Near Intents Exploited for $3.8M: Critical Bug in Cross-Chain Protocol

Topics: blockchain · Difficulty: intermediar

Attila Kiraly — Strateg AI & Educator · · 3 min read

Reprezentare conceptuală a unui seif digital securizat pe un fundal de circuite blockchain, sugerând securitatea cibernetică.

Originally published: October 1, 2026

Near Intents has suspended cross-chain swaps following a critical bug that allowed an attacker to drain $3.8 million. The incident occurs just days after the team denied links to a North Korean-affiliated hacker.

What happened

Near Intents, a protocol designed to streamline intent-based transactions within the Near ecosystem, suffered a major security breach resulting in the loss of approximately $3.8 million. The exploit was triggered by a logic flaw in the protocol's smart contracts, which allowed an attacker to manipulate cross-chain swap processes. Following the discovery, the Near Intents team immediately paused all cross-chain operations and publicly committed to reimbursing all affected users. The hack is particularly notable as it occurred just days after the project faced scrutiny over alleged links to a North Korean-affiliated hacker, claims which the team had vehemently denied.

Technology context

Near Intents operates on a model known as "intent-centric" design. In standard decentralized finance (DeFi), users must manually sign every step of a transaction. With intents, users simply state their desired outcome—such as swapping tokens across different blockchains—and leave the execution to "solvers." These solvers compete to find the best route and execute the trade. The vulnerability resided in the validation logic for these cross-chain messages, where the attacker managed to bypass security checks and drain liquidity without providing the necessary collateral.

Why it matters

The security of cross-chain bridges and intent-based protocols is a cornerstone of Web3 interoperability. Incidents like this highlight the inherent risks of "chain abstraction," where simplifying the user interface can sometimes hide complex back-end vulnerabilities. For the broader industry, this hack serves as a reminder that even innovative architectures are susceptible to traditional smart contract bugs. The team's decision to repay users is a significant move to preserve trust, but it also highlights the financial fragility of emerging DeFi protocols when faced with multi-million dollar losses.

Key terms explained

Impact

In the short term, the suspension of Near Intents reduces the available cross-chain liquidity for the Near network. In the medium term, this event will likely lead to more rigorous auditing requirements for intent-based systems. The incident also puts a spotlight on the "solver" networks; if these agents are not properly sandboxed or validated, they can become vectors for systemic risk. The reputational damage, coupled with the previous allegations regarding North Korean hackers, may lead to increased regulatory attention.

What's next

The Near Intents team is expected to release a comprehensive post-mortem report detailing the exact nature of the bug and the fix implemented. We will likely see a push for decentralized insurance products that specifically cover intent-based execution risks. As the industry moves toward "chain abstraction," the balance between ease of use and cryptographic security will remain the primary challenge for developers in 2025.

Sources


Educational analysis generated with AI and editorially reviewed.

Original source: decrypt.co

Want to learn the fundamentals? What is Blockchain?

Frequently Asked Questions

How much money was lost in the Near Intents hack?

Approximately $3.8 million was drained from the protocol due to the exploit.

Will affected users get their money back?

Yes, the Near Intents team has officially committed to repaying every affected user in full.

What caused the vulnerability?

The hack was made possible by a logic bug in the smart contracts governing cross-chain swaps.

Is this hack related to North Korean cyber-groups?

While there were previous allegations regarding a North Korean-linked hacker, this specific exploit is attributed to a code vulnerability, and the team previously denied those links.

Is the protocol currently operational?

No, cross-chain functions have been frozen to ensure the safety of remaining funds while the team works on a fix.

Glossary Terms

Continue Learning

Explore more insights about technology, automation, and Web3 in the EduWeb Academy.

Explore Academy