# protocol exploit — X 热门讨论 (2026-10-01 15:53 UTC)

## @ilblackdragon (Illia (root.near) (🇺🇦, ⋈)) · 10-01 15:50 · ♥37 ↻2 💬4 Earlier today, NEAR Intents was exploited for $3.8m. SHIELD, the AI security layer on Intents, detected outlier behavior and Intents were temporarily paused. All of the affected users will be compensated in full.

The attacker exploited a bug in the Omni deposit/withdrawal interaction with the NEAR Intents smart contract isolated to USDT on BSC. The Intents team quickly identified the exact vulnerability and it was fixed within an hour of detection. NEAR Intents and https://t.co/uilYXjPFHF are already back online, except for a few affected chains on Intents. The core NEAR Protocol, NEAR token, and other applications on NEAR were not affected.

NEAR Intents now processes over $4B a month in trading and payments volume, serving as the industry’s connector across chains and ecosystems. At this scale, we have to hold ourselves to a higher security standard. This was the first major exploit on Intents and we will apply all learnings from this incident as part of a full retro and postmortem.

The crypto space is entering a new era of far more sophisticated cyber attacks. Recently, we have seen BitGet, Metamask, Lido all being targeted by criminals equipped with AI systems that are continuously trying to hack all infrastructure. As a space, we need to be far more vigilant and raise the bar on both onchain contract standards and offchain monitoring and proactive prevention.

This includes incorporating formal verification, a key tool for preventing a large class of vulnerabilities. The NEAR ecosystem is already working on a formal verification system for NEAR contracts and will shortly implement it as part of the release process, alongside other security measures that will come out of the postmortem.

Being more proactive against criminal activity is a critical step to ensure the growth and legitimacy of crypto. It’s time to join forces and work together to use all tools at our disposal to detect and prevent malicious activity. SHIELD is our approach to monitoring and AI-based outlier detection. We welcome new SHIELD partners to work with us to share information faster and get better at detecting and containing criminals and exploits across web3. > 引用 @near_intents: Earlier today NEAR Intents services were stopped after a security incident was detected. The incident was caused by a bug in the Omni deposit and withdrawal infrastructure interaction with NEAR Intents smart contract.

The preliminary report indicates the total loss of approximately $3.8M. These funds will be compensated in full.

The contract-side vulnerability has been patched. The operations of the NEAR Intents and near(.)com are expected to resume within 1h.

Deposits and withdrawals on the following networks will remain unavailable for an additional ~12 hours while fixes to the Omni infrastructure are completed: BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, LayerX, Adi, Scroll and Plasma.

In case users hold any assets from these chains inside NEAR Intents (for example, in HOT wallet or on near(.)com), they will be able to swap them into other assets once NEAR Intents is back up (in ~1h).

The incident has been reported to law enforcement, and we are working with security and blockchain analytics partners to trace the funds and pursue recovery. A detailed report will be shared publicly in the following days. https://x.com/ilblackdragon/status/2105686871200366663

## @MARAFoundation_ (MARA Foundation) · 10-01 14:01 · ♥28 ↻4 💬4 Veteran Bitcoin Core Contributor, Peter Todd, Joins MARA Foundation as Lead Maintainer of Slipstream https://x.com/MARAFoundation_/status/2105659425054748922

## @RaymondMontreal (RayMontreal) · 10-01 14:16 · ♥20 ↻1 💬7 Three days ago @near_intents was the industry's security hero for blocking Bitget hacker funds

Today it lost 3.8M $ to an exploit

The protocol that froze stolen money couldn't freeze its own

@laurashin you are crypto journalist, I look forward to your coverage of this > 引用 @laurashin: Did THORChain Just Hand the DOJ an Easier Case Than Tornado Cash?

Attackers drained roughly $388M from @bitget. 🔓

On @bitsandbips, @austincampbell argues @THORChain's refusal to block the funds was an active choice, while @perkinscr97 and @ramahluwalia say weak security is pushing users back to intermediaries.

Timestamps: 🚨 01:28 How attackers took $388M from Bitget without stealing a single private key 🔌 06:57 Why Austin says THORChain's past chain pauses undercut its neutrality defense 🎯 09:43 Counterhacking and consequences: how to stop state-backed crypto thieves 🌊 18:37 1inch Aqua: Back multiple liquidity positions with one wallet balance at https://t.co/2ZfndbOT6F 📈 19:45 Rate hikes everywhere and a US 10-year at its highest since 2007 💡 22:03 Is it time to buy bonds? Why Ram would rather own utilities 🏗️ 33:52 Will credit markets, not regulators, discipline the AI buildout? 🤖 42:14 Why AI agents aren't legal persons and how product liability applies 💸 54:57 Why Chris sees the best venture setup in years at crypto, AI, and quantum https://x.com/RaymondMontreal/status/2105663222946640183

## @AMLBotHQ (AMLBot) · 10-01 13:15 · ♥22 ↻3 💬1 🚨 Suspicious activity involving @near_intents: ~$4M in withdrawals

Our monitoring has flagged a series of suspicious withdrawals totaling approximately $4M

At this stage, it is not clear whether this is an exploit of the protocol or whether the funds may be connected to another incident

Suspicious txs: 0x9fe58e031f73bbd880c782bc9e7446bcda32cadb304a729209871a4a81856c4c 0x0381265d6a1bb09de899f49f410a8b907cd548358a7e3c91076c3a52656b8220 0x69d1c68c7e961a0199d3c9f3b6a31cb168ed775ef34b51a42762253ac1efcceb 0x9c10b967da0c85631ec105e3b322c0a851fcd01b69ff390ff58f860e5cce003a

Our tracing indicates that funds are currently moving toward @kucoincom, with some funds bridged to BTC

We are actively monitoring the situation and will share updates as they become available, pending official confirmation of security incident from NEAR Intents https://x.com/AMLBotHQ/status/2105647685705597403