Cross-Chain Swap Layer Halts Operations Across Eleven Networks
NEAR Intents, a prominent cross-chain swap layer operating within the NEAR protocol ecosystem, has confirmed a security breach resulting in the loss of more than $3.8 million on October 1, 2026, according to CryptoTicker. Following the irregular outflow of funds, the project team immediately closed the vulnerable point in its smart contract and suspended all deposits and withdrawals across eleven connected blockchain networks.
The affected networks include BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma. While the protocol operators stated that core internal operations would resume quickly, deposits and withdrawals remain frozen indefinitely. This distinction is critical for users: a cross-chain interface that permits asset swapping but locks outbound transfers leaves user balances temporarily inaccessible.
The Technical Root: Omni Bridge and Intents Contract Interaction
According to the project’s technical breakdown, the vulnerability did not stem from a single isolated smart contract, but rather from the complex handover between the Omni deposit-and-withdrawal layer and the upper-level NEAR Intents contract. In cross-chain architectures, Omni handles inbound deposits from external blockchains and releases withdrawals, while the Intents layer coordinates token swaps executed by competing service providers known as solvers.
Investigators determined that an exploit in the sequencing between these two layers allowed unauthorized withdrawals to bypass the standard deposit verification checks. On-chain investigator ZachXBT publicly traced the stolen $3.8 million from a BNB Chain hot wallet associated with NEAR Intents to the KuCoin exchange, where the illicitly acquired assets were subsequently swapped into Bitcoin to obscure the transaction trail.
The Hacker’s Ultimatum and Reimbursement Uncertainty
Adding immediate pressure to the incident, security researcher Alex Shevchenko publicly reported that the hacker behind the NEAR Intents breach issued a direct 48-hour ultimatum demanding terms before potentially dispersing the remaining stolen funds, as detailed by The Defiant. The sudden demand complicates ongoing recovery efforts by law enforcement and analytics firms brought in by the project.
While the NEAR Intents team has publicly promised a full reimbursement of all affected user funds, no specific timetable has been established. Because decentralised swap layers operate outside traditional banking frameworks and supervised deposit protection schemes under regulations like the European Union’s MiCA framework, user claims currently rely entirely on the project’s voluntary compliance rather than enforceable legal guarantees.
Immediate Safety Checks for Crypto Holders
Security analysts urge users interacting with cross-chain liquidity layers to take immediate precautions to safeguard their remaining assets:
- Inspect Open Swaps: Review transaction histories for any incomplete swaps initiated after September 30 that lack matching ledger entries, and save corresponding transaction IDs.
- Revoke Smart Contract Permissions: Disconnect legacy token approvals granted to third-party contracts for unlimited spending amounts.
- Avoid Suspicious Detours: Wait for official network re-enactments rather than attempting risky manual workarounds across unverified secondary bridges.

