NEAR Intents $3.8 Million Exploit: What Users Should Know and Do

Last Updated:
NEAR Protocol
Google News

Get our latest news first. Add us as your Preferred Source on Google and tap "Star" to prioritize our updates.

  • Hackers exploited the NEAR Intents protocol using a bug linked to its Omni infrastructure.
  • The NEAR Intents team has patched the bug and promised to fully reimburse users.
  • All NEAR Intents users need to tread cautiously while the issue is being resolved.

NEAR Intents has reported an exploit on its platform resulting in a $3.8 million loss of users’ funds. According to the report, a bug linked to NEAR Intents’ Omni deposit and withdrawal system triggered the exploit. 

What Happened on the NEAR Intents Protocol?

The incident was triggered by a smart contract vulnerability sitting directly at the “handoff seam” between two core components—the Omni infrastructure and the NEAR Intents Smart Contract. Omni infrastructure is the protocol’s underlying multi-chain gateway that manages how token deposits and withdrawals move across external blockchains, while the NEAR Intents Smart Contract is the core protocol ledger that registers and executes users’ desired cross-chain asset swaps.

The exploit capitalized on a logical bug in the interaction/communication flow between Omni infrastructure and the smart contract. The attacker exploited a breakdown in communication and tricked the smart contract into validating or inflating artificial deposits/withdrawals without providing equivalent collateral, allowing them to drain funds from the platform.

The NEAR Intents Team Response and Plans

Despite acknowledging the exploit, the NEAR Intents team has assured users of their funds’ safety. In a statement, the team pledged that all affected user assets will be compensated in full utilizing treasury funds. Meanwhile, the team has patched the main smart contract vulnerability to prevent further losses.

In practice, NEAR Intents’ compensation promise places the protocol as the issuer, thereby taking full responsibility for the loss rather than repaying only a percentage of lost funds. Therefore, users whose funds are part of the stolen assets would have their internal ledger balances reflect the pre-exploit amount once the team finalizes the accounting adjustments.

Related Articles: NEAR Protocol Price Prediction: Is $5.95 the Next Stop After This Breakout?

As is typical with such attacks, the NEAR Intents team paused deposit and withdrawal services on the platform after discovering the exploit. However, the protocol is expected to resume full service approximately 12 hours from the time of the official protocol announcement. Having patched the main smart contract vulnerability, all external gateways will face the full 12-hour suspension window while engineers finalize and test repairs on the multi-chain bridge network.

What Should NEAR Intents Users Do?

Amid the ongoing repair and protocol maintenance, NEAR Intents users are advised to wait for the official restart before attempting any deposit or withdrawal transactions. Trying to interact with paused or partially restored gateways carries high technical risks, such as trapped transactions, wasted network fees, and system reboots. Therefore, users are advised to hold off on transfers, monitor NEAR Intents’ official channels for updates, and verify transaction resumption on small amounts after the official resumption announcement.

While waiting for full operations to resume on the NEAR Intents protocol, users are advised to review their accounts and transaction histories to verify if their funds were affected by the exploit. Checking these specific areas will confirm if a user is eligible for the protocol’s treasury-backed reimbursement. Three crucial steps to take while reviewing include identifying pending or in-transit transactions, verifying internal account ledger balances, and reviewing wallet token approvals.

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.