NEAR Intents has restored most trading operations after a security incident produced a preliminary loss estimate of approximately $3.8 million and forced the cross-chain service to halt activity. According to the project’s official October 1 disclosure, the incident originated from a bug in the interaction between its Omni deposit and withdrawal infrastructure and a NEAR Intents smart contract. The affected security boundary was the cross-chain deposit and withdrawal stack, not the underlying NEAR blockchain itself.
The team said it stopped services after detecting the breach, patched the contract-side vulnerability and committed to compensating the affected funds in full. It also reported the incident to law enforcement and began working with security and blockchain analytics firms to trace the assets. The $3.8 million figure remains preliminary, and NEAR Intents has not yet published its promised detailed post-mortem or a final accounting of recoveries and reimbursements.
Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.
The preliminary report indicates the total loss of…
— NEAR Intents (@near_intents) October 1, 2026
Omni Infrastructure Delayed Full Cross-Chain Recovery
The initial restart followed two separate tracks. NEAR Intents and near.com were expected to resume general operations within roughly one hour of the disclosure, while deposits and withdrawals on BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, ADI, Scroll and Plasma were expected to remain unavailable for around 12 additional hours while Omni-side repairs continued. Patching the vulnerable contract therefore did not immediately restore every deposit and withdrawal route that depended on the affected infrastructure.
Users already holding assets from those networks inside NEAR Intents were told they could swap them into other supported assets once trading resumed, even while the corresponding deposit and withdrawal rails remained unavailable. The team later said trading had restarted across most networks. That phased recovery distinguishes execution inside NEAR Intents from the external infrastructure required to move assets into and out of individual chains.
The incident resembles other failures where infrastructure surrounding a protocol became the effective attack surface. In July, an Across Protocol Solana exploit exploited off-chain relayer software that interpreted fabricated Solana events as legitimate deposits. Across said its smart contracts and Solana itself were not compromised. Both cases illustrate how cross-chain systems can inherit critical security dependencies from software operating between otherwise functioning blockchain components.
Security Boundary Matters More Than the Cross-Chain Label
That distinction is also visible in the recent Chainflip TRON USDT exploit, where incorrect memo processing generated six unauthorized payouts totaling 736,442.17 USDT without compromising TRON or Tether’s USDT contract. Cross-chain infrastructure can fail at deposit parsing, routing, validation or settlement without implying that the connected base networks have been breached.
The same principle applies to other DeFi incidents with very different root causes. Ostium’s $23.75 million incident involved oracle and settlement infrastructure, while the recent FlashLoopAdapter exploit affected an external Safe module rather than Aave V3 itself. Identifying the compromised component is essential because “protocol exploit” can otherwise obscure whether the failure sits in core contracts, bridges, modules, relayers or external data systems.
NEAR Intents has pledged full compensation, but that promise should remain distinct from completed reimbursement. No public breakdown currently specifies the funding source, amount already repaid to users or final unrecovered balance. The immediate technical vulnerability has been patched and most trading has resumed, while the remaining material questions concern full cross-chain restoration, asset recovery and the final financial accounting that the promised post-mortem should clarify.
