The NEAR Intents exploit cost the cross-chain protocol about $3.8 million in USDT on BNB Chain, and it landed barely a week after the same team publicly refused to help the Bitget hackers move their loot. NEAR Intents says a bug has been patched, users will be paid back in full, and the NEAR blockchain itself was never touched.

What happened
NEAR Intents confirmed the loss on Thursday, October 1. It blamed "a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract." In plain terms, the flaw sat at the handoff between two components. Omni is the gateway that moves deposits and withdrawals across outside blockchains. The NEAR Intents contract is the ledger that records and executes swaps. Neither piece was necessarily broken alone, but the way they talked to each other was.
On-chain data reviewed by Unchained shows the drain began on Wednesday afternoon. Two tiny test transfers of 10 and 11 USDT went out first. Five much larger ones followed, from 35,000 USDT up to 1.5 million USDT. In all, about 3.87 million USDT left a BNB Chain contract in roughly six hours, and the receiving address passed almost everything onward within minutes. Unchained noted that NEAR Intents' own documentation lists that contract as the HOT Bridge treasury address on BNB Chain.
Investigator ZachXBT traced the stolen money from the BNB Chain hot wallet to the KuCoin exchange, where it was swapped into Bitcoin. Nobody has publicly attributed the attack to a specific group, and NEAR Intents has not said it is connected to the Bitget breach.
What the NEAR Intents exploit actually hit
Cofounder Illia Polosukhin said the damage was limited to USDT on BNB Chain (BSC). The NEAR core protocol, the NEAR token and other applications built on it were not affected.
The response was quick on the technical side:
The contract-side flaw was patched within about an hour of detection.
Core services and near.com were expected back within roughly an hour, and Polosukhin later said both had been restored.
Deposits and withdrawals on 11 networks were frozen for about 12 more hours while the Omni infrastructure was repaired. The list included BSC, Polygon, Optimism, TON, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma.
Some affected networks were still restricted after the main service came back.
A post-mortem has been promised in the coming days, and the case has been referred to law enforcement.
The team also posted three addresses and gave the attacker 48 hours to return the funds, according to The Defiant as relayed by Crypto Briefing. Affected users will be compensated in full.
The Bitget connection
The timing is what made this story travel. After the September 24 Bitget breach, which cost the exchange about $387.5 million, NEAR Intents general manager Alex Shevchenko said the attackers tried to push more than $50 million through the protocol. Almost none of it went through. By his estimate, about $166,000 was processed, $503,000 was frozen mid-swap, and the rest was refused outright, with much of that routed to other providers.

NEAR Intents also said it would waive the 5% freeze and 5% recovery bounties that Bitget is offering, so more money could return to the exchange. That stance drew pushback from people who argue that open protocols should stay neutral. Shevchenko rejected that, writing that "permissionless doesn't mean neutral."
Whether the two events are linked is unknown. Treat the timing as a coincidence until the team's post-mortem says otherwise.
Market reaction
The NEAR token slipped on the news. Reports put the drop anywhere from about 6% to 10% depending on the source and the moment measured, with prices around $4.76 to $4.95. Bitwise's spot NEAR ETF, which had launched only two days earlier, fell about 6.4% and gave back its opening gains, per Cryptopolitan.
Context helps here. Cryptopolitan cites Q3 losses of about $1.26 billion across 247 incidents, with Bitget alone making up roughly 31%. Against that, $3.8 million is small.

Bitnxt's view
We would not file this under "minor." The money is small, but the lesson is not.
The bug did not live in a swap algorithm or a token contract. It lived in the plumbing between a custody gateway and a smart contract. Cross-chain products depend on exactly that kind of seam, and seams are where audits tend to look least. NEAR Intents says it routes more than $30 billion in volume across 35 blockchains, based on its own website figures reported by Cryptopolitan. A protocol at that scale carries real responsibility for the handoffs.
The team deserves credit for a fast patch, a full-refund promise and a clear explanation of the root cause. We would still like to see how long the gap really was between the first outflows on Wednesday and the public confirmation on Thursday, and the promised post-mortem should answer that. If the exploit is as contained as described, the report should be short and specific.
There is also an uncomfortable irony. A protocol that took a hard public line on stolen funds then lost funds itself. We do not read that as a verdict on its security work, because attackers shop for weak spots everywhere, and a prominent refusal to launder stolen money can make a project more visible. But it is a fair reminder that having a strong risk-screening layer for incoming funds does not protect the infrastructure underneath.
What users should do
Use only the official NEAR Intents and near.com channels for updates. Expect scammers to send fake "compensation" links.
Do not sign anything or connect a wallet because a message about a refund asked you to.
If you had a pending BSC USDT deposit or withdrawal, wait for the team's compensation process instead of retrying the transaction.
What to watch next
The post-mortem and its root-cause detail
Whether the 48-hour return window produces any movement from the attacker's addresses
When the remaining restricted networks fully reopen
Whether on-chain tracing ties the stolen funds to any known group
This article is for information only and is not financial advice.







































.jpg)





