NEAR Intents lost $3.8 million of customer funds to a bug in its Omni deposit and withdrawal infrastructure. The protocol paused cross-chain swaps and promised to cover every loss in full. This matters to the market for two reasons: it is the second big story around the project in a week, and liquidity at services like this runs on trust.
What exactly broke
On Thursday NEAR Intents reported the incident from its own X account. As the team describes it, this is a software error where two parts of the system meet. It involves the Omni infrastructure that takes deposits and processes withdrawals, and the protocol's own smart contract.
"A bug in the Omni deposit and withdrawal infrastructure interaction with the NEAR Intents smart contract."
- NEAR Intents, from a post on X dated October 1, 2026
The contract-side vulnerability is already patched. Affected users are promised full compensation. Law enforcement has been notified, and the team plans to publish a detailed report in the coming days. According to The Block, the protocol's services stay halted while the investigation runs.
Bugs like this are sneaky because each component can pass its checks on its own and still behave correctly. The trouble starts where they connect. The team names the interaction between two layers as the cause, not a weak key or an operator mistake. For users that difference is real, since a code fix closes one specific hole instead of changing people or processes.
Reaction time matters too. The protocol halted services fast, and that capped the sum. A $3.8 million loss looks modest next to the volume that flows through Intents, but for a halted service every hour of downtime has a price.
Where the money went
Blockchain investigator ZachXBT traced the funds. By his data, the stolen assets landed at the KuCoin exchange and were bridged to the Bitcoin network. Who is behind the attack is unknown.
A route through an exchange gives investigators a point where they can ask for a freeze. A bridge into Bitcoin makes that work harder, because the money quickly leaves the network where people are looking for it. Whether anything comes back will show in the team's report.
For the investigation it matters that part of the funds is already at an exchange. If the platform can stop withdrawals, the chance of a partial recovery goes up. If not, the money scatters across addresses and gets much harder to follow. The decision here belongs not to users or NEAR but to the exchange team and law enforcement.
The timing overlap with Bitget
The attack came days after NEAR Intents helped the Bitget exchange during its roughly $388 million breach. The protocol blocked $50 million in swaps then and froze more than $500,000 tied to the attack. According to Bitget CEO Gracy Chen, North Korean hackers may be involved in that breach.
Decrypt reports that after NEAR turned them away, the Bitget attacker began hiding about $3.8 million in ZEC inside a Zcash private pool. The amounts in the two stories look alike, but no source confirms the two attacks are connected. Timing alone is not proof.
NEAR Intents played a defensive role in that episode, refusing swaps that could have helped launder the stolen assets. Decrypt put the two events side by side in its headline, but that is an editorial angle, not proof of cause. If the team's report shows a link, the risk picture for the whole sector shifts. If it does not, this is just bad timing.
What it means for the NEAR token and liquidity
The market reacted at once. At the time of publication NEAR was down about 8% on the day, at $4.92. For a token that gained 78% in a week not long ago, with Intents volume closing in on $30 billion, that is a painful but not critical pullback.
The Intents model is simple. A user says what they want to swap, and market makers compete on the best price. That works well as long as deposits and withdrawals are sound. That layer is exactly what failed.
For people who use the service, the main risk is not the size of the loss but the pause. While swaps are halted, liquidity that flowed through this route looks for other bridges. For rivals that is a chance, for NEAR it is a test of how fast the service returns. The longer the pause, the more it costs to win trust back.
The promise of full compensation means the loss lands on the team's balance sheet or the ecosystem treasury. Where exactly the money will come from has not been spelled out yet. The report has to answer that, because it decides whether reserves will cover the next incident of this kind. The market likes compensation tied to a concrete figure and date, not a general pledge.
There is a wider consequence for cross-chain swaps. Investors and large traders look not only at fees and speed but also at incident history. One hack does not kill a service, but repeated lapses quickly send volume to rivals.
What to do next
Until the service is back, a few things are worth keeping in mind.
- Do not rush funds back into Intents until the report on the cause is out and the fix has been independently checked.
- Follow the team's official announcements, not chat comments, where phishing links usually show up.
- For large sums, consider several swap routes instead of a single protocol.
This is shaping up as a heavy year for crypto security. According to Cointelegraph, losses from attacks in the third quarter passed $1 billion, and September was the worst month of the year at $768 million. The NEAR Intents incident is small in size, but it again shows where bugs hide: where several components meet.




Comments
Your email address will not be published. Required fields are marked *