NEAR Intents, a cross-chain trading protocol built around the NEAR ecosystem, was exploited for approximately $3.8 million on Thursday, forcing the platform to pause services and disable deposits and withdrawals across eleven networks.
The project said the incident stemmed from a bug in the way its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract. The contract-side vulnerability has been patched, trading has resumed across most networks, and affected funds will be reimbursed in full, the team said. The protocol reported the incident to law enforcement and is working with security and blockchain analytics firms to trace the funds, with a full post-mortem expected in the coming days.
Deposits and withdrawals on BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma were set to remain unavailable for longer while fixes are completed, according to the platform's status page, as reported by CoinDesk.
The On-Chain Trail
Blockchain investigator ZachXBT documented the exploit as it unfolded: irregular withdrawals from a BNB Chain hot wallet linked to NEAR Intents, with transactions stopping as the team halted processing. "The funds were immediately transferred to Kucoin and bridged to Bitcoin," he wrote — a laundering path that mirrors the one used after the Bitget breach the week before.
NEAR, the native token of the NEAR Protocol blockchain, fell roughly 6% in the hours after the disclosure, though the disclosed vulnerability sat in NEAR Intents' cross-chain infrastructure, not the underlying protocol. The platform's website says it has processed more than $30 billion in volume across 35 chains.
One Week After It Froze Bitget's Money
The timing is awkward. In the days after the $387.5 million Bitget theft, more than $50 million in wallet-linked funds attempted to pass through NEAR Intents. General Manager Alex Shevchenko said its SHIELD risk system rejected most of those swaps, froze roughly $503,000 mid-execution and let only about $166,000 through — a screening posture that stood in contrast to THORChain, which processed tens of millions in stolen ETH and refused Bitget's requests to block the addresses.
Now the protocol that argued permissionless infrastructure can still refuse known illicit transactions is itself cleaning up an incident, and its emergency halt — a centralized kill switch by design — has revived the debate over how decentralized operator-gated cross-chain systems really are, as Protos noted.
The $3.8 million loss is small against this year's major incidents. But it lands in a week when the industry's cross-chain plumbing — the bridges, solvers and intent systems that move value between chains — has been used both to launder one of the largest exchange thefts on record and to fail on its own terms within the same seven-day window.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.