NEAR Intents Loses $3.8 Million in Exploit, Pauses Cross-Chain Services
TECHNOLOGY

NEAR Intents Loses $3.8 Million in Exploit, Pauses Cross-Chain Services

Image credit: Pexels

Key Takeaways

  • The exploit stemmed from a bug in how the Omni system interacted with the NEAR Intents smart contract, and the underlying NEAR Protocol blockchain was not affected.
  • ZachXBT said the theft began with irregular withdrawals from a BNB Chain hot wallet, with funds sent to KuCoin and converted into bitcoin.
  • Core services are expected to resume quickly, but deposits and withdrawals on several networks will stay down longer while further fixes are completed.

Cross-chain trading protocol NEAR Intents suffered a security exploit Thursday that resulted in about $3.8 million in losses, forcing the platform to pause services and temporarily disable deposits and withdrawals across several blockchains. The project said the vulnerability has been patched and that affected funds will be reimbursed in full.

A Bug in the System Connecting Blockchains

NEAR Intents said in a statement the incident stemmed from a bug in how its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract. The contract-side vulnerability has since been fixed, according to the project.

NEAR Intents is built to simplify cross-chain trading. Rather than requiring users to manually select a bridge, exchange or trading route, the system lets users specify the swap they want, and independent market makers known as solvers compete behind the scenes to execute it most efficiently. 

The platform’s own website states it has processed more than $30 billion in trading volume across 35 blockchains since launch.

NEAR, the native token of the NEAR Protocol blockchain closely associated with NEAR Intents, fell about 6% over the 24 hours following the exploit. 

The vulnerability itself was confined to the cross-chain infrastructure layer rather than the underlying NEAR Protocol blockchain, a distinction that matters for assessing the incident’s scope: the core blockchain and its consensus mechanism were not affected, and the exploit did not involve any flaw in how NEAR Protocol itself validates transactions.

Part of a Costly Year for Crypto Security

The incident adds to a difficult year for crypto security broadly. Exchange Bitget suffered a breach resulting in more than $350 million in stolen assets last week. 

Other major incidents this year have included a roughly $320 million exploit affecting Liquid Network, a Bitcoin-focused network used by exchanges; a $295 million exploit at prediction market protocol Drift; and a $293 million exploit at liquid restaking protocol Kelp, according to tracking data from DefiLlama.

Measured against that backdrop, the NEAR Intents exploit is comparatively modest in dollar terms. It adds to a pattern in which cross-chain infrastructure, the systems that let assets and data move between otherwise separate blockchains, has remained one of the more frequently targeted categories of crypto infrastructure throughout the year. 

That pattern reflects a structural reality: cross-chain systems must correctly interpret and act on data originating from a different blockchain’s own rules and formatting, creating more points where a parsing or validation error can be exploited than a system operating entirely within a single blockchain’s environment.

Tracing the Stolen Funds

NEAR Intents said it has reported the incident to law enforcement and is working with security and blockchain analytics firms to trace the stolen funds. 

Blockchain investigator ZachXBT said the exploit began with irregular withdrawals from a BNB Chain hot wallet linked to NEAR Intents, and that the stolen funds were subsequently sent to crypto exchange KuCoin and converted into bitcoin.

Converting stolen funds into Bitcoin and routing them through a centralized exchange is a common pattern in crypto theft cases. It can make funds harder to trace through DeFi protocols alone while giving an attacker a path toward eventually cashing out, though exchanges that identify suspicious deposits can freeze accounts before funds are withdrawn.

Service Restoration Expected to Take Time

NEAR Intents said it expects core services to resume relatively quickly, but deposits and withdrawals on several affected networks were expected to remain unavailable for longer while additional fixes are completed. 

The project’s status page showed ongoing issues affecting BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma as of this writing.

More For You

Explore More News