NEAR Intents paused cross-chain services on October 1 after attackers exploited a bug in the interaction between the NEAR Intents smart contract and Omni's custody architecture, draining $3.8 million from the platform's BNB Chain hot wallet. The stolen funds were quickly transferred to KuCoin and converted to Bitcoin. The native NEAR token plunged 7.5% to $4.76 before partially rebounding to $4.84. NEAR Intents pledged full user compensation from its treasury.
NEAR Intents exploit
- ▪The October 1, 2026 NEAR Intents hack cost the project $3.8 million
- ▪The native NEAR token plunged 7.5% within minutes of NEAR Intents' October 1, 2026 exploit announcement, hitting a local low of $4.76 before partially rebounding to $4.84
- ▪NEAR Intents' SHIELD security system had successfully blocked $50 million in transactions, foiling a hackers' attempt to launder funds after the $387.5 million Bitget exchange hack
- ▪NEAR Intents, the cross-chain trading protocol, has more than $30 billion in trading volume
- ▪NEAR Intents officially confirmed on October 1, 2026 that its Omni deposit and withdrawal infrastructure had been hacked
Attack mechanics
- ▪Attackers quickly transferred the stolen NEAR Intents assets to KuCoin, then converted them into Bitcoin through cross-chain bridges
- ▪Attackers exploited the Omni custody vulnerability to make unauthorized withdrawals from NEAR Intents' hot wallet on BNB Chain
- ▪The October 1, 2026 NEAR Intents incident was caused by a bug in the interaction between the NEAR Intents smart contract and Omni's custody architecture
Chain abstraction vulnerability
- ▪NEAR Intents implements the concept of Chain Abstraction, where users or AI agents state an intention and its underlying infrastructure handles bridges, gas fees, and network selection
- ▪NEAR Intents is positioned as a key financial layer for the AI agent economy, where agents need to interact with Web3 automatically without manual transaction signing
- ▪The October 1, 2026 NEAR Intents hack showed that an intents architecture remains vulnerable at integration points with conventional bridges even when external defenses are protected effectively
Debatable claims
- ▪Chain abstraction architectures introduce unacceptable security vulnerabilities
- ▪DeFi protocols bear legal liability for smart contract exploit losses
- ▪NEAR Intents' treasury compensation adequately addresses user losses from the exploit
- ▪Current DeFi security standards are inadequate for AI agent economies
Story comments
Loading comments…