NEAR Intents Halts Services After $3.8M Exploit
Security & Exploits ·
NEAR Intents paused deposits and withdrawals across multiple networks after a $3.8 million exploit, with the team pledging full compensation to affected users.
NEAR Intents confirmed the incident and halted operations, saying on X that all lost funds would be fully compensated, according to a post from the protocol's account. The Block reported the service freeze and the $3.8 million figure, noting the compensation commitment came alongside the shutdown rather than after an investigation concluded.
Accounts of the root cause vary across early reporting. Some descriptions point to a contract flaw underlying the exploit, while other reports attribute the losses to a bug in the Omni deposit and withdrawal flow; a separate account describes the breach as stemming from a compromised BSC hot wallet. Wu Blockchain covered the event as part of its ongoing exploit tracking. The discrepancy between a smart-contract-level flaw and a hot-wallet compromise points to two fundamentally different attack surfaces, and it is not yet clear which, if either, fully explains the loss.
Operationally, deposits and withdrawals were paused across 11 networks following the exploit, affecting users attempting to move funds through the Intents system during the halt. The team has said the vulnerability has since been patched and that service resumption is expected within hours, though no confirmed relaunch time has been independently verified across the reporting.
Seven distinct sources have corroborated the core facts of the incident: the $3.8 million loss figure, the service halt, and the compensation pledge. NEAR Intents operates as part of NEAR Protocol's cross-chain intent execution infrastructure, a system that has processed over $19 billion in volume, which underscores why an exploit touching deposit and withdrawal mechanics across multiple chains drew swift, wide attention. Leviathan's exploit tracker has logged the event within its broader incident coverage.
What remains unresolved is the precise technical cause of the breach, whether