NEAR Intents confirms $3.8 million exploit tied to Omni custody integration bug

Editorial illustration: A transparent teal mechanism connects to an open metal vault containing gold bars through a broken glass tube. Glowing gold fragments spill from the break onto a dark stone platform.

In brief

  • NEAR Intents confirmed a $3.8 million infrastructure hack on October 1, 2026, per U.Today.
  • NEAR Intents team blamed a bug between its smart contract and Omni's custody architecture.
  • BNB Chain hot wallet targeted; funds routed via KuCoin to Bitcoin, per team account reported by U.Today.
  • NEAR price fell 7.5% to a $4.76 low before recovering to $4.84, U.Today reported.

How the exploit worked

The team's account (as relayed by U.Today) points to an integration problem, not one broken contract on its own. According to NEAR Intents, the bug sat where its smart contract met Omni's custody architecture. The attackers used that vulnerability to make unauthorized withdrawals from the platform's hot wallet on BNB Chain (BSC).

The funds didn't sit still for long. Per the team's account, the stolen assets went to KuCoin and were then converted into Bitcoin through cross-chain bridges. NEAR Intents hasn't publicly named anyone behind the attack, and U.Today doesn't link to or quote the official report itself, so the details above are the team's version as U.Today relayed it.

NEAR price reaction

The NEAR token fell 7.5% within minutes following the disclosure and hit a local low of $4.76, U.Today reported. It then partly recovered to $4.84.

Those prices come from U.Today's reporting, not a named market-data feed. It's also worth being careful about cause and effect here: the drop came after the report went out, and that's as far as the sourcing goes.

A security record with two sides

The timing is awkward.

A few days before the exploit, NEAR Intents' SHIELD security system blocked $50 million in transactions linked to an attempt to launder funds from the Bitget exchange hack. So the same stack that stopped a laundering attempt went on to lose $3.8 million through a custody integration bug a few days later.

The design explains why integrations like this matter. NEAR Intents is built on Chain Abstraction: a user (or an AI agent) states an intention, and the underlying infrastructure finds bridges, calculates gas fees and selects networks. The protocol presents itself as a key financial layer for the AI agent economy. That convenience depends on contracts talking cleanly to custody systems, and one of those connections is where this bug lived, according to the team.

For a protocol with more than $30 billion in trading volume behind it, the full official report is the missing piece. U.Today doesn't link to it, so for now the team's account is all there is.

Frequently asked questions

What caused the NEAR Intents exploit?

According to the NEAR Intents team, as relayed by U.Today, a bug in the interaction between the NEAR Intents smart contract and Omni's custody architecture caused the incident. Attackers used it to make unauthorized withdrawals from the platform's hot wallet on BNB Chain (BSC).

Where did the stolen funds from NEAR Intents go?

Per the team's account reported by U.Today, the attackers moved the stolen assets to KuCoin. They then converted them into Bitcoin through cross-chain bridges. No culprit has been publicly named.

How does NEAR Intents work?

NEAR Intents uses a Chain Abstraction model. A user or AI agent states an intention, and the underlying infrastructure finds bridges, calculates gas fees and selects networks. The protocol presents itself as a key financial layer for the AI agent economy.