Skip to content
NEAR Intents Loses $3.8 Million in Exploit Days After Blocking Bitget Hacker

NEAR Intents Loses $3.8 Million in Exploit Days After Blocking Bitget Hacker

Finance.Biggo • October 1, 2026

Cross-chain swap service NEAR Intents halted operations Thursday after an attacker exploited a vulnerability to drain roughly $3.8 million in user funds, just two days after the protocol helped block a $50 million laundering attempt tied to the Bitget exchange breach.

The team said the exploit stemmed from a flaw in how its Omni deposit and withdrawal infrastructure interacted with the NEAR Intents smart contract. The contract-side vulnerability has already been patched, and the platform pledged to reimburse affected users in full.

"Earlier today NEAR Intents services were stopped after a security incident was detected," the team wrote in a post on X. "The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery."

Blockchain investigator ZachXBT traced the stolen funds to KuCoin, where they were subsequently bridged to Bitcoin. The identity of the attacker remains unknown at the time of publication.

The breach comes on the heels of NEAR Intents' involvement in the aftermath of the Bitget hack, which saw approximately $387.5 million drained from the exchange last week. The protocol reported blocking $50 million in swap attempts and freezing more than $500,000 tied to that attack.

Bitget CEO Gracy Chen and blockchain analytics firm Elliptic both pointed to North Korean state- hackers as the likely culprits behind the exchange breach, citing tell-tale on-chain patterns. That attribution has not been officially confirmed, and it remains unclear whether the two incidents are connected.

The timing of the exploit compounded pressure on NEAR's token, which fell 8.93% to $4.86 on Thursday. Shares of the Bitwise NEAR ETF, which launched just two days earlier, dropped more than 7% in the same session. Bitwise first filed paperwork for the fund in April 2025, when NEAR traded at $2.61, meaning the token has nearly doubled since that initial filing.

NEAR Intents has processed more than $30 billion in cumulative swap volume across 35 blockchains, according to the team. The service functions as an always-open exchange counter where rival market makers compete to fill user orders across different networks.

Cross-Chain Infrastructure Under Scrutiny

The incident highlights the persistent vulnerabilities in cross-chain infrastructure, which requires pooling assets in intermediary contracts that have repeatedly proven attractive to attackers. The 2022 Harmony bridge hack, which resulted in roughly $100 million in losses, remains one of the most prominent examples of this risk profile.

Unlike traditional bank deposits, crypto balances held in such protocols carry no deposit insurance, making the full-repayment pledge from NEAR Intents particularly significant for affected users. The team has not disclosed whose funds were taken or the breakdown of losses across the 11 supported networks.

Core services were expected to resume within approximately one hour of the announcement, while deposits and withdrawals on networks including BNB Chain, Polygon, and Optimism were slated to remain offline for roughly 12 additional hours while the Omni infrastructure fixes were completed.

A detailed incident report is expected to be published in the coming days, according to the team.

Broader Security Context

The Bitget breach pushed third-quarter crypto security losses past $1 billion, underscoring a year in which cross-chain protocols and centralized exchanges have remained prime targets for sophisticated attackers. The movement of stolen Bitget funds into Zcash's shielded Ironwood pool earlier this week further complicated tracing efforts, with the attacker converting roughly 2,700 ZEC—approximately $3.8 million—into the privacy-focused network.

ZachXBT noted that the Bitget attacker began moving funds into Zcash's private pool on Wednesday, a move that encrypts sender, receiver, and amount data, making on-chain tracking significantly more difficult.

For NEAR Intents, the dual role of having assisted in the Bitget response while subsequently falling victim to its own exploit raises questions the security posture of cross-chain infrastructure more broadly. The protocol's willingness to compensate users in full may mitigate immediate reputational damage, but the incident serves as another data point in what has become a defining challenge for the industry's interoperability layer.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Attack Types (1)

Companies (2)

Countries (1)

Industries (1)

Platforms (2)