NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
NEAR Intents confirmed an exploit of more than $3.8 million on October 1, 2026, closed the vulnerability and halted deposits and withdrawals on eleven networks. Full reimbursement of all affected funds has been promised; a date for it has not. If you have used the swap layer to move balances between two blockchains, one thing now decides above all: where your balance sits at this moment, and whether it has to stay there.
The price of NEAR stood at $4.90 on the afternoon of October 1, 2026, 6.96 percent below the previous day; over the week the value is up 7.66 percent. The price here is only the visible part, though. The more important part is an infrastructure through which, according to the operators, more than $30 billion has already flowed across 35 networks, and which was only partly usable for several hours.
What happened at NEAR Intents on October 1, 2026
NEAR Intents is the cross-chain swap layer in the orbit of the NEAR protocol. This layer takes in an intention, such as swapping a token on one blockchain for a token on another, and lets service providers compete to execute it. On Thursday, irregular withdrawals flowed out through a hot wallet of this layer. The damage, as the project describes it, amounts to more than $3.8 million.
The team publicly acknowledged the incident, closed the affected point in the smart contract and suspended deposits and withdrawals on several connected networks. Core operations were, by its own account, to resume quickly, while deposits and withdrawals stay down longer. That order matters more to you than the damage figure: a service that permits swapping but not withdrawing is not usable for you.
Hot wallet: what the term means here
A hot wallet is a wallet whose keys sit on a system connected to the internet, so that a platform can execute payments automatically. That access is the reason it is fast, and at the same time the reason it remains the preferred target of an attack. Set against it is the cold wallet, whose keys stay offline.
The fault sat between the Omni bridge and the Intents contract
The project describes the cause as a fault in the way the Omni system for deposits and withdrawals interacted with the NEAR Intents smart contract. It was not a single component that was defective, but the handover between two. That is the normal case in attacks on cross-chain infrastructure, and the reason audit reports on individual contracts say only so much: what is audited is usually the building block, what is exploited is the joint.
In this architecture Omni is the layer that accepts deposits from an external blockchain and releases withdrawals back to it. The Intents level above it decides what happens to the balance. Anyone who can get the order of the two levels out of step can trigger a withdrawal for which there was no valid deposit. The contract-side gap has been closed, according to the team.
Why a patch is not yet the all-clear
A closed contract fault prevents a repeat of the same attack. It says nothing about whether the same joint is still open elsewhere, and it does not bring back any funds that have flowed out. What counts for you is therefore not the notice about the patch but the release of withdrawals on the network where your balance sits.
Eleven networks without deposits or withdrawals: BNB Smart Chain, Polygon, TON and more
Affected by the suspension, according to the CoinDesk report, were BNB Smart Chain, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll and Plasma. This list is the day's actual finding. A single faulty handover point can shut down access to eleven different ecosystems at once, and the list shows at the same time how many chains now hang off a shared layer.
In practice that means a swap in progress whose counter-value was due to arrive on one of these networks could be left hanging. A balance already sitting on one of these chains was not automatically affected, as long as it was in a wallet of your own and not in the swap layer. The distinction between in my wallet and in transit within a service decides the damage in hours like these.

How ZachXBT traced the $3.8 million through KuCoin into bitcoin
The investigator ZachXBT, who publicly analyses on-chain traces, has retraced the movement: the irregular outflows began at a hot wallet on BNB Chain attributed to NEAR Intents. From there the funds went to the KuCoin exchange and were swapped into bitcoin. This chain is typical, because bitcoin offers the deepest liquidity and a move through an exchange breaks the trail as soon as accounts are interposed there.
The project says it has reported the incident to law enforcement and brought in security and analytics firms to follow the funds further. Whether an exchange freezes the amounts received is its own decision, and usually only after a formal request. There are no reliable statements about recovery on this day, and nobody should promise you any.
Hold your own assets in self-custodyFull reimbursement promised, date open: what happens to your balance in the gap
The team has promised to reimburse affected funds in full. No timetable was named. This combination is the most delicate point of the incident, because it creates a claim you can neither quantify nor date: your claim is against a project, not against a supervised institution with deposit protection.
In practice that means three things. Your balance in the swap layer is unavailable until release. A promised reimbursement without a date is a declaration of intent, not a due date. And as long as you have no evidence of the state of your balance before the incident, you carry the burden of proof for your own claim. A screenshot with a date and the transaction ID of the last swap are worth more at this point than any market analysis.
Anyone holding long-term positions should take the opportunity and put them where no third-party service stands between them and the key. Which devices and programmes come into question for that and how they differ is set out in the hardware wallet comparison. A swap layer is a passage, not a warehouse.
Cross-chain swaps, intents and solvers: how the swap layer works
An intent is a declaration of intention: you set out what you want to give up and what you want to receive, and leave the route there to others. A solver is the service provider that carries out this intention and earns on the price difference. A classic bridge, by contrast, locks your token on one chain and issues a representation of it on the other.
The difference is decisive for the risk question. With a bridge, the risk lies in the locked holding that backs the representations. With an intent system it lies in the deposit and withdrawal layer and in the hands of the solvers, who temporarily have other people's balances at their disposal. That is precisely the layer affected on October 1. For you that means the question is not whether a method is safe, but how long your balance is in a third party's hands at all.
How long your balance is in transit
A swap completed in seconds exposes you briefly to a failure. A swap whose counter-value arrives only minutes or hours later exposes you for a long time. A balance you leave sitting in the service after the swap exposes you permanently. The third variant is the most expensive and at the same time the most common, because it is convenient.
$50 million blocked a week ago, now hit itself
The same platform was on the other side of events the week before: back then the service intercepted some $50 million from the Bitget hack before the money could move on. We described that on September 30, 2026, under the title "NEAR Intents blocks $50 million from the Bitget hack". Seven days later, $3.8 million is missing from the same infrastructure.
No schadenfreude follows from that, but a sober insight. A platform able to stop other people's funds has deep insight into payment flows and correspondingly many points of contact. The same reach that makes a block possible creates the attack surface. Anyone who looks only at a service's capabilities and not at the number of its handover points is pricing the risk too cheaply.

What to check now on your own cross-chain holdings
Four concrete points are at stake, and none of them takes more than a few minutes.
- Open swaps: look through your history for a swap after September 30 that still stands without a matching entry. Note the time, the network and the transaction ID.
- Residual balance in the service: a balance left sitting in the layer after a swap belongs in your own wallet as soon as withdrawals are released again.
- Approvals in your wallet: revoke permissions you once granted a contract for unlimited amounts. An old approval keeps working even if you stopped using the service long ago.
- The network your balance is on: if it sits on one of the eleven suspended chains, wait for the release and do not attempt a detour through a second unfamiliar service.
What matters is the difference between waiting and doing nothing. Waiting means watching the situation, securing evidence, putting no new funds into the affected layer. Doing nothing means leaving a balance there and being unable to show later how much it was.
Providers with EU authorisationMiCA, custody and holding period: the German legal framework in an exploit
Since January 1, 2026, only authorised providers may offer crypto-asset services in Germany; the national transition periods in the EU expired on July 1, 2026 at the latest. A decentralised swap layer is not a supervised custodian, and that is exactly what the legal consequence hangs on: there is no deposit protection, no supervisory complaint to BaFin over a duty to provide a service, and no body that enforces a reimbursement.
Anyone wanting to draw this line cleanly in daily use buys and sells through an authorised provider and uses cross-chain routes only for the purpose they were built for. An overview of providers with European authorisation is in the hub on regulated crypto exchanges. That replaces no judgement of your own, but it moves the part of your assets entrusted to a third party into a framework with obligations.
What a reimbursement does to your holding period
The one-year holding period under German income tax law attaches to the acquisition and disposal of the same asset. Whether a reimbursement counts for tax as a reversal or as a new acquisition depends on how it is technically executed: whether the same token comes back or a counter-value in another currency. You should document that distinction before the reimbursement happens, not after.
How NEAR reacted to the exploit: $4.90 and 6.96 percent down
The NEAR price stood at $4.90 on the afternoon of October 1, 2026, after a day's high of $5.52 and a day's low of $4.79. The loss of 6.96 percent against the previous day makes NEAR the weakest value among the 25 largest cryptocurrencies that day; the market capitalisation is around $6.4 billion, daily turnover some $1.4 billion. Over seven days a gain of 7.66 percent still stands. The figures come from CoinGecko.
These numbers describe a reaction, not a valuation. A decline of almost 7 percent on damage of $3.8 million shows that the market classes the sum itself as small and the interruption of the swap layer as the costlier part. How things go from here depends on how quickly deposits and withdrawals run again on all eleven networks.
A month of heavy losses as the backdrop
The incident does not stand alone. On September 30, 2026 we compiled the finding that crypto hacks caused losses of $766 million within a month. Against that backdrop $3.8 million is a small item, and for that very reason the lesson from it is the more important one: it is not only the large sums that are hit, and not only the unknown projects.
Tax after a hack: how to document the loss and the reimbursement
For a German tax return, what you can evidence is what counts. Secure the following now rather than later: the holding before the incident with its date, the transaction IDs of the affected operations, the project's public statement with its date, and every later credit with its amount and time. A loss that cannot be evidenced has no effect for tax, and a reimbursement whose origin you cannot explain prompts questions.
Whether a loss from a theft is deductible at all has not been conclusively settled in Germany and depends on the individual case; only a tax adviser or the tax office can give a binding answer on that. The first step is undisputed: a complete, timely record. How the basic rules on holding period, allowance and reporting obligations interact is set out in our overview of crypto tax in Germany.
The NEAR Intents exploit: what to take away
- Secure your evidence, today. The holding before the incident, the transaction IDs, the date of the project's statement. For the ongoing bookkeeping of your holdings, one of the tools from the hub on tax tools and portfolio trackers helps.
- Take long-term holdings out of the passage. What you intend to hold for longer does not belong in a swap layer. Which programmes allow self-custody on a phone or a computer is shown by the software wallet comparison.
- Separate the buying route from the swapping route. Regular purchases through an authorised provider, cross-chain routes only for the specific purpose. The selection is in the hub on the best crypto exchanges.
Sources for further reading: the report by CoinDesk of October 1, 2026 with the list of affected networks and ZachXBT's findings, and the NEAR Intents documentation on how intents and solvers work.
(As of October 1, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about NEAR Intents
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- NEAR Intents at $169 Million: What to Check Before a Cross-Chain Swap
- Chainflip Hack on Tron: How to Check Whether Your USDT Swap Is Still Stuck
- Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
- Breaking: Trust Wallet Chrome Extension Hack Drains $7M, Full Reimbursements Promised
- Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
April 21, 2026 2:00 PM

LayerZero Security Alert: Is Your Crypto Safe After the $292M KelpDAO Exploit?
A $292M exploit on KelpDAO exposes a massive LayerZero vulnerability. With 47% of apps at risk, are your assets still safe in the crypto space?
August 19, 2026 7:27 AM

Blockchain Rollback After an Exploit: What Happens to Your Tokens When a Chain Is Reset
At Harmony, roughly four billion ONE were minted without authorisation, and a rollback of the chain has been on the table ever since. This piece explains what a blockchain rollback means technically, when it can still succeed, and what it triggers for your holding period.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 30, 2026 10:38 PM

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
August 22, 2026 10:39 AM

Maya Protocol Exploit: MAYAChain Is Halted, What to Check Now on Cross-Chain Swaps
On August 18, 2026 an attacker drew roughly $1.65 million out of MAYAChain's liquidity pools through six chained faults, and the team then halted the chain globally. Anyone who swapped or provided liquidity there can check in a few minutes whether their own money is stuck in the halted system.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
May 15, 2026 9:47 AM

Top 10 Altcoins to Buy in May 2026 as Bitcoin Recovers
Here are the top 10 altcoins to buy in May 2026 as Bitcoin rebounds near $80K and market momentum shifts.
September 26, 2026 4:14 PM

Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
Bitget is releasing the withdrawals frozen after the September 24 incident in four stages from September 28. For a residual balance held from Germany that is a deadline, not a reason to wait.
September 13, 2026 4:13 AM

Symbiosis Hack: How to Check Whether Your Bridged Bitcoin Can Still Get Out
An attacker minted billions of unbacked syBTC on the cross-chain bridge Symbiosis and pulled out roughly $336,000. We checked for ourselves on September 12 which routes are still running: the way into the bridge is suspended, the way out is open.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
July 7, 2023 9:14 AM

Breaking News: Multichain Potentially Compromised in a Major Exploit Exceeding $126 Million
Multichain Potentially Compromised in a Major Exploit Exceeding $126 Million. Let's take a look at this breaking news in more detail.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
February 21, 2025 9:55 PM

Bybit Hack Revealed: Here's the Mastermind Behind the $1.46 Billion Theft
The Bybit hack has been traced back by the blockchain investigator ZachXBT, with conclusive evidence linking the hackers to the $1.46 billion theft. Full details revealed...
May 23, 2025 6:49 PM

Cetus Hack on Sui Network: What Happened and Why SUI Price Is Crashing
A $260 million exploit on Sui’s top DEX, Cetus Protocol, has triggered panic across the ecosystem. Here's what really happened, how Sui is responding, and what it means for the SUI token price.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 16, 2026 1:28 PM

Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Seven of ten providers available in Germany offer a payout to a wallet address you control yourself; three do not. Our survey of September 16, 2026, shows how to spot the difference before you buy, and why the question matters right now.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
September 29, 2026 7:12 PM

MEXC Refunds $340,000: The Attacker's API Key Survived the Account Freeze
During an account takeover at MEXC, an attacker created an API key with withdrawal rights that the exchange did not revoke when it restored the account. Twenty-seven minutes after the withdrawal freeze expired, roughly $340,000 was gone.
August 31, 2026 4:12 AM

Cronos chain halt: how a Tectonic exploit emptied the chain's largest lending market
On August 30, 2026, the validators of the Cronos chain halted block production after an attacker had emptied the lending market Tectonic via an inflated TONIC price. What is established, why the damage figures diverge, and what you can check if your balance sits on a haltable chain.
More from CryptoTicker
