Blockchain Swap Service Suffers $3.8M Theft From Security Flaw in Smart Contracts

NEAR Intents, a cross-chain swap service, disclosed a security breach on October 1 that resulted in attackers stealing $3.8 million from its BSC hot wallet by exploiting a bug in its Omni infrastructure interaction with smart contracts. The company rapidly patched the vulnerability and suspended deposits and withdrawals across multiple networks for approximately 12 hours while working with security partners and law enforcement. NEAR Intents committed to fully reimbursing affected users for the stolen funds.
NEAR Intents experienced a targeted attack that exploited a gap in how its cross-chain infrastructure communicated with underlying smart contracts. The vulnerability specifically affected the Omni layer responsible for managing asset transfers across multiple blockchain networks. The incident demonstrated how even established platforms remain exposed to technical failures in their architectural components, particularly where different systems must coordinate seamlessly.
The attackers demonstrated sophisticated operational security by rapidly converting stolen assets into Bitcoin through KuCoin, a common pattern in cryptocurrency theft cases. This swift conversion to a more difficult-to-trace asset reflects how quickly bad actors can move to obscure fund flows. The company's decision to implement a 12-hour network-wide suspension rather than immediately reopening services suggests a cautious approach to preventing copycat exploits or detecting secondary vulnerabilities.
The incident may amplify concerns among cryptocurrency users about the safety of cross-chain services, which require complex technical coordination and thus create additional points of failure. Users holding assets on multi-chain platforms could face pressure to reassess risk exposure, potentially reducing liquidity in newer or smaller swap protocols. However, NEAR Intents' quick patching and reimbursement commitment may help limit broader market confidence loss, though similar breaches at other platforms could contribute to longer-term skepticism about decentralized finance infrastructure security.