On Thursday, the service for Near Intents was shut down after an attacker took roughly $3.8 million from it. The team behind the project says the issue came from a problem in how its Omni deposit and withdrawal layer connected with the main smart contract.
“Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract,” the team posted on X.
“The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery.”
Two days after Near Intents stopped a $50 million swap move from the Bitget hacker, a new exploit has emerged. The attacker took roughly $387.5 million from the crypto exchange just last week. Whether the two incidents are connected remains unclear.
What Went Wrong
The issue sat within the middle layer itself, which connects different blockchains and stands between users and rival market makers who compete to fill their orders.
An error allowed an assailant to take roughly $3.8 million from the system, according to on-chain investigator ZachXBT, who claims the proceeds were transferred to KuCoin and then moved across to bitcoin.
According to the team, the contract-side issue has been resolved and core services are expected to come back within roughly an hour. However, deposits and withdrawals on 11 networks, which include BNB Chain, Polygon and Optimism, will remain paused for around 12 more hours until the Omni fixes are complete.
The lost funds, it says, “will be compensated in full.”
The Recent Hack That Got Stopped
Just two days before, Near Intents had stopped a swap worth $50 million that came from the Bitget hacker. That hacker took around $387.5 million from the exchange last week.
Elliptic and Bitget CEO Gracy Chen both identified North Korea as the probable actor behind the exchange’s hack, citing distinct signals. Neither claim has been verified.
The sequence is striking: on one day Near Intents apprehends a notorious thief, and on the very next, it falls victim to its own breach.
The Token Falls Again
Before the event took place, Near was enjoying a run of success. The Bitwise Near ETF, which allows ordinary investors to bet on a token through a regular brokerage account, went live two days before the incident.
NEAR, the network’s native token, fell 6.7% to $4.96 following the exploit. The ETF shares dropped more than 7%.
The paperwork for the fund was first filed by Bitwise in April 2025, at a time when NEAR was trading at $2.61. Since then, the token’s price has nearly doubled.
There is no deposit insurance for crypto balances like there is for money kept at a bank. This is why the repayment pledge holds such importance.
A detailed report is promised by Near Intents, with publication expected in the coming days.
Why Middle Layers Are the Weak Spot
Pooling money is what happens when value moves between blockchains, and it draws thieves to the center.
One notable case involves a major loss tied to the Harmony bridge hack, which occurred in 2022, with roughly $100 million vanishing as a result.
Across 35 blockchains, Near Intents has managed over $30 billion in swaps, though no word yet on which users’ funds were lost.
| Incident | Amount Lost | Timing |
|---|---|---|
| Near Intents hack | $3.8 million | Thursday |
| Bitget hack | $387.5 million | Last week |
Two attempts were presented back to back. One came to a halt; one made it past.
What This Means for Users
Whether the fixes will last is the question at hand. Near Intents reports that core services resume within about an hour, while deposits and withdrawals on 11 networks remain down for roughly 12 more hours.
Law enforcement has been contacted by the team, and the funds are being traced. The pledge to make good on the loss remains in effect.
Within the last couple of days, the NEAR token has declined significantly on two separate occasions. The ETF shares mirrored the token’s descent each time.
Near Intents has two separate incidents under investigation, and the question is whether they are connected. The team has not confirmed any link between them.
At the moment, the firm is applying fixes, tracking down the source of the problem and vowing to release a thorough account of what happened.
Source material: “Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker,” Decrypt.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

