The NEAR Intents protocol suffered a $3.8 million theft on Thursday, but the team’s exemplary crisis management — a fix within one hour, full reimbursement announced, and cooperation with authorities — has turned this hack into a resilience test for the cross-chain DeFi ecosystem.
🔑 Key Takeaways
- The attacker exploited a flaw in the software layer handling fund inputs and outputs.
- $3.8M stolen and laundered through KuCoin in bitcoin according to ZachXBT.
- NEAR Intents has processed over $30 billion in swaps across 35 networks.
- NEAR token drops ~9% to $4.86, Bitwise NEAR ETF loses more than 7%.
- All affected users will be fully reimbursed by the team.
1. Anatomy of the Hack
The attack targeted the software layer responsible for managing fund flows within NEAR Intents, as well as its interaction with the main contract holding user funds. NEAR Intents is a cross-chain cryptocurrency swap service that emphasizes transaction privacy by masking counterparties and amounts. The tool has established itself as a major player in the sector: the platform reports a cumulative volume exceeding $30 billion in swaps spread across 35 blockchain networks.
The attacker’s modus operandi has not yet been fully detailed, but early analysis points to an orchestration vulnerability between the protocol’s modules. Blockchain research team ZachXBT quickly traced the stolen funds: converted to bitcoin then deposited on the KuCoin exchange, a platform often used as an exit point by hackers due to its deep liquidity and variable regulatory tolerance depending on jurisdiction.
2. Crisis Management in Under One Hour
The NEAR Intents team’s response has been praised by several industry observers. The sequence of actions taken since the vulnerability was detected illustrates an operational discipline now expected in professional DeFi (decentralized finance).
Detailed timeline
| Event | Timing |
|---|---|
| Vulnerability detection | T0 |
| Service shutdown | T+several minutes |
| Faulty contract patched | < 1 hour |
| Core services restored | ~1 hour |
| Full recovery (11 networks) | T+13 hours |
Deposits and withdrawals on 11 blockchain networks — including BNB Chain, Polygon, and Optimism — remained suspended for an additional 12 hours after core services resumed, time needed to deploy a complete fix and audit the entire infrastructure. The company confirmed that all affected users will be fully reimbursed.
3. Impact on NEAR Token and Bitwise ETF
The market reacted instantly to the news. The NEAR token fell nearly 9%, sliding to $4.86 according to available data. Even more revealing: the Bitwise NEAR ETF, launched just two days before the incident, lost more than 7% of its value. This unfortunate timing placed Bitwise in a delicate situation, as the ETF had been presented by the company as “proof of NEAR network growth.”
The combined drop in the underlying asset and the derivative product illustrates the sensitivity of crypto financial instruments to security incidents, even when the scale of the damage remains contained. For asset managers launching crypto ETFs, the message is clear: security monitoring has become as crucial as the technical performance of the underlying protocol.
4. Comparison with Other Recent Incidents
The NEAR Intents incident fits into a series of security events that have marked the crypto ecosystem in recent weeks. This perspective helps relativize the scale of the hack and assess the maturity of each player’s response.
| Protocol | Amount lost / impact | Downtime |
|---|---|---|
| NEAR Intents | $3.8M | ~13 hours |
| Kelp DAO | Several hundred M$ | Under analysis |
| Bitget (exchange) | $387.5M | 4 days of withdrawal freezes |
| MetaMask | Validator withdrawal | Minimal communication |
The gap between $3.8 million and several hundred million dollars highlights both the maturity of detection mechanisms and the importance of a segmented architecture to limit the propagation of vulnerabilities. By that yardstick, NEAR Intents’ response ranks among the most structured in the sector.
5. A “Bullish Hack”?
The handling of the incident has led several analysts to use a provocative term: “bullish hack.” The parallel is drawn with the self-exploitation discovered by the ZCash team, a case where the rapid disclosure of a vulnerability had paradoxically strengthened confidence in the project. Tyler Warner, author of Decrypt’s Morning Minute newsletter, summarizes this perception:
“This is pretty much the best-case scenario for such a bad event.”
Tyler Warner, Author of Morning Minute (Decrypt)
Six ingredients of a bullish hack
- Rapid bug identification and immediate service shutdown.
- Patch applied in under one hour.
- Transparent public communication.
- Direct contact with law enforcement.
- Commitment to full user compensation.
- Refusal to downplay the incident or sweep it under the rug.
The incident also occurs a few days after NEAR Intents publicly denied any link to a hacker suspected of being affiliated with North Korea and considered responsible for the Bitget exchange hack. This stance reinforces the team’s credibility in its willingness to cooperate with authorities.
Conclusion
The NEAR Intents episode illustrates the new standard of crisis management in DeFi: rapid detection, transparent communication, and full reimbursement commitment. While the hack remains a warning signal about the growing complexity of cross-chain protocols, the team’s response could paradoxically strengthen institutional confidence in the medium term, provided the post-mortem audit is made public.
The scenario to watch remains the following: if the full reopening proceeds without new incident and reimbursements are effectively executed within 30 days, the NEAR token could recover its pre-hack level. Conversely, the discovery of a second flaw or a delay in compensation would shift the narrative from “bullish hack” to lasting distrust, mirroring what other protocols have experienced after reimbursement announcements that never materialized.
Sources
- Decrypt — Morning Minute: NEAR Intents Hacked for $3.8M
- Yahoo Finance — Morning Minute: NEAR Intents Hacked
- Bitcoin News — MetaMask Pulls Validators
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

