Skip to main content
AVOID.NET
← avoid.net

Verify a decision

Every moderation decision on AVOID.NET is anchored to the Solana blockchain. You don't have to trust us — you can verify cryptographically that we committed to a verdict at a specific moment and have not rewritten it.

How verification works

  1. We commit. When a moderator accepts/rejects a submission, we serialize the decision into deterministic UTF-8 bytes (payload_canonical_string), hash it with SHA-256, encode the digest as base58, and write it to Solana inside an SPL Memo v2 transaction.
  2. We store the bytes. The exact bytes we hashed are stored alongside the decision in our database. Anyone can read them and recompute the hash in any language.
  3. You compare three values. Database hash, your independently-recomputed hash, and the hash inside the on-chain memo. If all three match, the decision is authentic and timestamped.
The on-chain memo format is AVOID.NET|v1|h:<b58-sha256>|d:<id>|t:<iso>

Find a signature on any investigation page's decision log, or run python -m src.verify_decision --signature <sig> for a CLI check.

Sequence
#1
Score
→
Cluster
mainnet-beta
Slot
452349377
Off-chain at
2026-10-01T17:03:56.583Z
Anchored at
—
Block time
—

Independent verification

1. Database (off-chain)
ADkF68cmraux5M6fw6e4TqDcvud24JppMiLjuWk3k1zz
2. Recomputed (your browser)
computing…
3. On-chain (Solana memo)
fetching…
Canonical bytes hashed (21040 chars)
{"actor":"system:backfill","investigation_id":"f6117990-9f86-4fca-9f9f-44c646c1b886","kind":"publish","page_slug":"near-intents","published_at":"2026-10-01T17:03:56.430Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"NEAR Intents","sections":[{"content":"NEAR Intents is a cross-chain liquidity protocol developed by Aurora Labs and operated as core NEAR Protocol infrastructure. Originally known as Defuse Protocol, the project was renamed NEAR Intents in late 2024 and launched on mainnet in Q1 2025. Users declare a desired swap outcome and a network of competing third-party solvers fulfills that intent via the most efficient route across DeFi and CeFi liquidity, with final settlement through a Verifier smart contract on NEAR. The protocol supports more than 31 blockchains and, as of mid-2026, had processed over $10 billion in all-time swap volume across approximately 15.7 million transactions serving 1.6 million unique users. Alex Shevchenko, co-founder of Aurora, serves as General Manager of NEAR Intents. Aurora Labs commissioned a smart contract audit by Hacken in December 2024 covering the Verifier and bridge contracts; that audit identified five findings, of which two were resolved, two accepted, and one mitigated, with test coverage reported at 22% region coverage.","heading":"Platform Overview","severity":"low","sources":[{"credibility":2,"name":"What Is NEAR Intents? The Cross-Chain Swap Protocol Explained — LeoDex","type":"other","url":"https://leodex.io/learn/near-intents/what-is-near-intents"},{"credibility":2,"name":"Aurora Labs Limited audit by Hacken — Dec 2024","type":"research","url":"https://hacken.io/audits/aurora-labs-limited/sca-aurora-labs-defuse-contracts-dec2024/"},{"credibility":2,"name":"Aurora Labs Releases Intents Widget — Chainwire","type":"news_article","url":"https://chainwire.org/2026/02/11/aurora-labs-releases-intents-widget-making-near-intents-easy-to-embed-in-any-app/"}]},{"content":"On October 1, 2026, NEAR Intents confirmed a security breach in which approximately $3.8 million in USDT was drained from its HOT Bridge treasury address on BNB Chain. The team attributed the incident to a bug in the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract, which allowed an attacker to make unauthorized withdrawals from the platform's hot wallet. On-chain data reviewed by independent investigator ZachXBT showed approximately 3.87 million USDT leaving the contract across seven transactions: initial small test transfers of 10–11 USDT were followed by five larger transfers ranging from approximately 35,000 USDT to 1.5 million USDT, occurring between 7:54 p.m. ET on Wednesday, October 1 and 2:08 a.m. ET on Thursday, October 2. According to ZachXBT, the stolen funds were subsequently transferred to the KuCoin exchange and bridged to Bitcoin via cross-chain infrastructure. The team announced the breach publicly at approximately 8:53 a.m. ET on Thursday, October 2. Core protocol services were restored within roughly one hour of that announcement; however, deposits and withdrawals across 11 blockchain networks — including BNB Chain, Polygon, TON, Optimism, Avalanche, and Scroll — remained suspended for approximately 12 additional hours while Omni infrastructure underwent repairs. NEAR Intents stated it had patched the contract-side vulnerability and pledged full compensation to all affected users from its treasury. The incident was reported to law enforcement, and the team said it was working with security and blockchain analytics firms to trace the stolen funds.","heading":"October 2026 Exploit: $3.8 Million Drained from BSC Hot Wallet","severity":"critical","sources":[{"credibility":1,"name":"NEAR Intents hit by $3.8M exploit, pauses cross-chain services — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues"},{"credibility":1,"name":"NEAR Intents halts services after $3.8 million exploit, promises full compensation — The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-10-01-near-intents-halts-services-after-3-8-million-exploit-promises-full-compensation-417404"},{"credibility":2,"name":"NEAR Intents Pledges Full Compensation After a Bug Lets an Attacker Drain $3.8 Million — Unchained","type":"news_article","url":"https://unchainedcrypto.com/near-intents-pledges-full-compensation-after-a-bug-lets-an-attacker-drain-3-8-million/"},{"credibility":2,"name":"NEAR Intents Confirms Security Breach, Over $3.8 Million Stolen — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/near-intents-confirms-security-breach-over-3-8m-stolen"},{"credibility":2,"name":"Near Intents Breaks Silence on $3.8 Million Exploit, NEAR Token Slumps 7.5% — U.Today","type":"news_article","url":"https://u.today/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75"}]},{"content":"On-chain investigator ZachXBT publicly identified the BNB Chain address that received the drained funds. According to his analysis, the attacker first consolidated the stolen USDT on BNB Chain, then transferred the assets to the KuCoin centralized exchange, after which the funds were bridged to Bitcoin through cross-chain infrastructure. Approximately 1.5 million USDT was routed through CoW Protocol's settlement contract; the remainder was sent to additional unidentified addresses before the KuCoin transfer. NEAR Intents said it was engaged with law enforcement and blockchain analytics partners to pursue recovery. No on-chain recovery or return of funds had been publicly confirmed as of the date of this filing.","heading":"Fund Movement and On-Chain Tracing","severity":"high","sources":[{"credibility":2,"name":"NEAR Intents Pledges Full Compensation After a Bug Lets an Attacker Drain $3.8 Million — Unchained","type":"news_article","url":"https://unchainedcrypto.com/near-intents-pledges-full-compensation-after-a-bug-lets-an-attacker-drain-3-8-million/"},{"credibility":2,"name":"NEAR Intents Confirms Security Breach, Over $3.8 Million Stolen — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/near-intents-confirms-security-breach-over-3-8m-stolen"},{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker — Decrypt","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"}]},{"content":"Approximately one week before the exploit, NEAR Intents publicly reported that its SHIELD monitoring system had blocked more than $50 million in attempted cross-chain transfers linked to wallets associated with the Bitget exchange hack of September 24, 2026, in which roughly $387.5 million was allegedly stolen from Bitget. According to NEAR Intents, only approximately $669,000 in suspicious transfers actually entered its liquidity network: $503,000 was frozen mid-swap, and approximately $166,000 was completed before the block was implemented. The remaining $50 million-plus in attempts was rejected before execution. General Manager Alex Shevchenko stated that NEAR Intents waived both the five percent freezing bounty and five percent recovery bounty offered by Bitget so that a larger share would flow back to the exchange. Shevchenko was quoted as saying: 'The crypto industry cannot demand recognition of digital property rights while simultaneously building infrastructure optimized to help launder stolen funds.' The juxtaposition of this publicly touted security success with the subsequent internal exploit drew significant press attention. No security firm has formally attributed the October 1 attack to the same actors behind the Bitget hack; researcher reports noted that shared wallet patterns can indicate money laundering services rather than identical attackers.","heading":"Context: $50 Million Bitget Interception (September 2026)","severity":"medium","sources":[{"credibility":1,"name":"NEAR Intents says it blocked $50M tied to Bitget hackers — Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/near-intents-says-it-blocked-50m-tied-to-bitget-hackers"},{"credibility":2,"name":"NEAR Intents Blocked $50M in Bitget Hack Funds, but Only $503K Was Frozen — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/29/near-intents-blocked-50m-in-bitget-hack-funds-but-only-503k-was-frozen/"},{"credibility":2,"name":"NEAR Intents Hacked: Intercepted $50M in Hacker Funds Last Week, $3.8M Stolen from Itself This Week — TechFlow","type":"news_article","url":"https://www.techflowpost.com/en-US/article/34343"},{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker — Decrypt","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"}]},{"content":"Following the public announcement of the exploit on October 1–2, 2026, the NEAR Protocol native token declined approximately 7.5% to a local low of $4.76 before partially recovering to approximately $4.84. Reports indicated NEAR ETF shares also dropped more than 7%. The price drop was directly correlated with the timing of NEAR Intents' public disclosure.","heading":"Market Impact","severity":"medium","sources":[{"credibility":2,"name":"Near Intents Breaks Silence on $3.8 Million Exploit, NEAR Token Slumps 7.5% — U.Today","type":"news_article","url":"https://u.today/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75"},{"credibility":2,"name":"Why is Near Protocol falling? — FXStreet","type":"news_article","url":"https://www.fxstreet.com/cryptocurrencies/news/near-protocol-slides-below-500-after-near-intents-4m-exploit-202610011619"}]},{"content":"Aurora Labs commissioned a smart contract security audit from Hacken in December 2024 covering the Defuse (now NEAR Intents) Verifier and bridge contracts. That audit, completed January 27, 2025, identified five findings across Rust code: two resolved, two accepted, and one mitigated. Reported test coverage was 22% by region, with a note that negative case coverage was partially missed. The October 2026 exploit affected the HOT Bridge Omni deposit and withdrawal infrastructure — a component described as part of the custody architecture rather than the core Verifier contract. Whether the exploited Omni integration was within scope of the December 2024 audit has not been confirmed in public reporting. The incident highlights a structural concern: cross-chain protocols operating large hot wallets on EVM-compatible chains require rigorous review of all bridge and custody integration points, not only core swap contract logic. A post-mortem report was promised by the team but had not been published as of the date of this filing.","heading":"Security Posture and Audit History","severity":"high","sources":[{"credibility":2,"name":"Aurora Labs Limited audit by Hacken — Dec 2024","type":"research","url":"https://hacken.io/audits/aurora-labs-limited/sca-aurora-labs-defuse-contracts-dec2024/"},{"credibility":1,"name":"NEAR Intents halts services after $3.8 million exploit, promises full compensation — The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-10-01-near-intents-halts-services-after-3-8-million-exploit-promises-full-compensation-417404"},{"credibility":2,"name":"NEAR Intents reports $3.8 million loss after smart contract bug — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/near-intents-bsc-hot-wallet-exploit/"}]},{"content":"Following discovery of the exploit, NEAR Intents suspended cross-chain services, patched the contract-side vulnerability, and pledged full reimbursement of affected users from the project treasury. Core services including the main intents.near.org interface were expected to resume within one hour of the public announcement. Deposit and withdrawal functionality across 11 blockchain networks remained suspended for approximately 12 additional hours pending repairs to the Omni infrastructure layer. The team reported the incident to law enforcement and stated it was coordinating with blockchain analytics platforms to trace and potentially recover stolen funds. A post-mortem report was committed to but had not been published as of the investigation date. No independent confirmation of the reimbursement status or scope of affected users had appeared in public reporting at the time of this filing.","heading":"Team Response and Remediation Status","severity":"medium","sources":[{"credibility":2,"name":"NEAR Intents Confirms Attack, Promises Full Compensation — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/near-intents-confirms-attack-promises-full-compensation-for-over-3-8m-loss"},{"credibility":3,"name":"NEAR Intents Exploit: $3.8M Drained, Full Refund Promised — AirdropAlert","type":"news_article","url":"https://airdropalert.com/blogs/near-intents-exploit/"},{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker — Decrypt","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"}]}],"sources_used":[{"credibility":1,"name":"NEAR Intents hit by $3.8M exploit, pauses cross-chain services — CoinDesk","type":"news_article","url":"https://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues"},{"credibility":1,"name":"NEAR Intents halts services after $3.8 million exploit, promises full compensation — The Block","type":"news_article","url":"https://www.theblock.co/news/ecosystems/2026-10-01-near-intents-halts-services-after-3-8-million-exploit-promises-full-compensation-417404"},{"credibility":1,"name":"NEAR Intents says it blocked $50M tied to Bitget hackers — Cointelegraph","type":"news_article","url":"https://cointelegraph.com/news/near-intents-says-it-blocked-50m-tied-to-bitget-hackers"},{"credibility":2,"name":"Near Intents Hacked for $3.8M Days After Denying North Korea-Linked Bitget Hacker — Decrypt","type":"news_article","url":"https://decrypt.co/379822/near-intents-hacked-days-after-denying-bitget-hacker"},{"credibility":2,"name":"NEAR Intents Pledges Full Compensation After a Bug Lets an Attacker Drain $3.8 Million — Unchained","type":"news_article","url":"https://unchainedcrypto.com/near-intents-pledges-full-compensation-after-a-bug-lets-an-attacker-drain-3-8-million/"},{"credibility":2,"name":"NEAR Intents Confirms Security Breach, Over $3.8 Million Stolen — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/near-intents-confirms-security-breach-over-3-8m-stolen"},{"credibility":2,"name":"NEAR Intents Confirms Attack, Promises Full Compensation — KuCoin News","type":"news_article","url":"https://www.kucoin.com/news/flash/near-intents-confirms-attack-promises-full-compensation-for-over-3-8m-loss"},{"credibility":2,"name":"NEAR Intents Hacked: Intercepted $50M in Hacker Funds Last Week, $3.8M Stolen from Itself This Week — TechFlow","type":"news_article","url":"https://www.techflowpost.com/en-US/article/34343"},{"credibility":2,"name":"NEAR Intents Blocked $50M in Bitget Hack Funds, but Only $503K Was Frozen — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/09/29/near-intents-blocked-50m-in-bitget-hack-funds-but-only-503k-was-frozen/"},{"credibility":2,"name":"Near Intents Breaks Silence on $3.8 Million Exploit, NEAR Token Slumps 7.5% — U.Today","type":"news_article","url":"https://u.today/near-intents-breaks-silence-on-38-million-exploit-near-token-slumps-75"},{"credibility":2,"name":"Why is Near Protocol falling? — FXStreet","type":"news_article","url":"https://www.fxstreet.com/cryptocurrencies/news/near-protocol-slides-below-500-after-near-intents-4m-exploit-202610011619"},{"credibility":2,"name":"NEAR Intents reports $3.8 million loss after smart contract bug — CryptoBriefing","type":"news_article","url":"https://cryptobriefing.com/near-intents-bsc-hot-wallet-exploit/"},{"credibility":2,"name":"Aurora Labs Limited audit by Hacken — Dec 2024","type":"research","url":"https://hacken.io/audits/aurora-labs-limited/sca-aurora-labs-defuse-contracts-dec2024/"},{"credibility":2,"name":"NEAR Intents Exploit Drains $3.8 Million as 11 Networks Face Restrictions — CryptoMeter","type":"news_article","url":"https://www.cryptometer.io/news/near-intents-exploit-drains-3-8-million-as-11-networks-face-restrictions/"},{"credibility":2,"name":"What Is NEAR Intents? The Cross-Chain Swap Protocol Explained — LeoDex","type":"other","url":"https://leodex.io/learn/near-intents/what-is-near-intents"}],"summary":"NEAR Intents is a cross-chain swap protocol built on NEAR Protocol by Aurora Labs, formerly known as Defuse Protocol, enabling trustless asset exchanges across 31+ blockchains using an intent-based architecture. On October 1, 2026, the protocol suffered a confirmed $3.8 million exploit traced to a vulnerability in the interaction between its Omni deposit and withdrawal infrastructure and its smart contract, resulting in unauthorized outflows from its BNB Chain hot wallet. The team patched the flaw, pledged full user reimbursement, and reported the incident to law enforcement; the breach occurred days after the protocol's SHIELD system intercepted $50 million in suspected Bitget hack proceeds, exposing a gap between external threat interception and internal security posture.","timeline":[{"date":"2023-01-01","event":"Defuse Protocol concept developed by Aurora Labs as part of NEAR chain abstraction initiative.","source":"LeoDex — What Is NEAR Intents?","source_url":"https://leodex.io/learn/near-intents/what-is-near-intents"},{"date":"2024-12-01","event":"Hacken completes smart contract security audit of Aurora Labs Defuse contracts, identifying five findings with 22% test coverage.","source":"Hacken Audit — Aurora Labs Limited","source_url":"https://hacken.io/audits/aurora-labs-limited/sca-aurora-labs-defuse-contracts-dec2024/"},{"date":"2025-01-27","event":"Hacken audit report published. Two findings resolved, two accepted, one mitigated.","source":"Hacken Audit — Aurora Labs Limited","source_url":"https://hacken.io/audits/aurora-labs-limited/sca-aurora-labs-defuse-contracts-dec2024/"},{"date":"2025-03-01","event":"NEAR Intents launches on mainnet at ETHDenver following rebrand from Defuse Protocol.","source":"LeoDex — What Is NEAR Intents?","source_url":"https://leodex.io/learn/near-intents/what-is-near-intents"},{"date":"2026-02-11","event":"Aurora Labs releases Intents Widget, expanding NEAR Intents embeddability across third-party applications.","source":"Chainwire — Aurora Labs Releases Intents Widget","source_url":"https://chainwire.org/2026/02/11/aurora-labs-releases-intents-widget-making-near-intents-easy-to-embed-in-any-app/"},{"date":"2026-09-24","event":"Bitget exchange suffers approximately $387.5 million hack. Attackers subsequently attempt to launder funds through multiple protocols including NEAR Intents.","source":"Cointelegraph — NEAR Intents says it blocked $50M tied to Bitget hackers","source_url":"https://cointelegraph.com/news/near-intents-says-it-blocked-50m-tied-to-bitget-hackers"},{"date":"2026-09-29","event":"NEAR Intents publicly reports its SHIELD system blocked over $50 million in transfer attempts linked to Bitget hack wallets; $503,000 frozen mid-swap, $166,000 completed before block, remaining $50M+ rejected pre-execution. Team waives Bitget bounty.","source":"CryptoTimes — NEAR Intents Blocked $50M in Bitget Hack Funds","source_url":"https://www.cryptotimes.io/2026/09/29/near-intents-blocked-50m-in-bitget-hack-funds-but-only-503k-was-frozen/"},{"date":"2026-10-01","event":"Exploit begins: small test withdrawals of 10–11 USDT are made from NEAR Intents HOT Bridge treasury on BNB Chain, followed by five larger withdrawals totaling approximately 3.87 million USDT between 7:54 p.m. ET and 2:08 a.m. ET.","source":"Unchained — NEAR Intents Pledges Full Compensation","source_url":"https://unchainedcrypto.com/near-intents-pledges-full-compensation-after-a-bug-lets-an-attacker-drain-3-8-million/"},{"date":"2026-10-02","event":"NEAR Intents announces breach publicly at approximately 8:53 a.m. ET. Contract patched; cross-chain services suspended across 11 networks; law enforcement notified. NEAR token drops 7.5% to a low of $4.76.","source":"CoinDesk — NEAR Intents hit by $3.8M exploit","source_url":"https://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues"},{"date":"2026-10-02","event":"ZachXBT publicly identifies the BNB Chain receiving address; traces stolen USDT to KuCoin and subsequent bridging to Bitcoin.","source":"KuCoin News — NEAR Intents Confirms Security Breach","source_url":"https://www.kucoin.com/news/flash/near-intents-confirms-security-breach-over-3-8m-stolen"}]},"v":1}