NEAR Intents Recovers $3.8M in Full After Cross-Chain Exploit
A bug in the Omni deposit/withdrawal infrastructure interaction with NEAR Intents smart contracts led to a security incident, resulting in the theft of $3.8 million in USDT from a vault on the BNB Chain. The NEAR Intents team identified the preliminary cause of the incident and paused operations to patch the contract-side vulnerability. Within one hour, the team had patched the vulnerability and restored services. The stolen funds were later returned in full, with 76% converted into Bitcoin and distributed into four wallets. The remaining funds were returned via another route, but the identity of the party involved and the tracking methods used remain unknown.
The incident only affected USDT in a vault on the BNB Chain, and NEAR Protocol, the NEAR token, and other applications within the ecosystem were not compromised. The total loss of $3.87 million was concentrated in five major withdrawals over six hours, with most of the damage happening within the first hour. The associated address had executed two test withdrawals worth 10 USDT and 11 USDT on the evening of September 30, but the system successfully processed these requests before the large sums were withdrawn.
The NEAR Intents team initially committed to fully compensating affected users but did not disclose the number of impacted accounts or a payout plan prior to announcing that all stolen funds had been returned on October 2. The project halted its investigation after the funds were returned, with Alex Shevchenko, general manager of NEAR Intents, stating that the team had identified the party behind the exploit and had returned the funds in full.