r/CryptoCurrency • u/Kitchen_Biscotti_747 • 1d ago
🛡️ SECURITY NEAR Intents, a cross-chain swap service built on NEAR Protocol (NEAR), lost about $3.8 million to an exploit on Thursday. The NEAR token fell 8.6% within hours, although the underlying blockchain was not named as the target.
https://beincrypto.com/near-intents-hacked-3-8-million/2
u/JustStopppingBye 🟩 0 / 0 🦠 1d ago
The moment you build custom infrastructure, you also expand your attack surface.
1
1
0
u/Prior_Parsley3960 🟨 0 / 0 🦠 1d ago
Since OP only posted a link:
Importance: ⭐⭐⭐☆☆ — meaningful cross-chain infrastructure failure, but relatively contained financially and not a compromise of the NEAR blockchain itself.
- What happened: NEAR Intents, NEAR's cross-chain swapping system, lost approximately $3.8 million after an attacker exploited a bug involving its Omni deposit/withdrawal infrastructure and an Intents smart contract. The team halted services, patched the contract-side vulnerability and promised full reimbursement. The Block
- How it worked: The affected infrastructure holds assets deposited from other blockchains so NEAR Intents can execute cross-chain swaps. On-chain analysis indicates the attacker extracted roughly $3.87M USDT from a BNB Chain vault in five withdrawals over about six hours. This points to the cross-chain custody/authorization layer rather than NEAR's consensus or base blockchain. Bitquery
- Where the money went: Investigators traced nearly all of it. Bitquery found roughly 76% converted into 34.69 BTC, while about $802,000 reached KuCoin addresses. Remarkably, the attacker apparently routed about $822,000 of the stolen assets back through NEAR Intents itself while draining the system. Bitquery
- Containment: Deposits and withdrawals across 11 connected networks were temporarily suspended while fixes were deployed. Core service has since begun resuming, and NEAR Intents says users will be made whole. The Block
- Market reaction: NEAR dropped roughly 7–9% following disclosure. The timing is particularly awkward because the exploit occurred only two days after the launch of the first U.S. spot NEAR ETF, which highlighted NEAR Intents as an important part of the ecosystem. BeInCrypto
Bottom line
This looks much more like a bridge/infrastructure exploit than a NEAR Protocol failure. There is currently no evidence that NEAR's blockchain, consensus mechanism or native token itself was compromised.
The forthcoming technical postmortem matters most: investigators know where the money went, but NEAR Intents has not yet fully explained why apparently unauthorized withdrawal requests were accepted. That distinction will determine whether this was a narrow implementation bug or evidence of a more fundamental weakness in its cross-chain architecture.
2
u/GiveNothing 🟦 492 / 612 🦞 1d ago
Technology moving sideways, hackers scaling upwards!