NEAR Intents, a cross-chain swap service built on the NEAR Protocol, lost approximately $3.8 million in an exploit on Thursday. The security breach knocked the underlying NEAR token down 8.6% within hours, though the main blockchain network was not targeted. The attack struck just two days after Bitwise launched the first U.S. spot NEAR ETF, a fund that actively promoted NEAR Intents and its reported volume of over $32 billion in processed swaps.
How the Smart Contract Exploit Unfolded
NEAR Intents lets users trade a token on one blockchain for a different asset on another network by matching orders through external market makers. According to the development team, a bug in the smart contract caused the loss. The vulnerability occurred specifically where the omni-deposit and withdrawal system interacted with the NEAR Intents smart contract, the self-executing code that records transactions.
On-chain investigator ZachXBT first flagged the exploit after tracking several unusual withdrawals from the service’s hot wallet on the BNB Chain. Those stolen funds moved directly to the KuCoin cryptocurrency exchange, where they were converted into Bitcoin (BTC). The NEAR Intents team stated that they patched the smart contract bug, reported the incident to law enforcement, and committed to fully reimbursing affected users.
Platform pauses deposits across eleven networks
To secure user funds following the attack, the platform paused deposits and withdrawals for roughly twelve hours across eleven different networks. The affected chains include BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. Neither the official project announcements nor ZachXBT’s alerts found any losses on the NEAR blockchain itself, confirming that the exploit remained isolated to the cross-chain swap service, the bridge, and its BNB Chain hot wallet.
At the time of the incident, the NEAR token traded at $4.92 with a market capitalization of about $6.4 billion. The token had rallied roughly 175% since early September ahead of the Bitwise NEAR ETF launch. This security breach marks the second major exploit for the NEAR ecosystem this year, following an April incident where Rhea Finance lost $7.6 million. The NEAR Intents team announced that it will publish a full technical report in the coming days.
Frequently Asked Questions About the Security Breach
Are user funds safe on the paused networks?
Users holding assets from the eleven paused blockchains can trade them again once the team restores main service functions, and the project has promised full reimbursement for all impacted accounts.
Where did the stolen funds go after the attack?
According to on-chain investigator ZachXBT, the attacker transferred the stolen money directly to the KuCoin cryptocurrency exchange and converted it into Bitcoin (BTC).
When will normal operations resume across the blockchains?
Deposits and withdrawals were paused for approximately twelve hours across networks like BNB Chain, Polygon, and Avalanche while developers patched the vulnerable smart contract.
Worth a look