NEAR Intents has paused services after an exploit drained nearly $3.8 million, but this isn’t a case of the NEAR blockchain itself being compromised. The core issue sits in the Omni deposit and withdrawal layer, the connective tissue that lets users move assets in and out for cross-chain swaps. NEAR Intents is built to make those multi-chain moves seamless, handling all the bridging and settlement behind the scenes. That convenience comes with its own risk: if the routing infrastructure breaks, every user relying on it is exposed.
The bug meant actors could exploit that transfer layer’s interactions with the NEAR Intents smart contract, but the underlying base chain remained secure. The operational response was immediate: services were halted, the vulnerability patched, and a public commitment made to fully reimburse affected users. Deposits and withdrawals across 11 separate networks were also disrupted.
This incident narrows the blast radius to that crucial middleware layer, the very part abstracting user friction but hiding much of the technical risk. It’s not evidence of failed chain-level security, but a sharp reminder that composable systems tend to concentrate risk where it’s least visible. For users and developers, the real question now is whether patching this isolated component is enough, or if intent-based systems need new rules for limiting risk as they streamline cross-chain design.