>_ nokycswap.me ENRU (brief)
btc→xmr 15.41 fixedfloatxmr→btc 0.0641 fixedfloateth→xmr 4.91 fixedfloatbtc→usdt 8 360 exolixltc→xmr 1.23 fixedfloat best offer per pair · our rates worker · tick 60s

home › blog › near-intents-exploit-3-8m

NEAR Intents exploit: $3.8M drained a week after it blocked $50M of Bitget funds

by Milan Voss · published

Key takeaways

What happened

NEAR Intents lets you swap a token on one blockchain for a token on another. Users state what they want — an intent — and solvers fill it, with assets moving in and out through the Omni deposit and withdrawal infrastructure and its hot wallets.

time (UTC, Oct 1, 2026)event
morningNEAR Intents’ status page opens incidents for its HOT bridge and for deposits and withdrawals on BNB Smart Chain, Avalanche, Optimism, Polygon, TON, Stellar, Scroll, Plasma, ADI, X Layer and, later, Monad — about 5–7 hours before 13:00 UTC.
~13:00ZachXBT reports irregular outflows from NEAR Intents’ BSC hot wallet 0x233c…, which then stops processing transactions. Funds go to KuCoin and are bridged to Bitcoin. BSC theft address: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37.
afternoonNEAR Intents confirms the incident: a bug in the Omni infrastructure’s interaction with its contract, about $3.8M lost, the contract flaw patched, core services back within about an hour, 11 chains paused for about 12 more hours, full compensation, law enforcement notified.

We read the status page ourselves on October 1. Ethereum, Solana and NEAR were not among the chains with open incidents at that point.

What is known — and what is not

Known: the loss is a preliminary figure of about $3.8 million; the cause is described as a bug between the Omni deposit/withdrawal infrastructure and the NEAR Intents contract; the BSC hot wallet was drained; the funds moved to KuCoin and on to Bitcoin; the team will compensate users.

Not yet known: the exact mechanism, whether other hot wallets lost funds, who the attacker is, and whether KuCoin has frozen anything. NEAR Intents has promised a full technical report — we will update this article when it is out.

The irony that is not a contradiction

A week before its own exploit, NEAR Intents was the protocol that said no to the Bitget hackers: its screening layer, SHIELD, rejected more than $50 million in attempted transfers. Some commentators now point at the gap.

It is worth being precise. Screening decides whose money a protocol accepts. Security is whether the protocol’s own contracts, bridges and hot wallets can be tricked. A protocol can be strict at the door and still have a bug in the wiring — as NEAR Intents now says it had.

Three incidents, three kinds of failure

Chainflip (Sept 12)Bitget (Sept 24)NEAR Intents (Oct 1)
What it isCross-chain swap protocolCentralized exchange with KYCCross-chain intents protocol
Loss736,442 USDTabout $387.5Mabout $3.8M (preliminary)
Weak pointHow it read TRON memos after signingInternal approval system, reached via a zero-day in third-party softwareInteraction between its Omni deposit/withdrawal infrastructure and its contract
Keys stolen?NoNoNot reported
Who carries the lossTRON USDT liquidity providers (repayment pending)Bitget’s protection fundNEAR Intents promises full compensation

In all three, the keys were not the problem. The failures were in the code that decides when and how funds move. Our earlier analyses: Chainflip’s TRON memo exploit and the Bitget hack.

What it means if you swap without KYC

Frequently asked questions

How much was stolen from NEAR Intents? About $3.8 million, according to the team’s preliminary report on October 1, 2026. The figure may change when the full technical report is published.

What caused the NEAR Intents exploit? The team says it was a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract. Investigator ZachXBT reported irregular outflows from its BNB Chain hot wallet. Technical details have not been published yet.

Will NEAR Intents users be compensated? NEAR Intents says affected funds will be compensated in full. Users holding assets from the paused chains inside NEAR Intents, including through HOT Wallet or near.com, should be able to swap them once the service is back.

Is it safe to use NEAR Intents now? The team says the contract flaw is patched. Deposits and withdrawals on 11 chains stayed paused for about 12 more hours after the core service returned. Check its status page before you deposit, and wait for the technical report if you move large amounts.

Isn’t NEAR Intents the protocol that blocked Bitget’s stolen funds? Yes. A week earlier its screening layer, SHIELD, rejected more than $50 million in transfers linked to the Bitget hack. Screening decides who may use a protocol; it does not protect the protocol’s own code and wallets.

Sources

This article is a first account, written on the day of the incident. It will be updated when NEAR Intents publishes its technical report.