Targeted_Comm
Relay_Station / Zone_39
TECH 03.10.2026

NEAR Intents Recovers $3.8M Following Cross-Chain Exploit on BNB Chain

A $3.8 million exploit targeting NEAR Intents’ cross-chain trading system saw a dramatic turn this morning, with the attacker returning the entirety of the stolen USDT roughly 24 hours after the initial breach. The incident, first disclosed on October 1, 2026, highlighted persistent vulnerabilities in complex multi-chain architectures, specifically in the interaction between smart contracts and bridging infrastructure. The rapid restitution, confirmed by NEAR co-founder Illia Polosukhin, offers a rare outcome in an increasingly volatile security landscape.

The exploit originated from a critical bug within the integration layer connecting NEAR Intents’ smart contract to its Omni deposit-and-withdrawal infrastructure. On-chain analysis by Bitquery placed the precise amount drained at $3.87 million in USDT from a BNB Chain vault, occurring overnight between September 30 and October 1. This technical flaw represented an authorization failure at the boundary between the two systems, not a compromise of NEAR Protocol’s base-layer consensus. The attack vector exploited how the Omni bridge, designed to facilitate asset movement across chains, interacted with the intent-based protocol.

NEAR Intents, a system that allows users to express desired swaps for market makers to fulfill, immediately froze cross-chain services across 11 networks upon detection of the breach. These affected networks included BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll, and Plasma. The rapid response team identified and patched the underlying smart contract vulnerability within hours of the incident. This decisive action was critical in preventing further losses and stabilizing the protocol’s operations.

The unprecedented return of funds came approximately one day after the NEAR Intents team established communication with the attacker. While the specifics of this negotiation or the attacker’s motivation remain undisclosed, the recovery represents a significant relief for affected users, whom the protocol had already pledged to reimburse in full. The swift resolution underscores the growing pressure on attackers, particularly as blockchain analytics and law enforcement capabilities mature in the Web3 space.

In the immediate aftermath of the disclosure, the NEAR token experienced a dip, falling approximately 6% and touching a low near $4.76. However, it partially rebounded to around $4.84, stabilizing as news of the fund recovery spread. This volatility reflects the market’s sensitivity to security incidents, especially those involving cross-chain components, which have historically been prime targets for exploits due to their intricate design and expanded attack surface.

The incident serves as a stark reminder of the technical complexities inherent in building and securing cross-chain infrastructure. 2026 has already been characterized by security firms like CertiK and PeckShield as one of the worst years for crypto security, with September alone seeing an estimated $766 million to $768 million lost across 99 separate incidents. The NEAR Intents exploit, while resolved, adds to a lengthening list of challenges facing protocols that aim to offer seamless interoperability.

The vulnerability in the Omni integration highlights the nuanced distinctions between traditional bridge security and the emerging attack surfaces presented by intent-based architectures. While bridges are often targeted for flaws in their locking and minting mechanisms, intent-based systems introduce new layers of interaction and authorization that require rigorous auditing and real-time monitoring. The successful exploitation of an authorization boundary rather than a fundamental cryptographic flaw suggests that security paradigms must evolve to match the increasing sophistication of Web3’s composable components.

Moving forward, the industry must grapple with how to build truly resilient cross-chain systems where an exploit on one component does not cascade into systemic risk. Will the exceptional return of funds in this case set a new precedent for attacker accountability, or merely remain an isolated anomaly in a landscape still struggling with fundamental security challenges?

Signals elevate this to HOT_INTEL priority.

// Related_Intel

More_Signals

‹ Return_to_Terminal

Traffic_Nodes

0

Mobile_Relay / Zone_37