NEAR Intents Suspends Operations After $3.8M Exploit Through Omni Bridge Infrastructure
How the Omni Bridge Exploit Unfolded Across Chains
NEAR Intents temporarily stopped all services on October 1, 2026, after discovering a critical vulnerability in its Omni deposit and withdrawal system that allowed approximately $3.8 million in digital assets to be drained across multiple blockchain networks. The platform immediately froze operations while developers investigated the root cause of the exploit.
Breaking news:
The security incident centered on flaws within the Omni infrastructure, which facilitates cross-chain deposits and withdrawals for the NEAR ecosystem. Attackers exploited the vulnerability to siphon funds from connected networks, triggering automated safety measures that halted all bridge activities. The company confirmed no user funds were permanently lost, though transactions remain paused pending a full security audit.
The Omni bridge serves as a critical liquidity gateway, enabling users to move assets between NEAR and other major blockchains including Ethereum, Bitcoin, and various Layer 2 networks. When the vulnerability was detected, the system's emergency protocols automatically suspended all deposit and withdrawal functions to prevent further fund movement. Blockchain analysis firms reported unusual transaction patterns originating from the Omni contract addresses, with funds rapidly dispersing across decentralized exchanges and mixing protocols within minutes of the initial breach.
What Recovery Measures Are Being Implemented?
Security researchers noted that the exploit leveraged a reentrancy vulnerability combined with insufficient validation checks in the cross-chain messaging layer. The attack vector allowed malicious actors to initiate withdrawals while simultaneously manipulating the system's balance tracking mechanisms, effectively creating phantom deposits that could be converted into real assets on destination chains.
The NEAR Intents team has partnered with leading cybersecurity firms to conduct a comprehensive review of the entire Omni infrastructure. All smart contracts have been placed under audit, with particular focus on the cross-chain communication protocols that were compromised. The company announced plans to implement enhanced validation layers and upgrade the bridge's core architecture before resuming operations.
Affected users have been advised to monitor official communication channels for updates on fund recovery procedures. The incident has raised broader questions about the security standards governing cross-chain bridge protocols, which have collectively suffered over $2 billion in exploits since 2022.
Frequently Asked Questions
How much money was stolen from NEAR Intents? Approximately $3.8 million was drained through the Omni bridge vulnerability before emergency protocols halted all operations. The funds moved across multiple blockchain networks including Ethereum and Bitcoin.
Are user funds safe after the NEAR Intents exploit? The company confirmed that no user funds were permanently lost, though all transactions remain frozen while security audits are completed. Users are advised to await further instructions regarding fund access and recovery procedures.
When will NEAR Intents services resume? Services will remain suspended until comprehensive security upgrades are implemented and third-party audits verify the fixes. The team has not provided a specific timeline for resumption, emphasizing that security takes priority over operational speed.
More stories: