home › blog › near-intents-exploit-3-8m
NEAR Intents exploit: $3.8M drained a week after it blocked $50M of Bitget funds
Key takeaways
- On October 1, 2026, NEAR Intents — a cross-chain swap protocol — halted services after an exploit. The team’s preliminary figure is about $3.8 million lost.
- The team says the cause was a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract. The contract flaw is patched; a full technical report is promised.
- Investigator ZachXBT reported irregular outflows from its BNB Chain hot wallet; the funds were sent to KuCoin and bridged to Bitcoin.
- NEAR Intents promises full compensation. Deposits and withdrawals on 11 chains stayed paused for about 12 more hours after the core service returned.
- A week earlier, the same protocol’s screening layer blocked more than $50 million of funds stolen from Bitget. The two facts do not contradict each other: screening controls who comes in; it does not secure your own code and wallets.
What happened
NEAR Intents lets you swap a token on one blockchain for a token on another. Users state what they want — an intent — and solvers fill it, with assets moving in and out through the Omni deposit and withdrawal infrastructure and its hot wallets.
| time (UTC, Oct 1, 2026) | event |
|---|---|
| morning | NEAR Intents’ status page opens incidents for its HOT bridge and for deposits and withdrawals on BNB Smart Chain, Avalanche, Optimism, Polygon, TON, Stellar, Scroll, Plasma, ADI, X Layer and, later, Monad — about 5–7 hours before 13:00 UTC. |
| ~13:00 | ZachXBT reports irregular outflows from NEAR Intents’ BSC hot wallet 0x233c…, which then stops processing transactions. Funds go to KuCoin and are bridged to Bitcoin. BSC theft address: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37. |
| afternoon | NEAR Intents confirms the incident: a bug in the Omni infrastructure’s interaction with its contract, about $3.8M lost, the contract flaw patched, core services back within about an hour, 11 chains paused for about 12 more hours, full compensation, law enforcement notified. |
We read the status page ourselves on October 1. Ethereum, Solana and NEAR were not among the chains with open incidents at that point.
What is known — and what is not
Known: the loss is a preliminary figure of about $3.8 million; the cause is described as a bug between the Omni deposit/withdrawal infrastructure and the NEAR Intents contract; the BSC hot wallet was drained; the funds moved to KuCoin and on to Bitcoin; the team will compensate users.
Not yet known: the exact mechanism, whether other hot wallets lost funds, who the attacker is, and whether KuCoin has frozen anything. NEAR Intents has promised a full technical report — we will update this article when it is out.
The irony that is not a contradiction
A week before its own exploit, NEAR Intents was the protocol that said no to the Bitget hackers: its screening layer, SHIELD, rejected more than $50 million in attempted transfers. Some commentators now point at the gap.
It is worth being precise. Screening decides whose money a protocol accepts. Security is whether the protocol’s own contracts, bridges and hot wallets can be tricked. A protocol can be strict at the door and still have a bug in the wiring — as NEAR Intents now says it had.
Three incidents, three kinds of failure
| Chainflip (Sept 12) | Bitget (Sept 24) | NEAR Intents (Oct 1) | |
|---|---|---|---|
| What it is | Cross-chain swap protocol | Centralized exchange with KYC | Cross-chain intents protocol |
| Loss | 736,442 USDT | about $387.5M | about $3.8M (preliminary) |
| Weak point | How it read TRON memos after signing | Internal approval system, reached via a zero-day in third-party software | Interaction between its Omni deposit/withdrawal infrastructure and its contract |
| Keys stolen? | No | No | Not reported |
| Who carries the loss | TRON USDT liquidity providers (repayment pending) | Bitget’s protection fund | NEAR Intents promises full compensation |
In all three, the keys were not the problem. The failures were in the code that decides when and how funds move. Our earlier analyses: Chainflip’s TRON memo exploit and the Bitget hack.
What it means if you swap without KYC
- Check the status page before you deposit. NEAR Intents publishes one per chain; so do many protocols. An open incident on your chain means wait.
- Assets “inside” a protocol are not in your wallet. If you hold balances in NEAR Intents — directly, through HOT Wallet or near.com — they depend on the protocol’s hot wallets and bridges.
- Prefer routes that settle to your own wallet quickly, and set a refund address where the interface allows it.
- Screening and security are separate questions. Our catalog labels screening for every service; incidents like this one are recorded separately, with sources, on each service’s page.
Frequently asked questions
How much was stolen from NEAR Intents? About $3.8 million, according to the team’s preliminary report on October 1, 2026. The figure may change when the full technical report is published.
What caused the NEAR Intents exploit? The team says it was a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract. Investigator ZachXBT reported irregular outflows from its BNB Chain hot wallet. Technical details have not been published yet.
Will NEAR Intents users be compensated? NEAR Intents says affected funds will be compensated in full. Users holding assets from the paused chains inside NEAR Intents, including through HOT Wallet or near.com, should be able to swap them once the service is back.
Is it safe to use NEAR Intents now? The team says the contract flaw is patched. Deposits and withdrawals on 11 chains stayed paused for about 12 more hours after the core service returned. Check its status page before you deposit, and wait for the technical report if you move large amounts.
Isn’t NEAR Intents the protocol that blocked Bitget’s stolen funds? Yes. A week earlier its screening layer, SHIELD, rejected more than $50 million in transfers linked to the Bitget hack. Screening decides who may use a protocol; it does not protect the protocol’s own code and wallets.
Sources
- NEAR Intents statement on X, October 1, 2026 — as reported by The Block, Crypto Briefing, ChainCatcher, BeInCrypto
- ZachXBT, Investigations channel, post 365
- NEAR Intents status page, read by us on October 1, 2026
- Our records: the incident on NEAR Intents’ page in our catalog, and the losses ledger
This article is a first account, written on the day of the incident. It will be updated when NEAR Intents publishes its technical report.