NEAR Intents pauses cross-chain swaps after $3.8 million exploit
The cross-chain platform halted services on October 1 after a bug in its Omni deposit system led to a preliminary $3.8 million loss. It came days after NEAR Intents said it had blocked more than $50 million tied to the Bitget hackers.
By Yash Malviya
Published · 4 min read
NEAR Intents halted its cross-chain trading service on October 1 after an attacker exploited a bug and took about $3.8 million. The platform paused deposits and withdrawals on 11 blockchains and said every affected user would be paid back in full.
That figure is preliminary, and it comes from NEAR Intents itself. In a statement posted the same day, the team blamed a bug in how its Omni deposit and withdrawal system worked with its main smart contract. The flaw is now patched.
What NEAR Intents says happened
NEAR Intents is a cross-chain trading service. It lets someone hold tokens on one blockchain and trade for tokens on another without the usual manual steps of bridging and swapping by hand. Plumbing called Omni moves the value behind the scenes. That plumbing is where the bug sat. Every extra hop between networks is another place for something to break.
The service was stopped, the contract was fixed, and NEAR Intents said deposits and withdrawals on 11 networks, including BNB Smart Chain, Polygon and Optimism, would stay off for about 12 more hours while it finished the repair. The main site and app were expected back within roughly an hour. The underlying NEAR blockchain was not the target.
Blockchain investigator ZachXBT said the stolen money was sent to the exchange KuCoin and then swapped into bitcoin. NEAR Intents said it had reported the incident to law enforcement and brought in security and analytics firms to follow the funds. Once money reaches a large exchange and becomes bitcoin, getting it back is hard. The NEAR token fell about 6% in the 24 hours to the afternoon of October 1, according to CoinDesk.
Tools that move value between blockchains have been a favorite target this year, as a run of bridge hacks has shown. The more code sits between two chains, the more surface an attacker has to probe.
A platform that had just blocked $50 million in stolen funds
The timing stings. Days earlier, NEAR Intents said it had stopped more than $50 million in transfers linked to the attackers behind the Bitget hack, using an internal screening tool it calls SHIELD. It froze $503,000 mid-swap. About $166,000 slipped through. Measured in dollars, the platform had just turned away more than ten times what it would soon lose.
Alex Shevchenko, general manager of NEAR Intents, framed that work as a matter of principle. "Refusing to help launder stolen assets is one of ours," he said. A week later the same platform was losing money itself, this time to its own code rather than someone else's keys.
People SHIELD was built to stop have tools of their own. The Bitget attacker moved roughly 2,700 Zcash coins into a shielded pool on September 30, according to Decrypt. Such pools hide the sender, the receiver and the amount, so investigators can watch money go in and come out but not see what happens inside. That is the wall anyone chasing stolen crypto now runs into.
A rough year for crypto security
This was not an isolated case. CoinDesk counted the NEAR Intents loss next to a string of larger thefts in 2026, including the $352 million Bitget hack, a $320 million loss at Liquid Network, and drains of $295 million at Drift and $293 million at Kelp. Set against those, $3.8 million is small. For the people whose funds moved, the size is not the point.
A promise to repay is not the same as getting money back. NEAR Intents has not said how many users were affected, has not given a final loss total, and has not recovered the funds that already reached bitcoin. Nor has it said where the money to repay users will come from. Those are the gaps that matter now.
What to watch
Watch for a final loss figure to replace the preliminary one. Then look for proof that affected users actually got their money back, not a repeat of the pledge. The real test is whether any funds that reached KuCoin and bitcoin get frozen or returned, which rarely happens once money passes through an exchange.
Trust is the other open question. NEAR Intents built part of its pitch on catching dirty money with SHIELD. Keeping users after a loss it caused itself will take more than a patch.
Frequently asked
How much did the NEAR Intents exploit cost?
NEAR Intents put the preliminary loss at about $3.8 million in a statement on October 1, 2026. The figure could still change. The team said it would pay back every affected user in full, but it has not published a final total or confirmed how many people were hit.
Was the NEAR blockchain itself hacked?
No. The exploit hit NEAR Intents, a cross-chain trading service, through a bug in its Omni deposit and withdrawal system. The underlying NEAR blockchain was not the target. NEAR Intents paused deposits and withdrawals on 11 networks, including BNB Smart Chain, Polygon and Optimism, while it finished the fix.
Will users get their money back?
NEAR Intents said affected funds would be reimbursed in full and that it had patched the bug. A pledge is not a recovery. An investigator said the stolen money was sent to KuCoin and swapped into bitcoin, which is hard to claw back once it passes through an exchange. Watch for proof users were actually repaid.
Sources, and what is behind them
- Earlier today NEAR Intents services were stopped after a security incident was detected, NEAR Intents (October 1, 2026)Other
- NEAR Intents hit by $3.8M exploit, pauses cross-chain services in latest crypto hack, CoinDesk (October 1, 2026)Press report
- NEAR Intents says it blocked $50M tied to Bitget hackers, CointelegraphPress report
- Bitget Hacker Turns to Zcash Privacy Pool After Near Rejects $50M in Swaps, DecryptPress report