Oct. 2 (CandyPulse) — NEAR Intents, a protocol that lets users swap crypto across different blockchains, is back online after an exploit drained about $3.8 million. The team has patched the vulnerability and pledged to fully compensate affected users.
Key takeaways
According to the team, the problem was a bug in how the Omni deposit and withdrawal infrastructure worked together with the NEAR Intents smart contract. An attacker exploited it to take roughly $3.8 million.
NEAR Intents halted services while it investigated and fixed the issue.
The contract vulnerability has been patched, and NEAR Intents and Near.com reopened soon after. Not everything came back at once, though:
| Area | Status |
|---|---|
| NEAR Intents and Near.com | Resumed after the patch |
| Deposits and withdrawals on 11 chains (incl. BSC, Polygon, Optimism) | Temporarily unavailable, for roughly 12 hours |
| User losses | Full compensation pledged |
The stolen funds were reportedly sent to the KuCoin exchange and bridged to bitcoin. NEAR Intents says it's working with law enforcement and blockchain analytics firms to trace them, and plans to publish a post-mortem report explaining exactly what happened.
The news weighed on the NEAR token, which reportedly fell about 9% after the exploit came to light.
Cross-chain tools are some of the most useful, and most targeted, parts of crypto. Every time funds move between blockchains, more code and more systems are involved, and each one is a possible weak point.
The quick patch and the promise of full compensation are reassuring. But this is another reminder that bridges and cross-chain swaps carry extra risk.
This article is for information only and is not financial advice.