NEAR Intents GM discusses $4M hack from Omni bug
Summary
NEAR Intents General Manager Alex Shevchenko announced that a complex bug in the Omni infrastructure led to a $3.8 million hack, which was exploited through asynchronous coordination issues in the protocol. Despite being audited multiple times, the exploit went undetected, highlighting the intricacies of the system that spans across networks. Following the incident, NEAR Intents quickly halted services, patched the vulnerability within an hour, and successfully recovered the full amount within approximately 24 hours after identifying the attacker and providing return addresses.
Tokens
$NEAR
Analysis
NEAR Intents: NEAR Intents is a multichain transaction protocol built on NEAR Protocol that enables users or agents to express desired outcomes, such as cross-chain token swaps, while solvers compete to fulfill them optimally through off-chain discovery and on-chain verification via NEAR smart contracts. It abstracts complex bridging and liquidity routing across networks using infrastructure like Omni for asset deposits and withdrawals. In the reported incident, a bug in its Omni cross-chain coordination layer with NEAR smart contracts allowed an attacker to exploit asynchronous interactions, prompting an immediate service halt and investigation. Alex Shevchenko: Alex Shevchenko serves as general manager of NEAR Intents and has prior experience as CEO of Aurora Labs. He publicly identified the suspected exploiter of the protocol's funds, issued return addresses across chains, and set a 48-hour deadline for restitution while emphasizing responsible disclosure. In response to the incident, he confirmed the full recovery of funds shortly after the public call-out and highlighted the team's rapid internal monitoring and patching efforts. Recovery: The protocol recovered the full amount lost in the exploit within approximately 24 hours after the general manager publicly identified the attacker and provided return addresses. Security Process: The exploit stemmed from a complex, asynchronous coordination bug in Omni infrastructure that had undergone multiple audits without detection of this specific operational sequence. Incident Response: The team halted services upon detection, patched the contract-side vulnerability within an hour, and committed to compensating affected users from its own resources while tracing the funds.
Categories
ethereumdeficrypto
Related sources
- https://x.com/i/status/2108199072926482521
- https://phemex.com/academy/who-is-alex-shevchenko
- https://unchainedcrypto.com/near-intents-says-exploited-3-8-million-is-back-closes-its-hack-investigation/
- https://cryptowatchdaily.com/news/near-intents-3-8-million-exploit-funds-returned/
- https://www.near.org/blog/unpacking-near-intents-a-deep-dive
- https://www.bitcoininsider.org/article/308320/near-intents-exploit-omni-bug
- https://x.com/i/status/2108216372492960157
- https://bingx.pro/en/flash-news/post/near-intents-names-suspected-entity-in-m-exploit-sets-hour-deadline-to-return-funds
- https://docs.near-intents.org/near-intents/
- https://www.near.org/intents
- https://x.com/i/status/2108200450423939261
- https://thedefiant.io/news/hacks/shevchenko-gives-near-intents-attacker-48-hours
- https://near-intents.pro/faq
- https://unchainedcrypto.com/near-intents-pledges-full-compensation-after-a-bug-lets-an-attacker-drain-3-8-million/
- https://x.com/i/status/2108202657026658467
- https://x.com/i/status/2108196824125178155
- https://x.com/CoinMarketCap/status/2106117815073665382
- https://www.cyberkendra.com/2026/10/near-intents-hit-by-3-8m-exploit-via-omni-bridge-bug.html
- https://www.cryptotimes.io/2026/10/02/near-intents-gm-says-3-8m-exploiter-identified-sets-48-hour-return-deadline/
- https://docs.near.org/chain-abstraction/intents/overview