NEAR Intents said on Oct. 1, 2026 that a bug in its Omni deposit and withdrawal system drained about $3.8 million, pledged full reimbursement, and paused deposits and withdrawals on several blockchains.

Contestants work at laptops in the contest area at DEF CON 24, a hacker conference. Photo: ArnoldReinhold via Wikimedia Commons (CC BY-SA 3.0). Source
Cross-chain trading protocol NEAR Intents said on Oct. 1, 2026 that an exploit drained about $3.8 million in user funds through a bug in its deposit and withdrawal system. Cointelegraph reported the breach on Oct. 1, writing that the platform blamed a flaw in how its Omni deposit and withdrawal infrastructure interacts with the NEAR Intents smart contract.
The protocol told users it would cover the losses in full. In a Thursday post on X, NEAR Intents called the cause a "bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract" and said the contract-side vulnerability had been patched to block repeat attacks. Affected users will be reimbursed for the full amount taken, the team said, putting the pledge at roughly $3.8 million.
NEAR Intents is built to simplify trading across blockchains. Instead of asking users to pick a bridge, exchange or route themselves, they state the swap they want and independent market makers known as solvers compete to fill it behind the scenes. Its site says the system has handled more than $30 billion in volume across 35 blockchains, according to CoinDesk's account of the incident.
The team paused core services and switched off deposits and withdrawals on several networks while it responded. Its status page showed problems on BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. CoinDesk wrote that core services were expected back quickly, with deposits and withdrawals on some networks staying dark for longer while fixes shipped.
Law enforcement has been notified. "The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery," the protocol said in its post. A detailed public report is set to follow in the coming days.
The pause hit eleven networks at once. This leaves the deposit and withdrawal path as the common point across the paused networks, with core trading expected back quickly while fund movements stay shut until each fix clears, according to the status page.
Blockchain investigator ZachXBT traced the opening move to irregular withdrawals from a BNB Chain hot wallet tied to NEAR Intents. In a Telegram post describing the flow, he said the stolen funds moved to the KuCoin exchange and were bridged into bitcoin. Cointelegraph noted that account of the money trail, adding that it remained unclear who carried out the attack at the time of publication.
The NEAR token, the native asset of the blockchain closely associated with NEAR Intents, slid after the disclosure. It traded down about 6 percent over the prior 24 hours at the time of reporting, though the flaw sat in the cross-chain infrastructure rather than in the underlying NEAR Protocol blockchain itself.
The timing stung. Days earlier, NEAR Intents had helped contain damage from an attack on crypto exchange Bitget last week, a theft Cointelegraph described as a $388 million breach. The protocol said it blocked $50 million in attempted transfers tied to the Bitget hackers and froze more than $500,000 during execution. Bitget chief executive Gracy Chen has pointed to North Korean hackers as possible culprits, citing IP clues, she said last week.
The incident extends a costly year for crypto security. CoinDesk counted roughly $320 million taken from Liquid Network, $295 million from Drift and $293 million from Kelp DAO among 2026 thefts. Those figures come from DefiLlama's exploit tracker, as reported. Each of those sums dwarfs the $3.8 million lost at NEAR Intents.
For now, traders face limited service while the protocol finishes repairs. Deposits and withdrawals on the affected networks stay shut until each fix clears, with the promised detailed report still to come. No date for full restoration was given.