79: the drop in the NEAR token's price in the minutes after the disclosure, according to the CoinGecko page linked in the report

Days earlier, the same protocol froze Bitget hack money

This happened shortly after NEAR Intents became involved in a separate case. Earlier in October, the centralised exchange Bitget, which is a company that runs a platform where people trade crypto, was hacked for more than $380 million in an attack that the report says was likely carried out by North Korea.

NEAR Intents' general manager, Alex Shevchenko, said about $50 million in Bitget funds tried to pass through the protocol. He said the protocol froze $503,000, while about $166,000 was able to move on. He said the rest "went to other providers."

Why users are debating how decentralized the protocol is

Decentralised means no single company controls the system. That word has come up because NEAR Intents both froze stolen funds earlier this month and halted its services on October 1. The report says those two actions sparked debate among crypto users about how decentralised NEAR Intents really is.

The report compares this with THORChain, a different protocol that handled some of the same Bitget funds. Bitget's chief executive asked THORChain to refuse service to the people moving the funds, and the protocol declined, saying it is decentralised and permissionless, meaning anyone can use it without approval. THORChain did pause its own services earlier this year after it was hacked for $10 million.

What is confirmed and what is not

Confirmed by the protocol itself: the October 1 incident, the pause, the stated cause of a contract-side vulnerability in the Omni system, and the later claim that trading resumed on most networks.

Reported by an outside tracker: the description of the BSC hot wallet outflows and the route from the wallet to Kucoin and on to Bitcoin. ZachXBT's findings are his own analysis and have not been confirmed in the material reviewed here.

Not established by the sources: how the vulnerability was found and exploited, whether any stolen funds were recovered, and whether attackers have been identified. The material reviewed does not address these points.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!