NEAR Intents said it will reimburse users after an attacker drained about $3.8 million in USDT from a BNB Chain liquidity pool on Oct. 1, exploiting a flaw in the protocol’s Omni deposit-and-withdrawal interface. The incident was contained within NEAR Intents’ cross-chain infrastructure and did not affect NEAR’s layer-1 consensus, the security of the NEAR blockchain, or the native NEAR token’s underlying protocol.
The attacker withdrew roughly 3.87 million USDT within a short period, according to the protocol’s disclosed transaction flow. The funds were then moved to an exchange, converted into Bitcoin, and transferred out. NEAR Intents said the exposure was limited to its USDT pool on BNB Chain.
The protocol detected unusual activity and deployed a hotfix within one hour, according to its incident update. As part of the response, it paused deposits and withdrawals on 11 connected networks for roughly 12 hours while the team isolated the issue and reviewed related infrastructure. The temporary restrictions covered BNB Chain, Polygon, Avalanche and other networks connected through the Omni system.
A flaw in the deposit-and-withdrawal layer
The exploit targeted application logic rather than the smart-contract consensus rules of NEAR itself. NEAR Intents uses Omni as an interface for deposits and withdrawals across chains, allowing users to move assets into and out of the intent-based trading system.
Intent-based protocols allow users to state a desired trade or transfer outcome, while third parties known as solvers compete to execute the transaction. That model can simplify cross-chain activity for users, but it also creates additional components between a wallet and the destination chain. Deposit interfaces, withdrawal permissions, liquidity reserves and message-routing systems can each become separate security boundaries.
In this case, the vulnerability reportedly enabled the attacker to bypass internal limits and access the liquidity held for USDT withdrawals on BNB Chain. The episode illustrates how a cross-chain service can face a material loss even when the blockchain beneath it continues operating normally.
Illia, who commented on the breach, said the issue was confined to NEAR Intents. That distinction carries practical consequences for users: the incident concerns funds routed through a specific cross-chain product, rather than balances secured directly on the NEAR network.
NEAR Intents said it expects deposits and withdrawals to resume after the isolation period and security checks are completed. The team also said it would publish a post-incident report, which should provide a fuller account of the affected contracts, the vulnerability and the reimbursement process.
Stolen funds converted into Bitcoin
Efforts to trace the stolen assets have continued after the initial USDT withdrawals. General manager Shevchenko said on Oct. 2 that the attacker had been given 48 hours to return the funds.
Security teams traced 34.69 BTC associated with the theft to four wallets, according to the information disclosed by the protocol. Those wallets had not moved the Bitcoin at the time of the update. The path from USDT to an exchange and then to Bitcoin complicates recovery efforts, particularly once assets leave the original chain and pass through centralized trading venues or additional wallets.
The protocol’s pledge to reimburse affected users would shift the immediate financial burden from pool participants to the project or its associated entities, depending on how the compensation is structured. The announcement may limit direct user losses, though it does not remove questions around the source of reimbursement funds, safeguards for liquidity providers and changes to the affected withdrawal system.
A second security test in a short period
The incident followed an earlier attempt to route funds linked to the Bitget exchange hack through NEAR Intents. In that episode, more than $50 million in suspected stolen proceeds were directed toward the protocol, according to the supplied account of the incident.
NEAR Intents said its SHIELD monitoring system froze about $503,000 during that earlier event, while approximately $166,000 passed through. Most transfer attempts were rejected. SHIELD is designed to identify and restrict suspicious activity, placing transaction monitoring alongside the protocol’s automated cross-chain execution tools.
The two episodes involve different security challenges. The Bitget-related case centered on detecting potentially illicit funds moving through the system, while the Oct. 1 breach involved an attacker exploiting the protocol’s own deposit-and-withdrawal logic. Monitoring tools can help flag suspicious transfers, but they cannot substitute for secure contract design and carefully limited withdrawal permissions.
Volume brings liquidity and exposure
NEAR Intents has reported processing more than $4 billion in monthly transaction and payment volume. Against that figure, the approximately $3.8 million loss represents less than 0.1% of a month’s reported flow.
That comparison provides scale, but transaction volume is different from the liquid reserves available in a particular pool. A vulnerability affecting a single pool can cause concentrated losses even when the wider protocol handles substantially larger volumes. USDT pools are especially attractive targets because the token can be moved rapidly across networks and is widely accepted by trading platforms.
The market reaction added pressure after the disclosure. NEAR fell from around $5.50 to roughly $4.74 intraday, according to the supplied market pricing, a decline reported in the range of 6% to 8%. Price moves following a protocol exploit often reflect uncertainty over the scope of an incident, potential reimbursement costs and the possibility of further vulnerabilities.
NEAR Intents now faces a narrower but demanding task: restore the paused services without reopening the route used in the attack, compensate affected users as promised, and demonstrate that the Omni interface has been reviewed beyond the immediate flaw. The quality of its post-incident report and the details of the remediation will determine whether users view the Oct. 1 breach as an isolated contract failure or a warning about the protocol’s cross-chain risk controls.
Worried about exploits like NEAR Intents? Strengthen your defenses with Toobit’s crypto safety standards guide today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
