NEAR Intents loses $3.8M in exploit, pledges full compensation to users
In brief
- NEAR Intents reported a $3.8 million loss of user funds in a security breach.
- The protocol blamed a bug in how Omni deposit and withdrawal infrastructure interacted with its smart contract.
- NEAR said the vulnerability is patched and affected users will be compensated in full.
- ZachXBT traced the funds to KuCoin and found they were bridged to Bitcoin.
What NEAR Intents says went wrong
The protocol traced the loss to a bug in the Omni deposit and withdrawal infrastructure and its interaction with the NEAR Intents smart contract. It's a specific failure point, and the team was direct about it.
NEAR said the contract-side vulnerability has been patched to prevent similar attacks. It also said users would be compensated in full for the lost funds, which is the part most affected users will care about first.
NEAR says the contract-side vulnerability is patched; tracing and recovering the funds is a separate effort.
“The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery,” said the platform.
The team added that a detailed report would be shared publicly in the following days. That's where we'd expect a fuller account of how the bug was found and exploited.
Where the funds went
According to an analysis by blockchain investigator ZachXBT, the funds were transferred to the KuCoin exchange and bridged to Bitcoin.
At the time Cointelegraph published, it was unclear who was behind the hack.
A week after helping Bitget
The exploit followed NEAR Intents assisting Bitget, which suffered a $388 million security breach the previous week. NEAR Intents reported blocking $50 million and freezing more than $500,000 in funds tied to that attack, as reported by Cointelegraph.
So a defi protocol that spent last week helping trace someone else's stolen crypto is now working with analytics partners to trace its own.
Bitget CEO Gracy Chen speculated that North Korean hackers may have been responsible for the Bitget breach. Her comment concerned Bitget's incident only. Cointelegraph's related coverage said Bitget's $388 million hack pushed Q3 crypto security losses past $1 billion, a figure that puts the scale of this quarter's breaches in context.
Frequently asked questions
What caused the NEAR Intents exploit?
NEAR Intents said in a Thursday X post that the incident came from a bug in the Omni deposit and withdrawal infrastructure's interaction with the NEAR Intents smart contract. NEAR said the contract-side vulnerability has since been patched to prevent similar attacks.
Will NEAR Intents users get their lost funds back?
NEAR said it would compensate affected users in full for the $3.8 million in lost funds. Separately, the platform said it reported the incident to law enforcement and is working with security and blockchain analytics partners to trace the funds and pursue recovery.
Where did the stolen NEAR Intents funds go?
According to an analysis by blockchain investigator ZachXBT, the funds were transferred to the KuCoin exchange and bridged to Bitcoin. At the time Cointelegraph published, it was unclear who was behind the hack.


