The protocol halted services, patched the contract-side flaw and promised to compensate users in full, naming eleven networks whose deposits and withdrawals would stay down for another 12 hours. Investigators who traced the outflows do not agree on where the money went.
NEAR Intents stopped its services on Thursday after detecting a security incident, and said a preliminary report put the total loss at about $3.8 million. The cross-chain swap protocol attributed it to "a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract," said the contract-side vulnerability had been patched, and committed to covering the shortfall: "These funds will be compensated in full."
By its own description the protocol routes swaps across more than 30 networks, and the component it blamed sits at the edge of that system rather than in the swap logic, handling deposits into and withdrawals out of the protocol. The restart was uneven as a result. NEAR Intents and near.com were expected back within an hour of the statement, posted at 12:53 UTC, while deposits and withdrawals were to stay unavailable for roughly another 12 hours on eleven networks: BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma. Users holding assets from those chains inside NEAR Intents, including in HOT wallet or on near.com, would be able to swap them into other assets once service returned, the project said.
What the protocol has not published is a timeline. Its statement says services were stopped "earlier today" without giving a detection or halt time, and the detailed report it promised within days had not appeared when this article was published. Unchained, reading on-chain records, placed the start of the outflows on Wednesday evening, with about 3.87 million USDT leaving the HOT Bridge treasury address on BNB Chain over roughly six hours. That figure measures movement out of one address on one chain, which is not the same quantity as a preliminary loss counted across the whole incident.
Investigator accounts of where the money went do not agree. Unchained said a receiving address moved funds onward within minutes, roughly 1.5 million USDT of it to CoW Protocol's settlement contract and the remainder to unidentified addresses, and noted that it could not independently verify the path. The Block reported that the blockchain investigator ZachXBT, writing on Telegram, traced irregular outflows from the protocol's BSC hot wallet to KuCoin and then across a bridge to Bitcoin. Both accounts begin at the same BNB Chain hot wallet and diverge after it.
NEAR Intents said it has reported the incident to law enforcement and is working with security and blockchain analytics partners "to trace the funds and pursue recovery." It did not name those partners, and it has not said that any funds have been recovered.
The compensation pledge arrives without a stated source of funds or a date. Recent failures in the same part of the stack have ended in different places: BounceBit shut down its own L1 after a $3 million exploit it could not patch, and Sandbox froze its bridges after $49 billion of unbacked SAND was minted.
The incident also lands days after the protocol was on the other side of one. Unchained reported that NEAR Intents blocked more than $50 million of attempted transfers tied to the Bitget hack, in which the exchange said its own approval process released $351.6 million. That blocked figure comes from Unchained's account and has not been independently verified here.
Until the promised report arrives, the cause rests on the project's own description of a fault between its bridge infrastructure and its smart contract, and the size of the loss rests on a preliminary figure the project supplied itself.