NEAR Intents, a cross-chain swap service built on NEAR Protocol, said it lost about $3.8 million in an exploit tied to its Omni deposit and withdrawal infrastructure. The team paused deposits and withdrawals after detecting the incident and said the flaw has since been patched.

The service said affected users will be fully reimbursed and that the case has been reported to law enforcement. While the incident weighed on NEAR’s token price, the NEAR blockchain itself was not identified as the direct target of the attack.

Bug traced to contract interaction

According to NEAR Intents, the exploit was caused by a bug in the way its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract, which handles the recording of swaps. The issue affected the service layer built around cross-chain transfers rather than the underlying NEAR blockchain.

After the problem was identified, NEAR Intents halted parts of the platform to contain the incident. The team later said the contract flaw had been fixed.

Funds moved out before shutdown

An on-chain investigator reported unusual outflows from the service’s hot wallet on BNB Chain shortly before transactions were stopped. The stolen assets were then sent to KuCoin and converted into Bitcoin, according to the source report.

NEAR Intents has not said in the extracted report that the attacker was identified. Its public response instead focused on patching the vulnerability, stopping further movement through the affected system, and planning reimbursement.

Deposits and withdrawals paused on multiple chains

Deposits and withdrawals were paused for roughly 12 more hours across 11 networks: BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. NEAR Intents said users with assets on those chains should be able to swap into other tokens again once the core service returns.

The interruption affects a product that had recently been highlighted for its processed swap volume. The source article noted that the exploit came shortly after Bitwise launched what it described as the first US spot NEAR ETF, which had pointed to NEAR Intents as a milestone in network usage.

Market reaction and wider context

The hack was followed by a drop in the NEAR token price. At the time referenced in the source article, NEAR was trading around $4.92, giving it a market capitalization of about $6.4 billion.

The report also described this as the second major exploit in the NEAR ecosystem this year, after Rhea Finance lost $7.6 million in April. So far, however, there has been no report in the source material of losses to the NEAR blockchain itself from the latest incident.

Next step is a technical report

NEAR Intents said a full technical report will be released in the coming days. That disclosure is expected to clarify how the bug was exploited, what safeguards were added after the patch, and how service restoration will proceed across the affected networks.

For now, the confirmed steps are the temporary suspension of deposits and withdrawals, the promise of full compensation for affected users, and the company’s statement that law enforcement has been notified.

Source: beincrypto.com