Fended Off a $50M Heist, Yet Had Their Home Base Stolen: The Full Story of the NEAR Intents Hack and Market Projections

On October 1, following a sudden security incident announcement, $NEAR, which had just experienced a strong rally, saw a rapid short-term plunge, with its drop reaching up to 8%.
Many traders who weren't tracking the market may still be puzzled: What happened to NEAR? Was the mainnet hacked?
To briefly outline the breaking developments: The core cross-chain protocol on the NEAR ecosystem, NEAR Intents, was hacked today, with approximately $3.8 million worth of assets drained from its underlying vault.

But if you piece together the timeline over the past 48 hours, you will notice this incident played out as a highly darkly comedic dramatic reversal.
Just days prior, Bitget exchange suffered a hack attack where thieves attempted to launder over $50 million in stolen funds via NEAR Intents. As a result, the protocol’s AI security monitoring layer, SHIELD, immediately identified and froze the substantial sum. Approximately $503,000 was successfully frozen during the execution phase, while only about $166,000 luckily managed to slip through. All other transfer attempts were overwhelmingly rejected.
In a short time, the community elevated NEAR Intents to the status of the "pioneer of full-chain defense." Yet before the glory could even settle, hackers exploited a contract logic flaw in the underlying deposit and withdrawal interface to forcibly drain assets directly from their own vaults.
They had barely pinned down a $50 million-class thief at the front door when someone else prided open the backdoor to their own vault.
Beyond the dramatic narrative, for secondary market traders and $NEAR holders, it is crucial to strip away emotional reactions and clearly assess the actual asset boundaries and follow-up scenarios of this incident.
The Mainnet Was Not Compromised; The Issue Lies with NEAR Intents
According to the disclosure by NEAR founder Illia, the cross-chain intent protocol NEAR Intents built on NEAR was affected, rather than the NEAR L1 mainnet consensus layer. The security of the core protocol and native token remains uncompromised.
The point of entry for the attack was extremely precise.
Hackers did not directly assault NEAR Intents’ core logic; instead, they exploited a logical flaw in the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents contract. The attack was strictly confined to the USDT asset pool on BNB Chain. Within an extremely short timeframe, hackers drained approximately 3.87 million USDT and rapidly transferred them to exchanges to convert into Bitcoin for exit.

Notably, the official emergency response and engineering handling demonstrated a high level of maturity.
The team identified the specific vulnerability and deployed a hotfix within one hour of detecting the anomaly. They also swiftly suspended deposit and withdrawal operations across 11 networks involved in the Omni fix (including BSC, Polygon, Avalanche, etc.) for approximately 12 hours of secure isolation and troubleshooting.
Most importantly, the official team explicitly committed to 100% compensation for all affected users.
Short-Term Price Dip, but Fundamentals Remain Largely Unchanged
The security incident directly triggered sell pressure in the secondary market. Driven by the unfolding news, $NEAR’s price dropped intraday from around $5.50 to approximately $4.74, marking a decline of 6%–8%.
From a trading dynamics perspective, this decline was primarily driven by emotional profit-taking leveraging negative news.
Reviewing September’s trend, NEAR experienced a highly explosive unidirectional rally. This was driven primarily by two factors: the release of the new “Confidential Intents” narrative, and the realization of expectations surrounding the Bitwise spot NEAR ETF launching for trading in the U.S. After accumulating significant profits in a short period, the market inherently faced the need for a technical correction.
In terms of fundamental scale, NEAR Intents has officially disclosed that its monthly transaction and payment processing volume exceeds $4 billion. The $3.8 million exposure represents an extremely small fraction of total throughput (less than 0.1%). Furthermore, due to the official promise of full compensation, this loss has been internally absorbed and will not ripple outward to trigger cascading liquidations or bad debt spirals within the DeFi lending ecosystem.
Therefore, this downward move defined the short-term panic floor. As deposit and withdrawal functions across the 11 chains are gradually restored, and with the subsequent release of a comprehensive postmortem report, funds pulled out due to risk-off sentiment are highly likely to return.

The Achilles’ Heel of the Intents Narrative
This event transcends a simple hack and touches upon the core pain point in the evolution of current crypto infrastructure: the security paradox between “bridge-less” and “cross-chain” systems.
Davis Hoffman, co-founder of Bankless, noted that hacks on centralized exchanges and cross-chain bridge vulnerabilities have historically been the two biggest sources of losses in the crypto industry. The NEAR team’s ability to patch quickly within hours and provide full compensation demonstrates top-tier engineering capability.
Yet, as crypto researcher Warden pointed out: “No matter how perfect the outer wrapper is, the cross-chain seams remain the most terrifying part.”
Within the “Intents” narrative, complex user cross-chain operations are abstracted and delegated to Solvers for backend processing, delivering a frontend experience as smooth as a centralized exchange.
However, the final settlement and mapping of assets across different heterogeneous chains still rely on underlying vaults and deposit/withdrawal interfaces.
These “seams” are precisely the juiciest targets in the eyes of hackers. Just moments after SHIELD AI used big data to catch external laundering anomalies, hackers exploited the most fundamental contract logic flaws to sneakily raid the vault.
With the integration of AI, offensive and defensive battles in the crypto space are entering a higher-dimensional era. Whether it is full-chain abstraction or confidential intents, the more expansive the business logic, the more boundary seams emerge.
Until robust engineering standards and formal verification become widespread, absolute security for cross-chain assets remains a pseudo-problem.
Therefore, for coin holders, there is no need for excessive panic in the short term. Focus should be placed on tracking three critical checkpoints:
- Whether the $3.8 million in compensation promised by the NEAR official team is fully disbursed;
- Whether the 11 chains with suspended deposits and withdrawals resume interactions as stated after the 12-hour mark;
- Whether the subsequent postmortem report can thoroughly eliminate potential risks in cross-chain interactions from an architectural perspective.
Join the official Coincamps community:
Telegram: https://t.me/coin_camps
Recommended
Hyperliquid will use $15 million USDC revenue for HYPE buybacks; buybacks will no longer rely solely on trading fees.
Oct 3, 18:27
Grayscale Zcash Spot ETF Sees $93.56M in Single-Week Redemptions: Honeymoon Period Turns Sharp, Once Held Nearly 3.5% of Supply
Oct 3, 16:41
After resuming withdrawals, funds did not fall but rose instead. How did Bitget turn the situation around in five days?
Oct 3, 16:32
SEC Clears 3x Leveraged Bitcoin and Ethereum ETPs: Listing Rules Approved, Trading Still Pending Activation
Oct 3, 16:22
Funds Rose Instead of Fell After Withdrawals Were Resumed: How Did Bitget Turn Things Around in Five Days?
Oct 3, 16:11
CryptoPunks Trading Volume Surges Nearly 12X in a Week: Rare Variants Sell for Millions Again, Market Rally Decoupled from ETH
Oct 3, 13:36