Friday, October 2, 2026 · Digital Edition
BTC $71,240.00 +2.14%ETH $3,412.00 -0.86%SOL $168.90 +4.32%BNB $612.40 +1.05%XRP $0.612 -1.42%DOGE $0.184 +6.71%ADA $0.441 +0.12%AVAX $38.20 +1.88%LINK $14.60 +3.02%DOT $6.14 -1.11%
Times of Crypto EraSubscribe
← BackHome/DeFi/NEAR Intents Exploit Costs $3.8M, Users To Be Repaid
DeFi

NEAR Intents Exploit Costs $3.8M, Users To Be Repaid

10/02/2026•3 min read
NEAR Intents logo above a broken bridge with a warning shield and falling coins, featured image for the NEAR Intents exploit
NEAR Intents Exploit Costs $3.8M, Users To Be RepaidSource: Times of Crypto Era

The NEAR Intents exploit cost the cross-chain swap platform about $3.8 million on October 1, 2026. In a post on X, the NEAR Intents account said services were stopped after a security incident. The cause was a bug in how the Omni deposit and withdrawal infrastructure interacts with the NEAR Intents smart contract. Users will be repaid in full.

What NEAR Intents Confirmed

The team called its loss figure preliminary. Core services were due back within about an hour, once the contract-side flaw was patched. Eleven networks stayed down for roughly 12 more hours while Omni fixes finished. Those were BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma.

The incident was reported to law enforcement. Per the same post, the team is working with security and analytics partners to trace the money. A detailed report is due in the following days.

NEAR Intents post on X announcing the security incident, October 1, 2026

NEAR Intents on X, October 1, 2026.

NEAR co-founder Illia Polosukhin added his own account in a separate post. SHIELD, the AI security layer on Intents, spotted outlier behavior and the service was paused. DefiLlama's hacks tracker lists the NEAR Intents exploit on BSC and tags it a bridge logic flaw.

A Message To The Attacker

Things moved fast. Early on October 2 (UTC), Alex Shevchenko, general manager of NEAR Intents, wrote that the team had identified the person responsible. His post lists return addresses for Bitcoin, BNB and Ethereum, and Solana.

Alex Shevchenko post on X addressing the attacker, October 2, 2026

Alex Shevchenko on X, October 2, 2026.

The rest of the message is cut off in the embed. Cointelegraph quoted it as giving 48 hours to return the funds under responsible disclosure, after which that window closes. We could only confirm the opening lines on X directly.

Days earlier, the platform was in the news for blocking stolen money. Wu Blockchain relayed on September 28 that Shevchenko said attackers behind the Bitget hack tried to move more than $50 million through NEAR Intents. Its SHIELD risk system flagged those flows, and the team waived its share of the recovery bounty. Shevchenko laid out the details in an X article, and our earlier Bitget hack report covers the original theft.

What The Exploit Leaves Open

Plenty remains open. What we read gives a preliminary loss figure and a cause in broad strokes. Stolen assets, wallet addresses and transaction hashes aren't published, and the promised full report still hasn't shown up.

The deadline matters too. If the 48 hours count from his post at 00:18 UTC on October 2, the window closes around 00:18 UTC on October 4. That is our own arithmetic, not a date the team has stated. Whether the attacker answers, and whether funds come back, will shape how much of the $3.8 million the team ends up covering itself.

NEAR Price Around The Exploit

Check CoinGecko's hourly data and NEAR was sitting near $5.49 at 06:00 UTC on October 1. Seventeen hours later, at 23:00 UTC, it had slid to around $4.78, roughly 12.8% lower. Roughly half of that slide came before the team's 12:53 UTC post, so timing alone proves little. At 16:31 UTC on October 2 the token sat near $4.83. The posts we read place the flaw in Intents and Omni, not in the NEAR chain itself.

This article is not investment advice. Crypto prices swing hard, and one day of trading says little about what comes next.

Related News