NEAR ecosystem protocol NEAR Intents suffered an exploit on Oct. 1 that drained about $3.8 million from its underlying treasury, sending NEAR sharply lower in intraday trading.
According to the source article, the token fell from around $5.5 to about $4.74 at one point, marking a drop of roughly 6% to 8% after the security incident came to light.
The breach did not hit the NEAR mainnet itself. NEAR founder Illia said the affected system was NEAR Intents, a cross-chain intents protocol built on NEAR, not the NEAR Layer 1 consensus layer. The core protocol and the security of the native token were described as unaffected.
A sharp reversal after a recent security success
The article framed the exploit as a dramatic turn over a 48-hour window. Just days earlier, after the Bitget exchange hack, attackers had tried to route more than $50 million in illicit funds through NEAR Intents.
Its AI-powered security monitoring layer, SHIELD, detected the activity and froze part of the funds. The report said about $503,000 was successfully frozen during execution, around $166,000 made it through, and most of the remaining transfer attempts were rejected.
That episode briefly turned NEAR Intents into a showcase for cross-chain defense. The latest exploit, though, came from a different direction: not a direct assault on the protocol’s core logic, but a flaw in the contract logic tied to the underlying deposit and withdrawal path.
The exploit targeted the Omni interaction layer
The source article said the attacker exploited a logic vulnerability in the interaction between Omni deposit-and-withdrawal infrastructure and NEAR Intents contracts. The damage was confined to a USDT asset pool on BNB Chain.
Roughly 3.87 million USDT was withdrawn in a short period, after which the funds were quickly moved to exchanges and converted into Bitcoin, according to the report.
Based on the disclosed details, the issue sat in the cross-chain infrastructure layer around treasury movement and deposit-withdrawal interfaces, rather than in NEAR’s base-layer consensus security.
Team says it patched the issue within one hour
The team said it identified the specific vulnerability and completed a hotfix within one hour of detecting the abnormal activity.
It also suspended deposit and withdrawal functions on 11 networks involved in the Omni-related fix, including BSC, Polygon and Avalanche, for about 12 hours while conducting isolation and security checks.
Most notably, the project said all affected users would receive 100% compensation.
Market reaction focused on the size of the loss and protocol exposure
The security incident quickly spilled into the secondary market. The article described the sell-off as a short-term reaction after a strong September rally in NEAR.
It pointed to two drivers behind that earlier move: the launch of the "Confidential Intents" narrative and expectations being realized around the listing and trading of a Bitwise spot NEAR ETF in the U.S.
With a large amount of profit already built up, the report argued that the market had room for a technical pullback even before the exploit.
Monthly processing volume was cited at more than $4 billion
NEAR Intents has disclosed monthly transaction and payment processing volume of more than $4 billion, according to the article. On that basis, the roughly $3.8 million exposure represented less than 0.1% of total throughput.
The report added that because the team committed to full reimbursement, the loss would be absorbed internally rather than spilling into a broader DeFi lending unwind or a bad-debt spiral.
Cross-chain "seams" are back in focus
The article used the incident to revisit a broader issue in crypto infrastructure: the security paradox around "bridge-less" design and cross-chain execution.
Bankless co-founder David Hoffman said centralized exchange hacks and cross-chain bridge vulnerabilities have historically been the two biggest sources of losses in crypto. In his view, the NEAR team’s ability to patch the issue within hours and promise full reimbursement showed strong engineering capability.
The article also cited crypto researcher Warden, who said, "No matter how perfect the outer wrapper is, the cross-chain seams remain the scariest place."
In intents-based systems, complex cross-chain actions are abstracted away from users and handled by solvers in the background, creating a front-end experience closer to that of a centralized exchange. But final settlement and asset mapping across heterogeneous chains still depend on underlying treasuries and deposit-withdrawal interfaces.
Those seams, the article argued, remain prime targets. SHIELD AI may catch suspicious external fund flows, but low-level contract logic flaws can still open the treasury to attack.
Three points to watch next
The source article said the next checkpoints are straightforward: whether the promised roughly $3.8 million in compensation is fully paid, whether the 11 suspended chains resume interaction after the stated 12-hour window, and whether the postmortem can rule out additional risks in other on-chain interaction paths at the architectural level.
As presented in the report, the confirmed impact was limited to the cross-chain asset pool tied to NEAR Intents, not the NEAR mainnet itself.

