NEAR Intents suspended its services on October 1, 2026, after identifying a security incident that the team preliminarily linked to roughly $3.8 million in losses.
The cross-chain trading protocol said the problem originated in a flaw involving the interaction between its Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract, and it committed to reimbursing the lost funds in full.
The announcement, posted by the official NEAR Intents account, described an interruption that began earlier the same day once the incident was detected.
According to the team, the vulnerability on the contract side had already been corrected by the time of the public update.
Core operations for NEAR Intents and near.com were expected to return within about an hour of that statement.
Access was not restored uniformly.
Deposits and withdrawals on eleven networks were scheduled to stay offline for an additional period of roughly twelve hours while remaining repairs to the Omni infrastructure were finished.
Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.
The preliminary report indicates the total loss of…
— NEAR Intents (@near_intents) October 1, 2026
The affected networks named in the update were BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll, and Plasma.
Users who already held assets from those chains inside NEAR Intents—for example through a HOT wallet or on near.com—were told they would still be able to exchange those holdings for other assets once the main service came back online, on the shorter timeline of about one hour.
The project also said the incident had been referred to law enforcement. It added that it was coordinating with security specialists and blockchain analytics partners to follow the funds and attempt recovery.
A fuller public account was promised in the days after the initial notice.NEAR Intents functions as an intent-based trading layer.
Rather than requiring users to manage bridging and routing themselves, the system lets them state a desired outcome, after which independent solvers compete to complete the transaction across supported chains.
That design has made the protocol a routing point for multi-chain activity, which is why a pause in deposits, withdrawals, and swaps can disrupt users even when the underlying NEAR Protocol chain is not the source of the bug.
The team’s description placed the defect in the Omni deposit and withdrawal path’s interaction with the Intents contract, not in a failure of the base chain itself.
The reimbursement pledge is the central user-facing commitment in the notice.
The project stated that the funds covered by the preliminary loss figure would be compensated in full, though the initial post did not spell out the payment schedule, the precise set of affected accounts, or the asset breakdown behind the estimate.
Subsequent public comments from NEAR co-founder Illia Polosukhin described the same loss figure, said an internal monitoring layer called SHIELD had flagged unusual activity and prompted the temporary halt, and characterized the issue as isolated to USDT on BSC.
He also said the vulnerability was identified and fixed within an hour of detection, and that NEAR Intents and near.com were already back online aside from a limited set of affected chain connections.
Separately, reporting on October 2 indicated that NEAR Intents general manager Alex Shevchenko had publicly said the exploiter had been identified and had set a short deadline for the return of the assets, naming addresses for Bitcoin and other networks.
That step sits alongside, rather than instead of, the earlier commitment to make users whole and the referral to law enforcement.
For users, the practical message from the October 1, 2026 notice is twofold: core swap functionality was expected to resume quickly after the contract-side patch, while deposit and withdrawal routes on the listed networks faced a longer maintenance window.
The team also warned, through the structure of its response, that recovery work and a detailed post-incident report were still ahead. Anyone contacted outside official channels about “claiming” compensation should treat those messages with caution, since incident announcements often attract impersonation attempts / scams.