NEAR Intents reported a security breach resulting in $3.8 million in user fund losses caused by a bug in the Omni deposit and withdrawal infrastructure interaction with its smart contract. The protocol confirmed that the contract-side vulnerability has been patched to prevent recurrence and stated that affected users will be compensated in full. Additionally, the incident was reported to law enforcement, with the team working alongside blockchain analytics partners to trace the stolen funds.
Blockchain investigator ZachXBT identified that the diverted assets were transferred to KuCoin and subsequently bridged to Bitcoin, though the attacker's identity remains unknown. This exploit occurred shortly after NEAR Intents assisted Bitget following a separate $388 million security breach, during which NEAR Intents helped block $50 million and freeze over $500,000 in related funds. The cumulative impact of these incidents contributed to Q3 crypto security losses exceeding $1 billion.
The rapid deployment of a fix and the commitment to full reimbursement highlight a critical shift in how cross-chain protocols manage operational risk and maintain user trust. By immediately addressing the vulnerability and engaging law enforcement, NEAR Intents demonstrates an institutional-grade response framework that prioritizes asset recovery and transparency. This approach is essential for sustaining confidence in decentralized finance infrastructure, where smart contract bugs can lead to irreversible financial damage if not handled with precision and speed.
From a market structure perspective, this incident underscores the persistent fragility of interoperability layers like Omni, even as they facilitate major exchange support roles. The fact that funds were quickly moved through centralized exchanges and bridged to Bitcoin suggests that while on-chain tracing is effective, off-chain coordination remains a bottleneck for recovery. Stakeholders should watch for the promised detailed report to assess whether the root cause analysis reveals deeper systemic issues in cross-chain communication standards or isolated implementation errors.


