NEAR Intents, the cross-chain trading system built on NEAR Protocol, lost roughly $3.8 million to an exploit on October 1, 2026, becoming the latest name on a lengthening list of 2026 crypto security failures. The protocol froze deposits and withdrawals across 11 blockchains within hours, patched the underlying smart contract bug, and promised full reimbursement to affected users. Then something unusual happened: according to NEAR co-founder Illia Polosukhin, the attacker gave the money back roughly a day after the team made contact.

The incident lands in the middle of what CoinDesk and blockchain analytics firms CertiK and PeckShield have called the worst month for crypto security in 2026, when roughly $766 million to $768 million disappeared across 99 separate incidents in September alone. NEAR Intents is smaller in dollar terms than the headline hacks that preceded it, but the technical story, how a single integration bug between a custody system and a smart contract forced a chain-abstraction protocol to shut down operations on 11 networks, raises harder questions about where the next wave of crypto losses will come from.

A $3.8 Million Hole Opens in NEAR’s Cross-Chain Plumbing

NEAR Intents disclosed the breach publicly on October 1, 2026, confirming that an attacker had drained approximately $3.8 million in USDT from a vault tied to its BNB Chain operations. Bitquery’s on-chain analysis put the figure slightly higher, at $3.87 million, and traced the drain to the overnight hours between September 30 and October 1. The team said the root cause was a bug in how its Omni deposit-and-withdrawal infrastructure interacted with a NEAR Intents smart contract, language that points to an authorization failure at the boundary between two systems rather than a flaw in NEAR’s base-layer consensus.

Blockchain investigator ZachXBT was among the first to flag the unusual outflows from the protocol’s BNB Chain hot wallet, a detail corroborated by U.Today’s coverage of the disclosure. NEAR Intents responded by halting cross-chain services, patching the contract-side vulnerability, and reporting the incident to law enforcement. The company said its cold wallets and core custody keys were never touched, framing the loss as contained to one operational vault rather than a systemic breach of the protocol.

What NEAR Intents Actually Does

NEAR Intents is a chain-abstraction layer built around an intents-based architecture. Instead of making a user sign a separate transaction for every chain involved in a swap, a user states the outcome they want, for example “swap USDC on Ethereum for USDT on BNB Chain”, and a network of solvers and relayers competes to fill that request. The protocol had processed more than $30 billion in cumulative volume across 35 blockchains before the exploit, according to NEAR Intents’ own published figures, making it one of the larger intents engines operating today.

That convenience comes with a cost. Every intents platform has to connect smart contracts, off-chain solvers, custody wallets, and chain-specific adapters, and each connection point is a place where validation can fail. NEAR Protocol was co-founded by Illia Polosukhin and Alexander Skidanov, with the NEAR Foundation overseeing the wider ecosystem, but NEAR Intents operates as a product layer with its own operational team handling incident response, which is who the public statements on October 1 and 2 came from.

Inside the Omni Integration Bug

NEAR Intents has not published a full technical post-mortem as of October 3, so the precise exploit primitive, whether it was a missing signature check, a replay flaw, or a broken nonce validation, remains unconfirmed. What the company has said is narrower but still telling: the vulnerability sat in the handshake between Omni’s custody and withdrawal system and a NEAR Intents smart contract, and it allowed the attacker to trigger withdrawals that should never have cleared.

That distinction matters for anyone trying to draw lessons from this hack. It was not a stolen private key, like the 2022 Ronin Bridge attack. It was not a forged signature on a message-passing layer, like Wormhole’s 2022 breach. It looks closer to an authorization gap between two systems that were each individually audited but never fully tested together under adversarial conditions, a pattern security researchers have flagged repeatedly as intents and solver-based architectures scale faster than the tooling built to test them.

The 48-Hour Timeline, From First Withdrawal to Patch

The public record does not yet include a minute-by-minute forensic log, but the broad sequence is clear from on-chain data and the company’s own statements. The attacker began pulling funds from the BNB Chain vault late on September 30. By October 1, ZachXBT and other on-chain watchers had flagged the irregular withdrawals, and NEAR Intents paused cross-chain services shortly after. Core website and swap functionality came back online within about an hour, while deposits and withdrawals on the affected networks stayed frozen for roughly 12 more hours while the team finished patching the Omni-side infrastructure.

Eleven networks were taken offline as a precaution during the pause: BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. NEAR Intents has been careful to note that the direct financial loss was confined to the BNB Chain vault holding USDT, and that the other ten networks were disabled defensively rather than because they were independently compromised.

Where the Stolen USDT Went

Bitquery’s tracing, summarized in CoinCentral’s reporting, shows the attacker moved the funds in five major withdrawals after testing the exploit with small transactions first, a common pattern among experienced on-chain attackers probing for detection before committing to a full drain. Roughly 76% of the stolen value was eventually converted into 34.69 BTC, while Bitquery separately reported that about $802,000 moved toward KuCoin deposit addresses. Another on-chain trace put roughly $1.5 million of the stolen USDT flowing through CoW Protocol’s settlement layer at some point during the laundering process.

That fragmented trail, a mix of exchange deposits, swap protocols, and Bitcoin conversion, is standard practice for attackers trying to break the link between stolen funds and their origin before cashing out. It is also exactly the kind of trail that made the next development in this story more surprising.

The Twist: The Attacker Gave It Back

On October 2, NEAR co-founder Illia Polosukhin posted on X that the exploiter returned all of the stolen assets, roughly 24 hours after the NEAR Intents team tracked the attacker down and opened a line of communication, according to CoinDesk’s reporting on the statement. That outcome would make the full-reimbursement pledge the team made on October 1 unnecessary in practice, since the underlying funds came back rather than being paid out of NEAR’s own treasury.

Voluntary fund returns are not unheard of in crypto, Poly Network’s attacker returned most of the roughly $600 million taken in 2021 after public pressure and promises of a bug bounty, but they remain the exception rather than the rule. Whether this attacker returned the money out of fear of being identified, a negotiated bounty, or genuine white-hat intent has not been detailed publicly, and NEAR Intents has not confirmed the exact terms of the exchange.

NEAR Token Takes a Hit, Then Steadies

NEAR’s native token dropped about 6% in the 24 hours following the disclosure, touching a local low near $4.76 before partially recovering to roughly $4.84, based on the most conservative figures across multiple trackers (some outlets reported drops as steep as 7.5%). The Bitwise NEAR ETF, a regulated product tracking the token, fell a comparable amount during the same window. For a token with NEAR’s market capitalization, a sub-$4 million exploit moving the price by mid-single digits reflects how sensitive crypto markets remain to any security headline, regardless of the dollar amount involved.

The price action also illustrates an asymmetry that keeps showing up in 2026: a hack a fraction of the size of the Bitget or Liquid Network breaches still moved NEAR’s price by a similar percentage to what those much larger incidents did to their respective tokens, suggesting the market now treats any confirmed exploit disclosure as a trust event first and a balance-sheet event second.

The Irony Nobody Missed: NEAR’s Own Shield Just Caught a Bigger Hack

Days before its own breach, NEAR Intents’ internal monitoring system had blocked approximately $50 million in suspicious transactions connected to the Bitget exchange hack, which Bitget disclosed on September 24 after attackers exploited a zero-day in a third-party security product used in its environment. NEAR Intents’ infrastructure was one of several routes attackers tried to use to launder the Bitget funds, and the protocol’s defenses caught a meaningful slice of that flow before the money could move further.

That a protocol capable of blocking $50 million in someone else’s stolen funds would, within days, lose $3.8 million of its own to a bug in its custody integration is the kind of detail that security researchers point to when they argue that detection and prevention are different disciplines. Catching laundering attempts after a hack requires pattern recognition across chains. Preventing a hack in the first place requires airtight validation logic at every integration point, and those two capabilities do not automatically come bundled together.

How NEAR Intents Stacks Up Against 2026’s Other Big Hacks

Placed next to the other major incidents from the past six weeks, the NEAR Intents exploit is small in dollar terms but notable for how fast the team moved and for the eventual return of funds. The table below compares the five largest publicly confirmed crypto security incidents from August through early October 2026.

IncidentDateAmountRoot CauseFunds Recovered
Bitget exchange hackSept 24, 2026~$350M-$388MThird-party security software zero-dayPartial, ongoing tracing
Liquid Network hack2026~$320MSidechain validator compromise~85% returned
Drift Protocol exploit2026~$295MNot fully disclosedNot fully disclosed
Kelp DAO / LayerZero rsETH exploit2026~$292M-$293MCross-chain messaging dispute, now in litigationDisputed
NEAR Intents exploitOct 1, 2026~$3.8MOmni custody/withdrawal integration bug100%, returned by attacker

Zooming out further, CoinDesk reported that crypto security incidents hit $768.5 million across 99 events in September 2026 alone, the worst single month of the year, and roughly $1.26 billion across 247 incidents for the third quarter overall. NEAR Intents’ $3.8 million represents a small fraction of that total, but it adds another data point to a year where chain-abstraction and cross-chain infrastructure, not simple phishing or exchange breaches, has driven an outsized share of total losses.

Bridges Have Failed Before, Just Not Like This

Cross-chain infrastructure has a long history of being the softest target in crypto, and NEAR Intents joins a list that includes some of the largest thefts in the industry’s history. The mechanics differ sharply from one incident to the next, which is part of why defending against “bridge risk” broadly is so hard.

Bridge/ProtocolYearApprox. LossFailure Mode
Ronin Bridge (Axie Infinity)2022~$625MCompromised validator private keys
Poly Network2021~$600M+Cross-chain contract access-control flaw
Wormhole2022~$325MSignature verification bypass enabling fake minting
Nomad Bridge2022~$190MMessage-verification flaw allowing fraudulent withdrawals
Multichain2023~$125M+Compromised MPC/validator key control
NEAR Intents2026~$3.8MCustody-to-contract integration/authorization bug

What separates the NEAR Intents case from the Ronin or Multichain playbook is that nobody has alleged a stolen private key or a captured validator set. The failure sits one layer up, in how two pieces of software agreed on what counted as a valid withdrawal, which is arguably a harder problem to fully eliminate because it scales with every new chain and every new integration a protocol adds.

Intents vs. Bridges: A New Attack Surface Hiding in Plain Sight

Traditional bridges lock an asset on one chain and mint a representation on another, concentrating risk in the lock-and-mint contract and whatever validates it. Intents-based systems replace that model with solvers and relayers who compete to fill a user’s requested outcome, which removes some bridge-specific risks (there is often no large pool of locked collateral sitting in one contract) but adds new ones: custody systems, off-chain matching engines, and settlement contracts all have to agree, in real time, on what has and has not been authorized.

Security researchers studying intent-based routing have already documented liquidity exhaustion and timing attacks against these systems in academic analysis published earlier in 2026. The NEAR Intents exploit adds a real-world case to that research: not an exotic liquidity attack, but a far more mundane authorization gap at the exact seam where “chain abstraction” promises to make multi-chain complexity disappear for the end user. The user experience win is real. So is the fact that the complexity did not actually vanish, it just moved behind the scenes, where a single bug can now affect eleven chains’ worth of deposits and withdrawals at once.

The Competitive Field: Across, deBridge and the Race to Make Chains Invisible

NEAR Intents is not operating alone in this category. Across Protocol has emerged as the largest intent-based bridge by volume in 2026, processing more than $35 billion across over 12.4 million transfers with a median fill time of about 8 seconds and a reported 99.7% success rate, using an optimistic verification model rather than locked liquidity pools on both sides. deBridge takes a different approach, using a decentralized validator network and what it calls a zero-TVL design specifically meant to remove the giant honeypot that classic lock-and-mint bridges create, and has processed close to $9.96 billion in volume with median settlement times near 2 seconds.

Alongside NEAR Intents, Across, and deBridge, CoW Protocol, UniswapX, and Anoma round out what industry trackers describe as the five dominant intent-execution engines of 2026. The broader cross-chain infrastructure market is projected to pass $3.5 billion in 2026, inside an industry that now moves more than $1.3 trillion in assets across chains annually. That scale is exactly why a bug like NEAR Intents’, confined to one vault on one chain, can still ripple into a defensive shutdown across 11 networks. When the market grows this fast, the incentive to ship new chain integrations outpaces the incentive to slow down and adversarially test each new connection point.

Why 2026 Is Already Crypto Security’s Worst Year on Record

The NEAR Intents incident is a footnote in dollar terms next to Bitget’s roughly $350 million to $388 million loss or Liquid Network’s $320 million breach, but it fits a pattern that has made 2026 historically bad for crypto security. CertiK and PeckShield’s September figures alone, between $766 million and $768 million lost, mean a single month this year came close to matching some entire prior years of industry-wide losses. CoinDesk’s quarterly tally of $1.26 billion across 247 incidents in Q3 2026 suggests the trend is not slowing as the year closes out.

Part of the shift is structural. More value now moves through intents, solvers, and chain-abstraction layers than through simple wallet phishing, which was the dominant attack category a few years ago. That shift moves the point of failure from individual users to shared infrastructure, meaning a single bug can now affect thousands of users across a dozen chains at once instead of one wallet at a time. NEAR Intents’ defensive pause across 11 networks after a $3.8 million loss on one chain is a direct illustration of that concentration risk.

What Happens Next: Five Predictions for Intents-Based Security

Based on how this incident unfolded and the broader pattern across 2026’s security failures, a few outcomes look likely in the coming months.

  • NEAR Intents will likely publish a full technical post-mortem naming the exact contract function and validation step that failed, following the pattern set by Wormhole and Nomad after their own bridge incidents, both of which eventually released detailed write-ups.
  • Expect other intents and chain-abstraction protocols, including Across, deBridge, CoW Protocol, and UniswapX, to announce expanded bug-bounty programs or third-party audits of their custody-to-contract integration layers specifically, rather than just their core settlement contracts.
  • Insurance and treasury-backed reimbursement commitments, like the one NEAR Intents made on October 1 before the funds were returned, will become a more standard first response to exploits, even when protocols cannot yet confirm whether funds will ultimately be recovered.
  • Regulatory and industry attention on cross-chain infrastructure will keep growing given the scale of 2026’s cumulative losses, with CertiK, PeckShield, and CoinDesk’s running tallies likely to be cited in any policy discussion about DeFi oversight heading into 2027.
  • More attackers may choose to negotiate or return funds voluntarily once identified, following the precedent set by Poly Network in 2021 and now NEAR Intents in 2026, particularly as on-chain tracing tools from firms like Bitquery and investigators like ZachXBT make staying anonymous after a major exploit progressively harder.

None of these are certainties, but they track the direction the industry has moved after every major cross-chain incident since Poly Network in 2021: disclose, patch, promise repayment, and eventually publish the technical details that let the rest of the ecosystem learn from the mistake rather than repeat it.

Frequently Asked Questions

What exactly happened to NEAR Intents?

An attacker exploited a bug in the integration between NEAR Intents’ smart contract and its Omni deposit-and-withdrawal infrastructure, draining roughly $3.8 million in USDT from a BNB Chain vault on October 1, 2026. The team paused cross-chain services on 11 networks, patched the vulnerability, and the attacker later returned the funds.

Did NEAR Intents users lose money permanently?

No. NEAR Intents pledged full reimbursement on October 1, and according to co-founder Illia Polosukhin, the attacker returned all of the stolen assets about 24 hours after the team established contact, making the reimbursement pledge unnecessary in practice.

Which blockchains were affected by the NEAR Intents pause?

NEAR Intents disabled deposits and withdrawals across 11 networks as a precaution: BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. The direct financial loss was confined to the BNB Chain vault.

How does this compare to other 2026 crypto hacks?

It is far smaller. Bitget lost roughly $350 million to $388 million in September 2026, Liquid Network lost about $320 million, and the Kelp DAO/LayerZero dispute involves close to $292 million. NEAR Intents’ $3.8 million loss is a fraction of those totals, and unlike most of them, the funds were fully returned.

What is NEAR Intents and how is it different from a bridge?

NEAR Intents is a chain-abstraction protocol where users state a desired outcome, such as a cross-chain swap, and a network of solvers competes to fulfill it. Unlike classic lock-and-mint bridges, it does not rely on one large pool of locked collateral, but it still depends on custody systems and smart contracts agreeing on what counts as an authorized transaction, which is where this exploit occurred.

Has NEAR’s token price recovered from the exploit?

NEAR’s token fell roughly 6% in the 24 hours after disclosure, touching a local low near $4.76, before partially rebounding to around $4.84. As of early October 2026, the token had stabilized but had not fully returned to its pre-exploit level.

Who found the NEAR Intents exploit?

On-chain investigator ZachXBT was among the first to publicly flag the irregular withdrawals from NEAR Intents’ BNB Chain hot wallet, with blockchain analytics firm Bitquery providing detailed tracing of where the stolen funds moved before they were returned.

Will NEAR Intents publish a technical post-mortem?

As of October 3, 2026, NEAR Intents had not published a full technical breakdown of the exact contract function or validation step that failed. The team has said the contract-side vulnerability was patched and that it would share further details, following the precedent set by other protocols after past cross-chain incidents.