Skip to content

Invest4 publishers2 min readPublished Updated

Attacker drains $3.8 million from Near Intents via bug in Omni deposit and withdrawal layer

Near Intents halted its cross-chain swap service after a bug in its Omni deposit layer let an attacker take about $3.8 million. Crypto balances carry no deposit insurance, so affected users are relying on the operator's promise to repay them in full.

The Investor · Invest desk

Illustration accompanying Attacker drains $3.8 million from Near Intents via bug in Omni deposit and withdrawal layer
Generated illustration

What happened

  • Blockchain investigator ZachXBT traced the stolen funds to the KuCoin exchange, from where they were bridged to bitcoin.
  • Near Intents says the contract-side hole is patched and core services return in about an hour, but deposits and withdrawals on 11 networks stay shut for roughly 12 more hours.
  • Two days before the drain, Near Intents had blocked a $50 million swap by the Bitget hacker and frozen more than $500,000 tied to that $388 million theft.
  • The team has reported the incident to law enforcement and says a detailed public report will follow in the coming days.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Buyers of Bitwise's Near ETF, two days old at the time, saw its shares fall more than 7% on a loss at one swap service tied to the network.
  • exposure The power to block and freeze flows that helped Bitget means Near Intents users are trusting an operator's judgement and solvency, in addition to its code.
  • precedent If Near Intents does pay the $3.8 million itself, it sets an expectation that cross-chain swap operators, and not their users, absorb losses in the layer that moves funds between chains.

Near Intents fills orders by having rival market makers compete to quote prices [12]. The attacker went in at the edge of the system, where deposits arrive and withdrawals leave. "The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract," the team posted on X [2]. Decrypt, reporting the drain, wrote that "Moving value between blockchains means pooling money in the middle, and pools attract thieves" [13]. Its reference case is the 2022 Harmony bridge hack, at about $100 million [14].

By size this one is small. Near Intents says it has handled more than $30 billion of swaps across 35 blockchains [12], so the $3.8 million taken [1] is at most about 0.013% of lifetime volume, a little over one basis point [1]. Harmony lost roughly 26 times as much [2]. Decrypt gave two readings for the NEAR token, a 6.7% fall to $4.96 [9] and an 8.93% fall to $4.86 [10]. Both imply a starting price near $5.33 [3], so they look like two snapshots of the same slide. Even at the lower figure the token sits about 86% above the $2.61 it traded at when Bitwise filed for its ETF in April 2025 [11] [4].

Three outcomes are open. The promised report [16] could show a narrow integration error, with affected users repaid in full within days, in which case the pledge was as good as cash. Repayment could instead come slowly or only in part, leaving those users as unsecured creditors of the operator. Or the drain could turn out to be linked to the Bitget hacker Near Intents turned away two days earlier, though Decrypt reported that no link is clear [6] and the North Korea attribution from Bitget CEO Gracy Chen and Elliptic is unconfirmed [8].

In my view users should assume the second case until the report arrives, though a contract fix already in place [5] is a point for the first. Near Intents has not disclosed whose funds were taken [15] or what will pay for its pledge that the losses "will be compensated in full" [4]. A repayment promise with no named source of money is a claim on the same operator whose contracts lost it. The view is wrong if the report names the affected accounts and shows them paid in full, from reserves Near Intents can identify, within days of publication.

What to watch

  • Whether Near Intents' detailed report names the affected accounts and the source of the money for repayment.
  • Whether deposits and withdrawals on BNB Chain, Polygon, Optimism and the other paused networks reopen on the roughly 12-hour schedule.
  • Whether tracing of the funds through KuCoin connects this attacker to the Bitget hacker, a link Decrypt says is not yet clear.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories