T
iTokenly

NEAR Intents (Omni deposit and withdrawal bug) hack — October 2026

Verified — 10 sourcesLast checked October 2, 2026

Incident facts

Date of incident
Publicly disclosedOctober 1, 2026
Target typeCross-chain bridge
Loss$3,800,000Price at time of incident
Recovered$3,800,000
MethodContract logic errorA bug in how NEAR Intents' Omni deposit and withdrawal infrastructure interacted with the Intents smart contract let an attacker make irregular USDT withdrawals from the service's BNB Chain hot wallet; NEAR Intents has not yet published the technical report it promised
ChainsBNB Chain
OutcomeFunds returned

What happened

NEAR Intents, a cross-chain trading service in the NEAR ecosystem in which independent market makers called solvers fill users' swaps, lost about $3.8m on 1 October 2026. NEAR Intents said the cause was a bug in how its Omni deposit and withdrawal infrastructure interacted with the Intents smart contract, and NEAR co-founder Illia Polosukhin said the loss was confined to USDT on BNB Chain. The on-chain investigator ZachXBT reported several irregular outflows from the service's BNB Chain hot wallet to a single address, from which the USDT went straight to the exchange KuCoin and was bridged into bitcoin. NEAR Intents' SHIELD monitoring system flagged the activity and the service was paused. The team said it patched the contract-side vulnerability within about an hour, while deposits and withdrawals on eleven networks, including BNB Chain, Polygon, TON and Optimism, stayed closed for roughly twelve more hours until the Omni infrastructure was fixed. The NEAR blockchain and the NEAR token were not affected.

The $3.8m is NEAR Intents' preliminary figure; the detailed report it promised has not been published. It pledged to compensate affected users in full and reported the incident to law enforcement. Early on 2 October its general manager, Alex Shevchenko, said the team had identified the person responsible, published addresses on Bitcoin, on BNB Chain and Ethereum, and on Solana for the funds to be sent back to, and set a 48-hour deadline. He then posted messages addressed to the attacker, encrypted so that only the holder of the theft address's key could read them.

Later on 2 October Shevchenko said the funds had been sent back in full and the investigation was closed, and Polosukhin said the recovery was complete at 14:30 UTC. The Bitcoin return address received 34.59 BTC in four transfers between 14:31 and 15:05 UTC, worth about $2.99m at the time, which this registry read from the chain; NEAR Intents has not said how the rest came back. At 16:15 UTC the theft address on BNB Chain sent the return address a small payment carrying a message that all the funds had been returned and that the sender had been in the wrong. The incident is recorded as funds returned, at the full amount NEAR Intents states. No one has been publicly named.

Sources

  1. NEAR Intents on XPrimary · retrieved 2026-10-02
  2. Alex Shevchenko, NEAR Intents general manager, on XPrimary · retrieved 2026-10-02
  3. ZachXBTSecondary · retrieved 2026-10-02
  4. crypto.newsSecondary · retrieved 2026-10-02
  5. CryptoSlateSecondary · retrieved 2026-10-02
  6. CoinMarketCapSecondary · retrieved 2026-10-02
  7. The Crypto TimesSecondary · retrieved 2026-10-02
  8. CryptopolitanSecondary · retrieved 2026-10-02
  9. Bitcoin return address, read by this registryOn-chain · retrieved 2026-10-02
  10. BNB Chain transaction with the return message, read by this registryOn-chain · retrieved 2026-10-02

Changes to this entry

  • Recorded the day after the exploit, once the funds had been returned. The $3.8m is NEAR Intents' preliminary figure and is recorded as returned in full on its statement; the 34.59 BTC received at its published Bitcoin address, about $2.99m, was read from the chain, and NEAR Intents has not said how the remainder came back.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "NEAR Intents (Omni deposit and withdrawal bug) hack — October 2026", iTokenly, accessed 2026-10-02, https://itokenly.com/hacks/near-intents-omni-october-2026
https://itokenly.com/hacks/near-intents-omni-october-2026

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.