NEAR Intents Hacked: Intercepted $50M in Hacker Funds Last Week, $3.8M Stolen from Itself This Week

By Xiaobing
On October 1, the cross-chain swap protocol NEAR Intents released a security advisory confirming it had been attacked. Initial investigations indicate the vulnerability stemmed from a flaw in the interaction between the Omni deposit/withdrawal infrastructure and the smart contract. The team stated that contract fixes have been completed, with core services expected to resume within one hour. Deposit and withdrawal services across multiple public chains including BSC, Polygon, and TON will be suspended for an additional approximately 12 hours.
On-chain investigator ZachXBT subsequently disclosed more specific details: multiple abnormal fund outflows were detected from NEAR Intents' BSC hot wallet, with stolen funds transferred to KuCoin and further bridged to the Bitcoin network. The amount involved exceeded $3.8 million.
NEAR Intents has committed to full reimbursement for affected assets, the case has been reported to authorities, and on-chain tracking is ongoing.
The "Security Guardian" From a Week Ago, The Victim a Week Later
The most unsettling aspect of this attack lies in the disturbing timeline behind the $3.8 million loss.
Just under a week ago, NEAR Intents appeared in another major security incident as a guardian of safety.
On September 24, crypto exchange Bitget suffered a $387.5 million security breach. Attackers exploited a zero-day vulnerability in a third-party security product to obtain internal credentials and bypass risk controls, initiating unauthorized withdrawals.
Following the Bitget incident, large amounts of stolen funds attempted to launder through cross-chain infrastructure. NEAR Intents' SHIELD security system detected and intercepted over $50 million in suspicious transfer attempts, freezing approximately $503,000 in transit. NEAR Intents General Manager Alex Shevchenko publicly announced that they would waive the total 10% bounty offered by Bitget (5% for freezing + 5% for recovery) to ensure more funds could return to the exchange.
At the time, Shevchenko made a widely quoted statement: “The crypto industry cannot demand recognition of digital property rights while simultaneously building infrastructure optimized to help launder stolen funds.”
Now, the very protocol that uttered those words has been breached.
Attack Vector: Contract Interaction Flaw in Omni Infrastructure
According to NEAR Intents' official advisory, the vulnerability lay in the interaction between the Omni deposit/withdrawal infrastructure and smart contracts. Specifically, this was a flaw at the infrastructure level when handling multi-chain asset deposits and withdrawals. Attackers exploited defects in the contract interactions to drain funds from the BSC hot wallet.
Fund flow tracked by ZachXBT revealed a typical money laundering path: stolen assets flowed out of the BSC hot wallet into KuCoin, and were then bridged from KuCoin to the Bitcoin network.
This path is noteworthy because it mirrors the money laundering patterns used in several prior attacks attributed to the North Korean hacker group Lazarus Group. In the Bitget case, CEO Gracy Chen confirmed that IP behavioral patterns and on-chain analysis indicated the attack was carried out by North Korean actors, with Elliptic and TRM Labs identifying wallet addresses overlapping with earlier North Korean hacking operations. Scorechain also attributed the relevant wallets to Lazarus Group.
It must be clarified that no security firm or on-chain analytics company has currently attributed this attack on NEAR Intents to North Korean hackers. However, the fund routing to KuCoin and then to Bitcoin, combined with the timing shortly after NEAR Intents' highly publicized interception of Bitget's stolen funds, these two coincidences are sufficient to spark outside speculation.
In a note on September 30, Blocksec proposed an important analytical framework: overlaps in on-chain wallet addresses sometimes point to shared money laundering service providers rather than the same group of attackers.
What Is NEAR Intents, and Why Was It Targeted?
NEAR Intents is a cross-chain intent protocol built on NEAR Protocol. Simply put, users only need to declare their desired outcome (e.g., "swap USDC for ZEC"), and the protocol uses specialized routers to execute trades across multiple blockchains in the background.
This intent-based cross-chain architecture has seen rapid growth over the past year.
NEAR Intents' cumulative trading volume has surpassed $2 billion, processing approximately $800 million in cross-chain volume over the past 30 days across major chains including Ethereum, Solana, and Zcash. It is also integrated with Electric Coin Company's Zashi wallet, enabling direct swaps from BTC, SOL, and USDC into the privacy coin ZEC, with $600 million to $700 million in volume flowing through this channel.
Precisely because NEAR Intents handles massive cross-chain capital flows, its deposit/withdrawal infrastructure and hot wallets have become high-value targets. Cross-chain bridges and swap protocols have long been disaster zones for crypto security incidents. From Wormhole ($320 million) and Ronin Bridge ($620 million) in 2022 to WazirX ($230 million) in 2024, attackers have repeatedly proven: The security of infrastructure connecting multiple chains depends entirely on its weakest link.
Ripple Effects of the Bitget Case Continue to Spread
NEAR Intents' own security incident occurred against the backdrop of lingering fallout from the Bitget case.
On October 1, blockchain tracking company MistTrack reported that addresses linked to the Bitget attackers were still converting DAI stablecoins and bridging them to the Tron network. Attackers simultaneously utilized Wasabi CoinJoin (a Bitcoin privacy mixing tool) to obfuscate fund sources. One week later, only about $503,000 of the $387.5 million had been frozen, yielding a recovery rate of just 0.13%.
In the Bitget incident, NEAR Intents played a defensive role, while THORChain rejected Bitget CEO's request to freeze funds, citing its "design philosophy of non-censorship." The debate over whether decentralized protocols should freeze suspicious funds remains unresolved.
Now that NEAR Intents itself stands on the side of the victim, its stance on "digital property rights" and "refusing to become money laundering infrastructure" will inevitably be scrutinized differently: a protocol calling on the industry to assume security responsibilities harbors exploitable vulnerabilities within its own security infrastructure.
The Crypto Security Landscape in 2026
Placing this incident within the broader 2026 landscape paints a grim picture.
Bybit was hacked for $1.5 billion in February 2025, confirmed by the FBI as being orchestrated by North Korea's TraderTraitor (i.e., Lazarus Group). Bitget lost $387.5 million in September 2026, with on-chain analysis pointing to the same state-level actor. NEAR Intents lost $3.8 million in October, with attribution yet unclear.
Since 2021, Lazarus Group is believed to have cumulatively stolen over $5 billion from the crypto industry. UN investigations indicate these funds were used for North Korea's weapons programs.
Previously, a NEAR Co-founder publicly stated that AI-assisted attacks are making traditional code audits increasingly difficult to manage, and the blockchain industry should shift toward formal verification. This assessment carries significant weight given that a protocol within NEAR's own ecosystem has now been compromised.
$3.8 million is not a large figure in the history of crypto security incidents. But when taken from a protocol that had just won industry respect for its security capabilities, the signal it sends far outweighs the amount itself: In this industry, no one can truly be secure the moment they declare themselves safe.
Join the official Coincamps community:
Telegram: https://t.me/coin_camps
Recommended
Hyperliquid will use $15 million USDC revenue for HYPE buybacks; buybacks will no longer rely solely on trading fees.
Oct 3, 18:27
Grayscale Zcash Spot ETF Sees $93.56M in Single-Week Redemptions: Honeymoon Period Turns Sharp, Once Held Nearly 3.5% of Supply
Oct 3, 16:41
After resuming withdrawals, funds did not fall but rose instead. How did Bitget turn the situation around in five days?
Oct 3, 16:32
SEC Clears 3x Leveraged Bitcoin and Ethereum ETPs: Listing Rules Approved, Trading Still Pending Activation
Oct 3, 16:22
Funds Rose Instead of Fell After Withdrawals Were Resumed: How Did Bitget Turn Things Around in Five Days?
Oct 3, 16:11
CryptoPunks Trading Volume Surges Nearly 12X in a Week: Rare Variants Sell for Millions Again, Market Rally Decoupled from ETH
Oct 3, 13:36