# bridge exploit — X 热门讨论 (2026-10-01 21:52 UTC)

## @LibertySwapFi (Liberty Swap | C.R.O.P.S. on PulseChain 🗽) · 10-01 20:27 · ♥22 ↻0 💬1 We do not yet know the exact mechanics of the exploit.

Based on the information available so far, the issue appears to have occurred somewhere in the deposit/withdrawal handoff or accounting between the Omni infrastructure and the NEAR Intents contract, allowing the attacker to trigger unauthorized USDT outflows.

The flow can be simplified as:

BNB Chain USDT treasury ↔ Omni accounting/message layer ↔ NEAR Intents contract

On-chain reporting indicates that approximately 3.87M USDT moved from a BNB Chain contract identified in NEAR Intents documentation as the HOT Bridge treasury address.

For PulseChain users, an important clarification: the “Omni” involved with NEAR Intents is not the same OmniBridge/TokenBridge system used by the PulseChain Main Bridge. They are separate systems with different architectures.

PulseChain OmniBridge

Ethereum token → bridge contract → validator/message mechanism → representation on PulseChain

HOT / NEAR Intents Omni

BSC USDT → locker contract → MPC validation → Omni Balance on NEAR → NEAR Intents > 引用 @ilblackdragon: Earlier today, NEAR Intents was exploited for $3.8m. SHIELD, the AI security layer on Intents, detected outlier behavior and Intents were temporarily paused. All of the affected users will be compensated in full.

The attacker exploited a bug in the Omni deposit/withdrawal interaction with the NEAR Intents smart contract isolated to USDT on BSC. The Intents team quickly identified the exact vulnerability and it was fixed within an hour of detection. NEAR Intents and https://t.co/uilYXjPFHF are already back online, except for a few affected chains on Intents. The core NEAR Protocol, NEAR token, and other applications on NEAR were not affected.

NEAR Intents now processes over $4B a month in trading and payments volume, serving as the industry’s connector across chains and ecosystems. At this scale, we have to hold ourselves to a higher security standard. This was the first major exploit on Intents and we will apply all learnings from this incident as part of a full retro and postmortem.

The crypto space is entering a new era of far more sophisticated cyber attacks. Recently, we have seen BitGet, Metamask, Lido all being targeted by criminals equipped with AI systems that are continuously trying to hack all infrastructure. As a space, we need to be far more vigilant and raise the bar on both onchain contract standards and offchain monitoring and proactive prevention.

This includes incorporating formal verification, a key tool for preventing a large class of vulnerabilities. The NEAR ecosystem is already working on a formal verification system for NEAR contracts and will shortly implement it as part of the release process, alongside other security measures that will come out of the postmortem.

Being more proactive against criminal activity is a critical step to ensure the growth and legitimacy of crypto. It’s time to join forces and work together to use all tools at our disposal to detect and prevent malicious activity. SHIELD is our approach to monitoring and AI-based outlier detection. We welcome new SHIELD partners to work with us to share information faster and get better at detecting and containing criminals and exploits across web3. https://x.com/LibertySwapFi/status/2105756581451497902