NEAR Intents announced on October 1, 2026, that attackers exploited a vulnerability linking its Omni infrastructure to platform smart contracts, draining more than $3.8 million from a BSC hot wallet. The team patched the flaw and pledged full reimbursement to affected users, while suspending deposits and withdrawals across EVM-based chains, including BSC, Polygon, and TON, for approximately 12 hours to monitor for irregular activity.
The stolen funds were rapidly routed to KuCoin and bridged into Bitcoin, complicating recovery efforts. NEAR Intents confirmed that core services would resume within an hour of the announcement, though broader chain operations remained frozen longer. Independent analyst ZachXBT initially flagged the irregular outflows before the official disclosure. The protocol stated that all lost funds will be compensated regardless of whether the assets are recovered by law enforcement or security partners currently assisting in the investigation.
This incident highlights the persistent operational risks associated with cross-chain infrastructure, specifically where connective layers like Omni interact with smart contracts. By attributing the breach to a technical breakdown rather than a systemic protocol compromise, NEAR Intents aims to preserve user confidence. However, the rapid movement of stolen assets through exchanges and bridges underscores the difficulty of tracing funds once they leave the original blockchain environment, a common challenge in DeFi security incidents.
The decision to absorb the financial loss entirely, shifting risk away from individual depositors, sets a high standard for institutional credibility in the crypto sector. While this approach may mitigate immediate reputational damage, it places significant pressure on the protocol’s reserves. Market observers will watch closely to see if the promised reimbursements are executed smoothly and whether the enhanced monitoring during the suspension period prevents further exploits, as these factors will determine long-term trust in the platform’s security posture.

