Particle.news

NEAR Intents Recovers $3.8M After Exploit

Investigators traced withdrawals from a BNB Chain treasury through KuCoin, a public 48‑hour deadline preceded the full return, highlighting concentrated risk in pooled multi‑chain swap infrastructure.

Overview

  • NEAR Intents was exploited on Thursday, October 1, 2026, when a bug in the Omni deposit/withdrawal integration let an attacker withdraw roughly $3.8 million, mostly USDT from a BNB Chain treasury.
  • The protocol’s SHIELD AI detected the irregular activity, teams paused services and patched the smart‑contract interaction vulnerability within about an hour, and deposits and withdrawals on eleven networks were temporarily restricted while fixes continued.
  • On October 2 the team publicly identified suspected addresses, posted three recovery wallets and gave a 48‑hour deadline, after which investigators traced flows through a BNB Chain hot wallet, KuCoin and a bitcoin bridge and the attacker returned the full amount.
  • NEAR Intents says it will reimburse affected users in full, has closed its investigation, and plans a detailed post‑mortem plus contract‑level hardening such as formal verification and tougher monitoring.
  • The incident underscores how pooled, middle‑layer cross‑chain systems concentrate risk while also showing that on‑chain tracing and exchange cooperation can enable rapid fund recovery and law‑enforcement engagement.