NEAR Intents announced on October 1, 2026, that attackers exploited a vulnerability linking its Omni infrastructure to platform smart contracts, draining more than $3.8 million from a BSC hot wallet. The team patched the flaw and pledged full reimbursement to affected users, while suspending deposits and withdrawals across EVM-based chains, including BSC, Polygon, and TON, for approximately 12 hours to monitor for irregular activity.

The stolen funds were rapidly routed to KuCoin and bridged into Bitcoin, complicating recovery efforts. NEAR Intents confirmed that core services would resume within an hour of the announcement, though broader chain operations remained frozen longer. Independent analyst ZachXBT initially flagged the irregular outflows before the official disclosure. The protocol stated that all lost funds will be compensated regardless of whether the assets are recovered by law enforcement or security partners currently assisting in the investigation.