Loading prices…
🩸BEARISH

NEAR Intents Loses $3.8M in Exploit, Pauses Services

A patch and reimbursement pledge address the immediate losses, but deposits and withdrawals remain restricted on several networks.

NEAR Intents Loses $3.8M in Exploit, Pauses Services
NEAR Intents Loses $3.8M in Exploit, Pauses Services
NEAR Intents Loses $3.8M in Exploit, Pauses Services
NEAR Intents Loses $3.8M in Exploit, Pauses Services

NEAR Intents suffered an exploit Thursday that caused about $3.8 million in losses, prompting the cross-chain trading platform to pause services and restrict deposits and withdrawals on several blockchains. The project traced the incident to a bug in how its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract. It said the contract-side vulnerability has been patched and pledged to reimburse affected funds in full.

Why it matters

NEAR Intents lets users specify a cross-chain swap while independent market makers, called solvers, compete to complete it behind the scenes. Its website says it has processed more than $30 billion in volume across 35 blockchains. A fault in the deposit and withdrawal system therefore disrupts the part of the service that moves assets between networks.

The incident follows several larger crypto security breaches. DefiLlama data cited in the report put recent losses at more than $350 million for Bitget, about $320 million for Liquid Network, $295 million for Drift and $293 million for Kelp.

Market impact

NEAR Intents expected core services to resume quickly, but said deposits and withdrawals on several networks would remain unavailable longer while fixes were completed. Its status page showed issues affecting BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma.

The project reported the incident to law enforcement and enlisted security and blockchain analytics firms to trace the funds. Investigator ZachXBT said irregular withdrawals began at a BNB Chain hot wallet linked to NEAR Intents, with stolen funds later sent to KuCoin and converted into Bitcoin. The immediate question for users is when affected deposit and withdrawal routes reopen.

Related tokens
$NEAR $BTC

Frequently asked questions

  1. What caused the NEAR Intents exploit?

    NEAR Intents attributed it to a bug in how its Omni deposit and withdrawal system interacted with the NEAR Intents smart contract. The project said the contract-side vulnerability has been patched.

  2. Will users affected by the NEAR Intents exploit be reimbursed?

    NEAR Intents pledged to reimburse affected funds in full.

  3. Which NEAR Intents services remain restricted?

    Deposits and withdrawals on several blockchains were restricted while fixes were completed. NEAR Intents expected core services to resume sooner than those routes.

  4. Why does a deposit and withdrawal bug matter for cross-chain swaps?

    NEAR Intents uses independent market makers, called solvers, to complete swaps across networks. The affected system handles deposits and withdrawals needed to move assets between those networks.

  5. What happened to the funds stolen from NEAR Intents?

    Investigator ZachXBT said the funds were sent to KuCoin and converted into Bitcoin. NEAR Intents said it reported the incident to law enforcement and enlisted firms to trace the funds.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 58m ago
Open original →