NEAR Intents suffered a hack estimated at $3.8 million on October 1, resulting from a bug between its smart contract and Omni infrastructure. The protocol suspended services, fixed the vulnerability, and CEO Alex Shevchenko claimed to have identified the attacker, granting them 48 hours to return funds via responsible disclosure.
The incident stems from a communication flaw in this cross-chain intent-based exchange model. Blockchain investigator ZachXBT reported that stolen assets were transferred to KuCoin and moved to Bitcoin, complicating tracking. NEAR Intents promised full user reimbursement but has not yet confirmed effective payouts. This event follows the Bitget hack, where NEAR Intents previously blocked $50 million in associated transfers using its SHIELD system.
This incident highlights the operational risks inherent in complex cross-chain architectures, specifically the fragility of interactions between smart contracts and external infrastructure like Omni. While the protocol’s rapid response and public attribution attempt demonstrate transparency, the reliance on voluntary restitution within a tight 48-hour window underscores the limitations of current recovery mechanisms in decentralized finance. The movement of funds through centralized exchanges and across multiple chains further illustrates the persistent challenges in asset tracing and enforcement.
From an institutional adoption perspective, the gap between promised reimbursement and confirmed execution poses a credibility risk. The previous success of NEAR Intents’ SHIELD system in blocking Bitget-related funds contrasts with this failure, suggesting that security measures may be reactive rather than preventive in novel attack vectors. Market participants should watch for the publication of the technical audit and the expiration of the ultimatum, as these will determine whether the protocol can maintain trust without judicial intervention or forced fund recovery.


