The cross-chain trading landscape faced another significant setback this week as NEAR Intents, a prominent protocol designed to streamline decentralized finance (DeFi) interactions, disclosed a security exploit that resulted in the loss of approximately $3.8 million in user assets. The incident, which occurred on Thursday, October 1, 2026, has forced the development team to suspend key services and halt deposits and withdrawals across a wide array of blockchain networks, casting a shadow over the project’s ambitious goal of simplifying complex, multi-chain transactions.
According to official communications from the project, the breach was not the result of a flaw in the underlying NEAR Protocol blockchain itself, but rather a specific technical vulnerability within the project’s proprietary infrastructure. The exploit reportedly stemmed from a critical bug in the way the platform’s "Omni" deposit and withdrawal system interacted with the NEAR Intents smart contract. This discrepancy in the communication between the front-end interface and the smart contract logic allowed unauthorized parties to drain funds from the system.
A Rapid Response and Promise of Restitution
In the immediate aftermath of the discovery, the NEAR Intents team took decisive action to mitigate further losses. By temporarily disabling the deposit and withdrawal functions, they effectively cordoned off the affected components of the protocol. The development team confirmed that they have successfully identified and patched the contract-side vulnerability that facilitated the theft.
Crucially, in an effort to maintain user trust and uphold the integrity of the platform, the project organizers have publicly committed to a full reimbursement of all affected funds. This move is a common, though financially taxing, practice among major DeFi protocols seeking to recover from security incidents without losing their user base. The team stated that they are working closely with law enforcement and specialized blockchain security firms to trace the movement of the stolen assets and hold those responsible accountable.
NEAR Intents serves a specialized niche in the crypto ecosystem by offering "intent-based" trading. Instead of requiring users to navigate the complexities of individual bridges, liquidity pools, or manual routing—all of which are prone to user error and high slippage—the protocol allows users to simply specify the desired swap. Once the user submits their "intent," a network of independent market makers, known as "solvers," competes to execute the transaction at the most efficient rate behind the scenes. With a stated track record of processing more than $30 billion in cumulative volume across 35 different blockchains, the protocol has established itself as a significant player in the infrastructure layer of decentralized finance.
Market Reaction and Broader Context
While the exploit was confined to the NEAR Intents cross-chain infrastructure, the news had a discernible impact on the broader ecosystem, particularly regarding the NEAR token. At the time of the announcement, the token saw a decline of approximately 6% over a 24-hour period. Market analysts noted that while the underlying NEAR Protocol blockchain remained secure and unaffected by the bug, the association between the two entities led to a degree of market anxiety. Investors and users remain hyper-sensitive to security news, particularly given the scale and frequency of similar incidents throughout 2026.
The breach at NEAR Intents is unfortunately part of a wider, concerning trend of security failures that have plagued the cryptocurrency industry throughout the current year. The sheer volume of capital lost to hacks in 2026 has been staggering, with data from platforms like DefiLlama highlighting a persistent vulnerability in the cross-chain and bridge sectors.

Just last week, the crypto exchange Bitget fell victim to an exploit that saw over $350 million in assets compromised. That event followed a series of high-profile security failures that have collectively cost investors billions. Notable incidents earlier this year included the Liquid Network exploit, which resulted in $320 million in losses; the breach of Drift, which saw $295 million stolen in what was later identified as a complex, months-long intelligence operation; and the Kelp DAO incident, where $293 million was stranded across 20 different blockchains due to a similar cross-chain vulnerability. These events have sparked an urgent industry-wide conversation regarding the need for more rigorous smart contract audits, decentralized insurance mechanisms, and more robust security protocols for cross-chain communications.
Tracking the Stolen Assets
The trail of the stolen funds has been the subject of intense scrutiny from on-chain analysts. The well-known blockchain investigator ZachXBT, who frequently tracks large-scale crypto thefts, provided initial insights into the methodology of the attackers. According to his analysis, the exploit began with a series of irregular, unauthorized withdrawals originating from a BNB Chain hot wallet that was directly linked to the NEAR Intents operational structure.
Once the funds were extracted, the trail led to the cryptocurrency exchange KuCoin, a common destination for hackers seeking to obfuscate the origin of illicit assets. Further analysis suggested that the stolen capital was subsequently bridged into Bitcoin, a move often used by bad actors to store value in a more liquid and widely accepted asset class while attempting to exit the DeFi ecosystem. These findings have been shared with relevant authorities as part of the ongoing investigation.
Status of Services and Future Outlook
While the core vulnerability has been patched, the path to a full restoration of services remains complex. The NEAR Intents status page, which is being updated in real-time for affected users, indicated that while some core services were slated to resume, the suspension of deposits and withdrawals would remain in effect for several networks for an extended period. The list of affected networks is extensive, reflecting the reach of the protocol, and includes the BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma.
For users, the priority remains the restoration of their deposits and the clarity of the reimbursement process. The platform has urged users to refrain from attempting to interact with the compromised contract functions until official updates are issued.
As the industry reflects on another multi-million dollar exploit, the case of NEAR Intents serves as a reminder of the inherent risks associated with early-stage, complex cross-chain infrastructure. While intent-based architectures represent a significant leap forward in user experience and efficiency, they also introduce new attack surfaces that require a higher standard of security and transparency. The success of the project’s recovery efforts and its ability to fully compensate users will likely serve as a litmus test for its long-term viability in an increasingly competitive and security-conscious market. For now, the team is focused on the dual tasks of system stabilization and the legal pursuit of the attackers, as the community watches to see if the promised reimbursements proceed without further delay.

