NEAR Intents Exploit Climbs to $3.8M, Pausing NEAR Cross-Chain Swaps
NEAR Intents estimated a $3.8 million loss from an Omni infrastructure bug, pausing deposits and withdrawals on 11 networks as investigators trace the funds.
AI SummaryAI
- NEAR Intents estimated a $3.8 million loss from an Omni infrastructure bug on October 1, 2026.
- On-chain data shows about 3.87 million USDT left the HOT Bridge treasury on BNB Chain within six hours.
- Investigator ZachXBT reported stolen funds reached KuCoin and were bridged into Bitcoin.
- Deposits and withdrawals stayed paused on 11 networks, including Polygon and TON, for about 12 hours.
A Drain Still Being Counted
On-chain data puts the running drain from Thursday's
NEAR Protocol (NEAR) Intents security incident at roughly 3.87 million USDT, a tally the team itself has estimated at about $3.8 million and one that may still move as fund tracing continues. The cross-chain swap service halted all operations after detecting irregular outflows, and the NEAR price fell in response. In an official statement, the team attributed the breach to a bug in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract, the self-executing code that records every swap. The service, which lets users state a swap while independent market makers compete to fill it, pledged that affected funds will be compensated in full.
Blockchain records show the receiving address collected funds from the HOT Bridge treasury contract, which the protocol's own documentation lists as its BNB Chain treasury. Two test-sized transfers of 10 USDT and 11 USDT appeared on Wednesday afternoon. Five larger withdrawals, ranging from 35,000 USDT to 1.5 million USDT, followed between 7:54 p.m. ET on Wednesday and 2:08 a.m. on Thursday. In all seven, the receiving address triggered the payout itself; in ordinary withdrawals from the same contract, a different address processes the payment. The treasury reportedly kept serving other users through the incident, paying out roughly 215,000 USDT shortly after 9:27 a.m. ET.
Funds Routed Toward KuCoin
Nearly all of the USDT left the receiving address within minutes of each transfer. On-chain flows show about 1.5 million USDT reached the settlement contract of CoW Protocol, a DeFi trading venue, while the remainder landed at four addresses not yet publicly identified. The on-chain investigator ZachXBT, who first flagged irregular outflows from a BNB Chain hot wallet, reported that the stolen funds reached the crypto exchange KuCoin and were bridged into Bitcoin (BTC). The team said it has notified law enforcement and engaged security and blockchain analytics firms to follow the money. Neither the team nor the investigator has confirmed how much, if anything, has been recovered.
11 Networks Still Paused
Remediation moved in two stages. The team said the contract-side flaw was fixed and that core operations, including near.com, would resume within roughly an hour of the morning announcement, posted around 8:53 a.m. ET. Deposits and withdrawals on 11 networks are set to stay offline for about 12 more hours while the Omni infrastructure itself is repaired: BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. Users holding assets from those chains inside the platform, including balances in HOT Wallet, can still convert them to other tokens once core service resumes, according to the official statement. A fuller incident report is promised in the coming days.
The exploit landed two days after Bitwise listed the first US spot NEAR ETF, a product pitched partly on the swap service, which the asset manager credited with more than $32 billion in cumulative volume across 35 blockchains. The token fell about 6% over the 24 hours through Thursday trading, after sliding as much as 8.6% earlier in the session, though the underlying layer-1 blockchain behind NEAR Protocol was not named as a target. That retreat follows a September in which the asset climbed roughly 175% ahead of the ETF debut, a 100%-plus September rally that left it holding near $5.00. Our live monitoring shows the token down about 5.9% over the past day.
Second Exploit This Year
The incident is not the protocol's first brush with stolen funds in recent days. General manager Alex Shevchenko said earlier this week that, days after
NEAR Protocol (NEAR) Intents blocked $50M in Bitget hack transfers, attackers still tried to push more than $50 million through the protocol, with roughly $166,000 slipping through and about $503,000 frozen. Bitget itself lost over $350 million last week, and DefiLlama's hack tracker lists Liquid Network at about $320 million, Drift at $295 million and Kelp at $293 million for the year. For the NEAR ecosystem specifically, it is the second major exploit of 2026 after Rhea Finance lost $7.6 million in April.
What Has Not Been Counted
Taken together, the day's events sketch one theme: cross-chain settlement desks concentrate custody risk across many chains at once, and a single contract-interaction bug can drain them within hours. The primary evidence here is consistent. The team's own statement identifies the Omni deposit and withdrawal interaction with the smart contract as the entry point and confirms the contract-side patch, while the on-chain trail of 3.87 million USDT out of the HOT Bridge treasury, through CoW Protocol and toward KuCoin, gives investigators a fixed starting point. The preliminary $3.8 million estimate now sits beside a slightly higher on-chain tally, still provisional. Not yet counted: any recovered funds, and the full technical report promised in the days ahead.
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

