Crypto Prices

Security Flaw in NEAR Intents Results in $3.8 Million Fund Loss as Recovery Efforts Unfold

1 hour ago
1 min read
2 views

NEAR Intents Suspends Services Due to Major Bug

NEAR Intents has temporarily suspended its services due to a significant bug in its Omni deposit and withdrawal system that resulted in a staggering loss of approximately $3.8 million. The organization has committed to fully compensating affected users.

Details of the Incident

According to on-chain investigator ZachXBT, the stolen funds did not remain idle; they were swiftly moved, first funneling towards Kucoin and subsequently converted into Bitcoin. Repair efforts continue for several affected networks, which remain offline at this time.

The incident came to light on Thursday morning when NEAR Intents detected the vulnerability that drained their reserves. This flaw, linked to the interaction between their Omni infrastructure and the associated smart contract, prompted the immediate shutdown of the service operations at near.com and beyond.

“Our initial findings show a total loss of around $3.8 million, and we guarantee that all impacted funds will be reimbursed fully.”

The vulnerability had a critical point where two aspects of their system communicated, which has since been rectified. The team anticipates that core services will be restored shortly, within approximately an hour.

Impact on Network Functionalities

Despite this progress, the broader network functionalities remain compromised. Users will be unable to conduct deposits or withdrawals on various chains like BSC, Polygon, and Avalanche for an estimated 12 hours while repairs on the Omni infrastructure take place. Notably, ZachXBT highlighted that irregularities were noted in the BSC hot wallet before operations ceased.

The funds were reportedly moved quickly after the exploit, directly transitioning to Kucoin and then routed into Bitcoin, demonstrating the urgency of the response. NEAR Intents reassured users that once the service resumes, they should be able to manage their assets secured within the temporarily disabled chains, whether through HOT Wallet or near.com.

Next Steps and Ongoing Investigation

In light of the incident, the company has alerted law enforcement authorities and engaged with security and blockchain analytics firms to trace the misappropriated funds. They promise a comprehensive follow-up report will be shared soon. Although the bug is addressed, the lost $3.8 million has already been transferred elsewhere.

This situation is ongoing, and further developments are anticipated in the days ahead, especially in light of recent trends in the cryptocurrency market where privacy coins have gained traction over larger altcoins.

Popular