Particle.news

NEAR Intents Recovers $3.8M After Omni Integration Exploit

The incident's recovery after an Oct. 1 exploit highlights weak points in cross‑chain middleware.

Overview

  • A bug in NEAR Intents' Omni deposit and withdrawal integration let an attacker drain about $3.8 million of primarily USDT from a BNB Chain treasury, with the activity first detected by the platform's SHIELD monitoring system.
  • NEAR Intents patched the contract vulnerability within about an hour and temporarily paused deposit and withdrawal routes on 11 networks while it completed broader Omni fixes.
  • Investigators traced the outflows through a BNB Chain hot wallet to KuCoin and into bitcoin, the team publicly set a 48‑hour deadline for return of the funds, and the suspected entity returned the full $3.8 million with the probe closed on October 4.
  • The disclosure and pause knocked NEAR token prices down roughly 6–10% and tested investor confidence just after Bitwise launched a NEAR ETF, showing how application‑level failures can ripple into markets.
  • NEAR Intents has pledged full compensation to affected users, will publish a post‑mortem and pursue formal verification and other security upgrades to harden cross‑chain operations going forward.