NEAR Intents, a cross-chain swap service on NEAR, lost $3.87 million on October 1, 2026 — almost all of it USDT — after an attacker exploited a bug in the service’s deposit-and-withdrawal plumbing. The team halted services, confirmed the incident at 12:53 UTC, patched the contract-side flaw within about an hour of detection, and pledged to repay users in full.
If you follow crypto security incidents, one detail sets this one apart from the usual drainer story: no user signed anything wrong. The attack worked entirely above the user layer, inside the machinery that decides who is owed what. Understanding that machinery — and where the money went — is useful for anyone who keeps balances inside swap services, bridges, or intent-based platforms.
What NEAR Intents is, and where it keeps your money
NEAR Intents is a swap service. You hand it a coin on one chain and it pays you a different coin on another — no bridge UI, no manual hopping. It is one of NEAR’s busiest applications, and it landed in the news days after a US spot NEAR ETF started trading.
To work across chains, the service keeps vaults of coins on each chain it serves. This incident centered on a vault contract on BNB Chain — Bitquery’s address labels tie the vault to the HOT Protocol contract family, while NEAR Intents calls the surrounding system its Omni deposit-and-withdrawal infrastructure.
The payout mechanism matters, because that is exactly what failed. In simplified form:
- Deposit. You send coins to the vault. The service credits your internal balance.
- Signed note. When you want to withdraw, NEAR Intents’ back end signs a short note: pay this amount, to this wallet.
- Payout. Whoever holds that note hands it to the vault. The vault checks the signature and pays.
Your balance does not live on BNB Chain. It lives in the service’s own bookkeeping, and the signed note is how that bookkeeping tells the vault what you are owed. The vault, in other words, is a cashier that trusts the ledger behind it. That is the intent-based architecture trade-off in miniature: smooth cross-chain UX, at the cost of a trusted middle layer holding hot wallet funds.
The bug: notes the vault had every reason to honor
By NEAR Intents’ account, the bug lived in how the Omni deposit-and-withdrawal infrastructure talked to its smart contracts — the side that decides who is owed what. The vault did as it was told.
Bitquery’s reconstruction supports that reading. All seven of the attacker’s withdrawals — two tiny tests, then the five big ones — came with notes in the same form as every legitimate user’s. The signature verification was not broken. The balances behind the notes were.
That distinction is the whole story. An attacker who breaks signature verification must defeat cryptography. An attacker who gets the bookkeeping layer to believe in a balance only has to defeat a database — and a buggy integration is as good as a forged note. For the user, it means the service’s promise (“we will pay whoever our ledger says we owe”) is only as strong as the ledger’s integrity.
This is also why this incident is categorically different from the signature phishing and drainer attacks we usually cover. Those start at your wallet, with a bait claim page and a malicious approval. Here, the claim page never entered the picture. The vault paid out from user deposits because the internal accounting said to.
Timeline of the theft
Bitquery indexed every hop, so the timeline is unusually complete:
| When (UTC) | What happened |
|---|---|
| Sep 28 | Attacker’s wallet is set up, funded with BNB for gas, swaps some to USDT |
| Sep 28 evening | 10 USDT deposited into the vault (building the position) |
| Sep 30 ~18:00 | First test: 10 USDT withdrawn. About an hour later, an 11 USDT test |
| Sep 30 just before midnight | First big withdrawal: 800,000 USDT |
| Oct 1, within the hour | Two larger withdrawals (1.2M, 1.5M USDT) |
| Oct 1, ~1 hour later | Fourth withdrawal: 330,000 USDT |
| Oct 1, just after 06:00 | Fifth withdrawal: 35,000 USDT — total $3.87M |
| Oct 1, 12:53 | NEAR Intents confirms the incident and pauses services |
Five withdrawals, about six hours, $3.87 million. The two 10-USDT probes the evening before are textbook attacker tradecraft: verify the mechanism end-to-end before committing.
Where the money went
The laundering path is instructive, because it is the standard playbook for stolen stablecoins:
- 76% — Bitcoin. $2.93M converted to 34.69 BTC across four Bitcoin wallets that had not spent a satoshi when Bitquery last checked. BTC held in fresh wallets is slow to trace and cheap to sit on.
- 21% — KuCoin. $802k reached KuCoin deposit addresses by two routes. One of those addresses had been in use since August 6 — a detail that matters for investigators, because exchange deposit addresses sit behind KYC. This slice is the most realistic recovery target.
- 2% — Monero exposure. The first batch was turned into a Monero token on Hyperliquid ($90k, unmoved). Monero is the classic exit toward untraceable value.
- 1% — costs. Swap fees and price slippage along the way.
Two details deserve emphasis. First, about a fifth of the loot ($822k) was swapped through NEAR Intents’ own service during the theft — including 750 BNB paid back to the very vault being drained. Second, the cross-chain swap provider Chainflip processed 17 of the attacker’s swaps, then rejected the next three; within ten minutes the attacker moved to THORChain. That is the cat-and-mouse reality of front-line laundering controls: they slow the flow, they don’t stop it.
If you want to go deeper on how investigators follow trails like this, our token flow analysis walkthrough covers the techniques — and why the BTC-in-cold-wallets tail is where trails usually go cold.
Not the first cross-chain incident, and the response playbook
NEAR Intents said it had previously blocked a significant amount of suspicious transactions tied to an earlier hack elsewhere — blocking tainted inflows is one thing; having your own vault drained is another.
The response followed the now-standard incident playbook:
- Pause everything. Services stopped, limiting further exposure.
- Patch fast. The contract-side flaw was fixed within about an hour of detection; core services returned quickly, with some cross-chain features offline longer.
- Pledge restitution. Users will be repaid in full, per the team’s statement.
- Public pressure. The protocol’s general manager gave the attacker a 48-hour window to return the funds and published three return addresses.
- Trace and engage. Work with law enforcement and blockchain analytics firms; AMLBot flagged the withdrawals and ZachXBT traced the outbound flows within the hour.
The 48-hour ultimatum is more than theater. Money that reaches a KYC exchange is money the attacker can barely touch without exposure — every hour the $802k sits at KuCoin, the recovery odds improve. For a comparison of what victims and platforms can realistically do after funds move, see our stolen crypto: first 24 hours guide and the recovery help hub.
What this means for ordinary users
The NEAR token dropped 6–10% on the news even though the NEAR chain itself never stopped — application-layer exploits get priced like protocol-layer ones. Separate the two in your head: your NEAR in your own wallet was never at risk here. The money at risk was money sitting inside the service.
That points at the practical takeaways:
- A swap-service balance is a hot-vault deposit. When you finish a swap or a trade, withdraw to a wallet you control. Balances that linger are effectively interest-free loans to the platform’s operational security.
- User-side OPSEC cannot cover platform-side bugs. Hardware wallet, careful signature review, revoked allowances — all of it assumes the theft starts at your keys. This one started at the ledger. Diversify where you park working balances, and size them like cash in someone else’s safe.
- Recovery runs through chokepoints. Nearly a quarter of this haul is at an exchange, and that is where law enforcement actually gets leverage. It is also why the attacker’s BTC-and-Monero tail exists: that money is parked, not spent, precisely because spending it risks exposure.
- Watch the pause, not the price. When a service halts withdrawals, assume the incident is material until a post-mortem says otherwise. Cheap insurance: move balances out during the uncertainty window.
NEAR Intents has promised a full technical report. Until then, the working picture — a signed-note payout system, a bookkeeping bug, five withdrawals, and a laundering chain through BTC, THORChain, and KuCoin — is confirmed by the company’s own statements and by independent on-chain tracing. We will update this article as the post-mortem and any recovery developments land.
Sources
- NEAR Intents incident statement (X)
- Bitquery: NEAR Intents Hack — Where the $3.87M Went
- AMLBot flagging of the withdrawals (X)
- Crypto Briefing: NEAR Intents GM gives attacker 48 hours to return funds
- Yahoo Finance: NEAR Intents Hacked for $3.8 Million — Is NEAR Protocol Safe?
Frequently Asked Questions
Was the NEAR Protocol itself hacked?
No. The exploit hit NEAR Intents, a swap application built on NEAR, not the NEAR blockchain. The stolen funds came from a deposit vault on BNB Chain. The underlying chain kept running normally; the NEAR token dropped 6–10% on the news anyway.
Could users have prevented this by refusing to sign something?
No. This was not a phishing or drainer attack where a victim signs a malicious message. The bug sat in NEAR Intents' own deposit-and-withdrawal infrastructure, and the vault paid out on notes that looked like everyone else's withdrawal notes. User-side signature hygiene had no lever to pull here.
Where did the stolen money go?
According to Bitquery's on-chain tracing: about 76% became 34.69 BTC sitting in four Bitcoin wallets that had not moved; about 21% ($802k) reached KuCoin deposit addresses; roughly $90k was converted into a Monero token on Hyperliquid; the rest went to swap fees. About a fifth of the loot was swapped through NEAR Intents' own service during the theft.
Will affected users get their money back?
NEAR Intents pledged to fully compensate affected users, gave the attacker a 48-hour window to return funds to three published addresses, and said it is working with law enforcement and blockchain analytics firms. The portion routed to KuCoin is the most realistic recovery path, because exchange deposit addresses sit behind KYC.
How is this different from a wallet drainer attack?
A drainer tricks you into signing a malicious transaction or message, so the theft starts at your wallet. Here the theft started at the service's internal accounting layer — the vault's signature verification worked exactly as designed, but the system that decides who is owed what had a bug. One attacks your keys; the other attacks the bank's ledger.