cleartext

Independent, sourced crypto news. No paid placements.

near

NEAR Intents halts trading after $3.8M exploit, pledges to make users whole

NEAR Intents paused its cross-chain trading service on October 1 after a smart-contract bug drained about $3.8 million, which an investigator traced to KuCoin and into bitcoin; the team patched the flaw and promised full reimbursement.

NEAR Intents, the cross-chain trading system tied to the NEAR blockchain, paused operations on Thursday, October 1, after an exploit drained roughly $3.8 million. The team says it has patched the underlying bug and will reimburse affected users in full — a pledge that, for now, remains a promise rather than a completed fact. The Block and CoinDesk both reported the loss at approximately $3.8 million, citing the project's own disclosure.

What happened

NEAR Intents is designed to hide the plumbing of cross-chain swaps. Rather than making users pick a bridge, exchange or route, the platform lets them state the trade they want; independent market makers called "solvers" then compete to fill it in the background, as CoinDesk described the mechanics.

According to the team's own statements, relayed by both outlets, the incident stemmed from a bug in how its "Omni" deposit-and-withdrawal infrastructure interacted with the NEAR Intents smart contract. The contract-side vulnerability has since been patched. NEAR Intents said it reported the incident to law enforcement and brought in security and blockchain-analytics firms to trace the money, with a post-mortem promised "in the coming days."

The on-chain trail came from blockchain investigator ZachXBT, posting on Telegram. He said the exploit began with irregular outflows from a BNB Chain (BSC) hot wallet linked to NEAR Intents, after which the stolen funds were moved to the KuCoin exchange and bridged into bitcoin. The Block said it contacted KuCoin and did not receive an immediate reply; whether the exchange has frozen any of the funds is not known.

The disruption

The team expected core services — NEAR Intents and the Near.com front end — to resume quickly, within about an hour, per The Block. The longer disruption is to deposits and withdrawals, which were set to remain unavailable for roughly another 12 hours while fixes completed.

On the scope of that disruption, the two accounts line up at 11 networks. The Block named BSC, Polygon and Optimism among them. CoinDesk published the fuller list from the project's status page: BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma.

The NEAR token fell on the news, though it is worth noting the disclosed flaw sits in the cross-chain infrastructure, not the underlying NEAR Protocol blockchain itself, as CoinDesk pointed out. The two outlets give slightly different drops: The Block logged NEAR down about 7.35% over 24 hours, CoinDesk about 6%, quoting a price of $4.9444. Bitcoin, where the stolen funds ended up, was around $84,072 at CoinDesk's time of writing.

Key facts

  • Loss: ~$3.8 million (NEAR Intents' disclosure, via The Block and CoinDesk).
  • Date: Thursday, October 1, 2026.
  • Cause: a bug in how the Omni deposit/withdrawal infrastructure interacted with the NEAR Intents smart contract; contract-side flaw patched (NEAR Intents).
  • Fund trail: irregular outflows from a BNB Chain hot wallet → KuCoin → bridged to bitcoin (ZachXBT, Telegram).
  • Networks disrupted: 11, including BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma (CoinDesk, from the status page); The Block cited BSC, Polygon and Optimism.
  • Recovery timing: core services expected back within ~1 hour; deposits/withdrawals down ~12 hours (The Block).
  • NEAR token: down ~6% (CoinDesk) to ~7.35% (The Block) over 24 hours; last ~$4.94 (CoinDesk).
  • Commitment: full reimbursement pledged; law enforcement notified; post-mortem promised (NEAR Intents).

The real-world read

A few things deserve a flag.

First, the compensation pledge is a statement of intent, not an accomplished fact. "Will reimburse in full" has been the standard line after exploits all year, and it only means something once wallets are actually topped up. Judge it when the post-mortem and the refunds land — not on the press-day promise.

Second, the "fully patched, back within an hour" framing is the project's own, and it papers over a gap. The contract-side bug may be fixed, but deposits and withdrawals across 11 networks were still down for roughly half a day — a reminder that the "intents" model concentrates risk in off-chain and bridging infrastructure (here, hot wallets and the Omni layer) even when the headline blockchain is untouched. The attacker's choice of a BNB Chain hot wallet, not the NEAR chain, is the tell.

Third, mind the volume numbers, because they come from an interested party. CoinDesk cites the platform's website claiming more than $30 billion processed across 35 blockchains; The Block notes NEAR said about a month and a half ago that it had crossed $25 billion in lifetime volume. Those are the project's own marketing figures, they are not reconciled with each other, and a loss this size against tens of billions in throughput is precisely the kind of "small in context" framing an operator would want foregrounded. Treat the $30B/35-chain line as a marketing claim, not independently verified data.

Fourth, the speed of the cash-out is its own story. Funds reached a centralized exchange (KuCoin) and were converted to bitcoin before most users knew anything was wrong — which both compresses the window for any freeze and raises the obvious question of what KuCoin's controls caught, if anything. KuCoin had not responded to The Block by publication.

Finally, context cuts against complacency. CoinDesk places this inside a brutal year: Bitget lost over $350 million last week, with Liquid Network (~$320 million), Drift ($295 million) and Kelp ($293 million) among the year's larger incidents per DefiLlama, and the outlet's own tally putting total 2026 hack losses at $1.26 billion. At $3.8 million, this is a small entry on that list — but it is one more cross-chain system compromised at the infrastructure layer.

Opinion, and whose

  • NEAR Intents (interested party): the vulnerability is patched, users will be made whole in full, and core services resume quickly — all per the team's own posts. Unverified until refunds and the post-mortem arrive.
  • ZachXBT (investigator): attributes the theft to irregular BNB Chain hot-wallet outflows routed through KuCoin and into bitcoin. An independent read of the on-chain trail, not the project's.
  • CoinDesk (framing): positions the hack within "crypto's rough year," implying systemic rather than one-off risk. A reasonable editorial read, not a claim about NEAR Intents specifically.

Sources

  • The Block (Tier 2, secondary), "NEAR Intents halts services after $3.8 million exploit, promises full compensation," 2026-10-01 — loss figure, Omni/contract cause, ~1-hour vs. ~12-hour recovery split, 11-network scope (BSC, Polygon, Optimism named), ZachXBT's KuCoin/bitcoin trail, $25B lifetime-volume reference, NEAR down ~7.35%. Relays NEAR Intents' own X post — an interested-party disclosure.
  • CoinDesk (Tier 2, secondary), "NEAR Intents hit by $3.8 million exploit as crypto's rough year of hacks continues," 2026-10-01 — corroborates loss and cause, full status-page network list, solver mechanics, NEAR ~$4.94 (down ~6%), BTC ~$84,072, and year-to-date hack context (Bitget, Liquid, Drift, Kelp; $1.26B total via DefiLlama). Cites the platform's website for the $30B/35-chain claim — a marketing figure.
  • Primary statements referenced within: NEAR Intents (X post) and ZachXBT (Telegram) — the first an interested party, the second an independent investigator.

This is news reporting, not financial advice; it does not recommend buying, selling or holding any asset.