Cross-Chain Protocol Suffers $3.8 Million Security Breach
NEAR Intents disclosed a $3.8 million exploit resulting from a bug in its Omni deposit and withdrawal system that allowed unauthorized access to user funds. The protocol has patched the vulnerability, committed to compensating affected users, and is working with law enforcement and blockchain investigators to trace and recover the stolen assets. Blockchain tracking firm ZachXBT identified the funds moving through KuCoin to the Bitcoin network, though the attacker's identity remained unknown.
The vulnerability stemmed from a flaw in how NEAR Intents' smart contract managed the interaction between its cross-chain deposit and withdrawal infrastructure. This allowed attackers to gain unauthorized access to customer assets stored within the system. Following discovery, the protocol moved quickly to implement a fix and pledged to restore all lost funds to affected users.
Law enforcement agencies and specialized blockchain analysis firms have begun investigating the incident. Tracking data shows the attacker moved stolen cryptocurrency through KuCoin exchange before converting portions to Bitcoin, a common obfuscation technique. Despite these forensic efforts, the perpetrator's identity and motivations remained undetermined at the time of disclosure.
This exploit could undermine confidence in cross-chain protocols, which depend on user trust to transfer assets across blockchain networks. Investors and traders may become more cautious about utilizing these services, potentially slowing adoption of multi-chain solutions. The incident may also prompt increased regulatory scrutiny of cryptocurrency infrastructure and accelerate demand for enhanced security audits and insurance products to cover such vulnerabilities.