en
Back to the list

NEAR Intents $3.8 Million Exploit: What Users Should Know and Do

source-logo  coinedition.com 1 h
image

$NEAR Intents has reported an exploit on its platform resulting in a $3.8 million loss of users’ funds. According to the report, a bug linked to $NEAR Intents’ Omni deposit and withdrawal system triggered the exploit.

What Happened on the $NEAR Intents Protocol?

The incident was triggered by a smart contract vulnerability sitting directly at the “handoff seam” between two core components—the Omni infrastructure and the $NEAR Intents Smart Contract. Omni infrastructure is the protocol’s underlying multi-chain gateway that manages how token deposits and withdrawals move across external blockchains, while the $NEAR Intents Smart Contract is the core protocol ledger that registers and executes users’ desired cross-chain asset swaps.

The exploit capitalized on a logical bug in the interaction/communication flow between Omni infrastructure and the smart contract. The attacker exploited a breakdown in communication and tricked the smart contract into validating or inflating artificial deposits/withdrawals without providing equivalent collateral, allowing them to drain funds from the platform.

app-logo

Know when your
coins move

Alerts, real-time prices, and market news — all in one app
4.8 based on 40K reviews in the App Store and Google Play

The $NEAR Intents Team Response and Plans

Despite acknowledging the exploit, the $NEAR Intents team has assured users of their funds’ safety. In a statement, the team pledged that all affected user assets will be compensated in full utilizing treasury funds. Meanwhile, the team has patched the main smart contract vulnerability to prevent further losses.

In practice, $NEAR Intents’ compensation promise places the protocol as the issuer, thereby taking full responsibility for the loss rather than repaying only a percentage of lost funds. Therefore, users whose funds are part of the stolen assets would have their internal ledger balances reflect the pre-exploit amount once the team finalizes the accounting adjustments.

As is typical with such attacks, the $NEAR Intents team paused deposit and withdrawal services on the platform after discovering the exploit. However, the protocol is expected to resume full service approximately 12 hours from the time of the official protocol announcement. Having patched the main smart contract vulnerability, all external gateways will face the full 12-hour suspension window while engineers finalize and test repairs on the multi-chain bridge network.

What Should $NEAR Intents Users Do?

Amid the ongoing repair and protocol maintenance, $NEAR Intents users are advised to wait for the official restart before attempting any deposit or withdrawal transactions. Trying to interact with paused or partially restored gateways carries high technical risks, such as trapped transactions, wasted network fees, and system reboots. Therefore, users are advised to hold off on transfers, monitor $NEAR Intents’ official channels for updates, and verify transaction resumption on small amounts after the official resumption announcement.

While waiting for full operations to resume on the $NEAR Intents protocol, users are advised to review their accounts and transaction histories to verify if their funds were affected by the exploit. Checking these specific areas will confirm if a user is eligible for the protocol’s treasury-backed reimbursement. Three crucial steps to take while reviewing include identifying pending or in-transit transactions, verifying internal account ledger balances, and reviewing wallet token approvals.

coinedition.com