← NEAR Intents Omni Exploit (October 2026)1 decision on this page
Audit log
Every state-changing event for NEAR Intents Omni Exploit (October 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-02 17:05:00ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 452,672,400
- sig
3oxQSjPTdbNk…pSiCXVZLexplorer ↗- hash
9CGRNPs3uK9E…pw6AKqs5sha256 → base58
verifying row…full verify ↗canonical bytes (11137 B) ▸
{"actor":"system:backfill","investigation_id":"80319ae0-ff55-4387-b566-3306a009cfb4","kind":"publish","page_slug":"near-intents-omni-exploit-october-2026","published_at":"2026-10-02T17:05:00.674Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"NEAR Intents Omni Exploit (October 2026)","sections":[{"content":"On October 1, 2026, NEAR Intents, a cross-chain intent-based swap protocol built on NEAR Protocol, halted service after an attacker drained approximately $3.8 million in user funds. NEAR Intents stated the loss stemmed from a bug in the interaction between its Omni deposit-and-withdrawal infrastructure and its core smart contract, which allowed unauthorized access to funds. In response, the protocol paused deposits and withdrawals across 11 networks, reportedly including BNB Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, Scroll and Plasma among others, while it implemented fixes.","heading":"The Exploit","severity":"critical","sources":[{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker (Decrypt)","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":2,"name":"NEAR Intents Hit By $3.8M Exploit In Latest Crypto Platform Hack (Cointelegraph)","type":"news_article","url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"},{"credibility":2,"name":"NEAR Intents hit by $3.8M exploit, pauses cross-chain services in latest crypto hack (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues"},{"credibility":3,"name":"NEAR Intents Pauses 11 Networks After $3.8M Omni Bug","type":"news_article","url":"https://gokhshtein.com/news/2026-10-02-near-intents-pauses-11-networks-after-38m-omni-bug"}]},{"content":"According to NEAR Intents' own account, the exploit arose from a contract-side flaw in how the Omni custody/bridging layer communicated with the primary NEAR Intents smart contract, rather than from a compromise of a private key or exchange account. Some reporting described the initial drain as occurring via a BNB Chain-linked hot wallet tied to the Omni system, though this detail has not been independently confirmed by a post-mortem report at the time of writing. NEAR Intents said the contract-side vulnerability was patched and that core services were expected to resume within about an hour of the incident being detected, with full deposit and withdrawal functionality across affected networks restored after approximately 12 hours.","heading":"Technical Cause","severity":"high","sources":[{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker (Decrypt)","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":2,"name":"NEAR Intents Hit By $3.8M Exploit In Latest Crypto Platform Hack (Cointelegraph)","type":"news_article","url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"},{"credibility":3,"name":"NEAR Intents Exploit Hits Multiple EVM Chains","type":"news_article","url":"https://globalcrypto.tv/near-intents-exploit-triggers-multi-chain-incident/"}]},{"content":"On-chain investigator ZachXBT reported that the stolen funds were sent to the KuCoin exchange and subsequently bridged into Bitcoin, a pattern consistent with efforts to obscure the trail of stolen crypto assets. As of publication of the cited reporting, the identity of the attacker had not been established. NEAR Intents stated it had reported the incident to law enforcement and was working with blockchain-analytics partners to trace the funds and pursue recovery. These claims rely on secondary reporting of ZachXBT's analysis rather than a published on-chain forensic report, and should be treated as allegations pending independent confirmation.","heading":"Fund Flow and On-Chain Tracing","severity":"medium","sources":[{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker (Decrypt)","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":2,"name":"NEAR Intents Hit By $3.8M Exploit In Latest Crypto Platform Hack (Cointelegraph)","type":"news_article","url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"}]},{"content":"NEAR Intents publicly stated that \"the contract-side vulnerability has been patched\" and committed to compensating all affected users in full, reportedly from treasury funds, and said it planned to publish a detailed incident report in the days following the exploit. The team's full statement, as quoted in press coverage, read: \"The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery.\" Following the news, the NEAR token fell sharply, with reporting citing declines of roughly 7.5 to 8.9 percent and a low near $4.76-$4.86, and shares of a recently launched NEAR-linked exchange-traded fund also dropped more than 7 percent.","heading":"Response, Reimbursement Pledge, and Market Impact","severity":"medium","sources":[{"credibility":2,"name":"NEAR Intents Hit By $3.8M Exploit In Latest Crypto Platform Hack (Cointelegraph)","type":"news_article","url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"},{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker (Decrypt)","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":3,"name":"Near Intents Finally Addresses $3.8M Exploit as NEAR Token Drops 7.5%","type":"news_article","url":"https://www.bitbase.com/news/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75"}]},{"content":"The exploit occurred roughly two days after NEAR Intents had reportedly blocked a $50 million swap attempt and frozen over $500,000 linked to the perpetrator of a separate, much larger theft of approximately $387.5-388 million from the exchange Bitget, an attacker Bitget's CEO had speculated, based on IP evidence, might be linked to North Korea. Press coverage has noted the proximity in timing between NEAR Intents' intervention in the Bitget case and its own subsequent exploit, but no reporting reviewed establishes a confirmed causal or operational link between the two incidents; any connection remains speculative (alleged) at this stage.","heading":"Context: Preceding Bitget Hack Intervention","severity":"low","sources":[{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker (Decrypt)","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":2,"name":"NEAR Intents Hit By $3.8M Exploit In Latest Crypto Platform Hack (Cointelegraph)","type":"news_article","url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"}]}],"sources_used":[{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker (Decrypt)","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":2,"name":"NEAR Intents Hit By $3.8M Exploit In Latest Crypto Platform Hack (Cointelegraph)","type":"news_article","url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"},{"credibility":2,"name":"NEAR Intents hit by $3.8M exploit, pauses cross-chain services in latest crypto hack (CoinDesk)","type":"news_article","url":"https://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues"},{"credibility":3,"name":"NEAR Intents Pauses 11 Networks After $3.8M Omni Bug","type":"news_article","url":"https://gokhshtein.com/news/2026-10-02-near-intents-pauses-11-networks-after-38m-omni-bug"},{"credibility":3,"name":"NEAR Intents Exploit Hits Multiple EVM Chains","type":"news_article","url":"https://globalcrypto.tv/near-intents-exploit-triggers-multi-chain-incident/"},{"credibility":3,"name":"Near Intents Finally Addresses $3.8M Exploit as NEAR Token Drops 7.5%","type":"news_article","url":"https://www.bitbase.com/news/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75"},{"credibility":3,"name":"Wu Blockchain on X: NEAR Intents Exploited for Over $3.8M, Vulnerability Patched with Full Reimbursement Pledged","type":"social_media","url":"https://x.com/WuBlockchain/status/2105671861241827634"}],"summary":"On October 1, 2026, the cross-chain swap protocol NEAR Intents suffered an approximately $3.8 million exploit attributed to a bug in how its Omni deposit-and-withdrawal infrastructure interacted with its core smart contract. The team paused deposits and withdrawals across 11 networks, said it patched the vulnerability within roughly an hour, and pledged full reimbursement to affected users while funds were allegedly moved through KuCoin and bridged into Bitcoin. This page covers only the exploit incident; it does not restate the trust score of the existing NEAR Intents protocol page.","timeline":[{"date":"2026-09","event":"NEAR Intents reportedly blocks a roughly $50 million swap attempt and freezes over $500,000 linked to the attacker behind a separate ~$387.5-388 million theft from exchange Bitget, days before NEAR Intents' own exploit.","source":"Cointelegraph","source_url":"https://cointelegraph.com/news/near-intents-exploit-assistance-bitget-hack"},{"date":"2026-10","date_evidence":"Near Intents, a tool for swapping crypto across different blockchains, stopped service on Thursday after an attacker drained about $3.8 million from it.","date_original":"2026-10-01","event":"NEAR Intents halts service after an attacker drains approximately $3.8 million, attributed to a bug in the Omni deposit/withdrawal infrastructure's interaction with the core smart contract.","source":"Decrypt","source_url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"date":"2026-10","date_evidence":"Near Intents says the contract-side hole is patched and core services should resume within about an hour.","date_original":"2026-10-01","event":"NEAR Intents states the contract-side vulnerability has been patched, pledges full reimbursement, and reports the incident to law enforcement; deposits and withdrawals on 11 networks remain paused for roughly 12 additional hours.","source":"Decrypt","source_url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"date":"2026-10","event":"On-chain investigator ZachXBT reports the stolen funds were sent to KuCoin and bridged to Bitcoin; attacker identity remains unconfirmed.","source":"Decrypt / Cointelegraph","source_url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision d383e3e9-4576-4c72-ba3c-57018e104280
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.