NEAR Intents Hack Exposes Cross-Chain Security Risks
A recent security incident has rocked the NEAR ecosystem, with an attacker draining around $3.87 million in USDT from a NEAR Intents-linked BNB Chain vault. The attack, which occurred on October 1, targeted the interaction between the protocol's Omni deposit and withdrawal infrastructure and its smart contract. NEAR Intents has identified the vulnerability and promised to compensate affected users in full.
The attacker, who appeared to have prepared in advance, made several small test transactions before launching the main attack. The funds were then routed through various exchanges and swap infrastructure, with a significant portion being converted into Bitcoin. Approximately 76% of the stolen value, around $2.94 million, was held across four Bitcoin addresses, while $802,000 was sent to KuCoin deposit addresses.
The attack highlights the challenges of securing cross-chain systems and the need for more advanced monitoring and detection mechanisms. NEAR Intents has emphasized that the vulnerability existed in the interaction between its Omni deposit-and-withdrawal infrastructure and its smart contract, rather than in the NEAR blockchain itself.
The incident is the latest in a series of high-profile attacks on the cryptocurrency ecosystem, including the Bitget breach and the MetaMask staking incident. It serves as a reminder of the importance of robust security measures and the need for ongoing vigilance in the face of evolving threats.