# protocol exploit — X 热门讨论 (2026-10-01 19:09 UTC)

## @CryptoPatel (Crypto Patel) · 10-01 16:30 · ♥85 ↻10 💬6 $NEAR INTENTS EXPLOITED FOR $3.8M+ | BSC HOT WALLET DRAINED

#NEAR Intents suffered a security exploit after its BSC hot wallet recorded multiple irregular outflows, with losses estimated at $3.8M+.

The affected hot wallet 0x233c has stopped processing transactions, while the protocol reported an ongoing incident impacting multiple EVM chains.

Funds Trail: The stolen funds were reportedly moved to KuCoin and then bridged to Bitcoin.

Response: NEAR Intents says the contract-side vulnerability has been patched and affected users will be fully compensated. Deposits and withdrawals on several networks remain temporarily restricted while infrastructure fixes are completed.

BSC Theft Address: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37

$NEAR 14% Dumped in just last 8 hours.

A detailed incident report is expected from the team. https://x.com/CryptoPatel/status/2105696743883227183

## @zacodil (Vadim (AI, ⋈)) · 10-01 16:25 · ♥51 ↻3 💬4 Today SHIELD caught an attack on Intents itself.

$3.8M left through a bug in the Omni deposit and withdrawal path, isolated to USDT on BSC. SHIELD flagged the outlier behaviour, Intents paused, and the fix was in within an hour of detection. The attacker had been working the hole for over four hours before that. Without the detection he had the rest of the night.

Affected users are made whole in full. The NEAR protocol, the token and every other app on NEAR were untouched, because the bug lived in one application and not in the chain.

For scale, Intents moves over $4B a month and this is the first major exploit it has had. The loss is about a tenth of one percent of a single month of volume.

Seven withdrawals got through. The eighth did not. > 引用 @ilblackdragon: Earlier today, NEAR Intents was exploited for $3.8m. SHIELD, the AI security layer on Intents, detected outlier behavior and Intents were temporarily paused. All of the affected users will be compensated in full.

The attacker exploited a bug in the Omni deposit/withdrawal interaction with the NEAR Intents smart contract isolated to USDT on BSC. The Intents team quickly identified the exact vulnerability and it was fixed within an hour of detection. NEAR Intents and https://t.co/uilYXjPFHF are already back online, except for a few affected chains on Intents. The core NEAR Protocol, NEAR token, and other applications on NEAR were not affected.

NEAR Intents now processes over $4B a month in trading and payments volume, serving as the industry’s connector across chains and ecosystems. At this scale, we have to hold ourselves to a higher security standard. This was the first major exploit on Intents and we will apply all learnings from this incident as part of a full retro and postmortem.

The crypto space is entering a new era of far more sophisticated cyber attacks. Recently, we have seen BitGet, Metamask, Lido all being targeted by criminals equipped with AI systems that are continuously trying to hack all infrastructure. As a space, we need to be far more vigilant and raise the bar on both onchain contract standards and offchain monitoring and proactive prevention.

This includes incorporating formal verification, a key tool for preventing a large class of vulnerabilities. The NEAR ecosystem is already working on a formal verification system for NEAR contracts and will shortly implement it as part of the release process, alongside other security measures that will come out of the postmortem.

Being more proactive against criminal activity is a critical step to ensure the growth and legitimacy of crypto. It’s time to join forces and work together to use all tools at our disposal to detect and prevent malicious activity. SHIELD is our approach to monitoring and AI-based outlier detection. We welcome new SHIELD partners to work with us to share information faster and get better at detecting and containing criminals and exploits across web3. https://x.com/zacodil/status/2105695583528698160