Ledger Nano X - The secure hardware wallet

NEAR Intents Suffers $3.8M Security Breach in Smart Contract Vulnerability

Key Points

  • A security vulnerability resulted in approximately $3.8 million being drained from NEAR Intents, a cross-chain cryptocurrency exchange platform, on Thursday.
  • The vulnerability originated from a flaw in the Omni deposit and withdrawal mechanism’s interaction with NEAR Intents’ smart contract infrastructure.
  • Operations were immediately suspended, with deposit and withdrawal functions frozen across eleven different blockchain ecosystems.
  • The platform has committed to providing complete compensation to all users who experienced losses.
  • Blockchain sleuth ZachXBT identified the movement of stolen assets through KuCoin before conversion to bitcoin.

NEAR Intents, a cross-chain cryptocurrency exchange protocol, became the latest victim of a security exploit on Thursday, resulting in approximately $3.8 million in stolen digital assets.

The protocol immediately suspended operations following discovery of the breach. All deposit and withdrawal functionalities were temporarily frozen across multiple blockchain networks as developers implemented emergency security measures.

Root Cause of the Security Breach

According to NEAR Intents’ official statement, the vulnerability stemmed from a defect within its Omni deposit and withdrawal infrastructure. This component failed to properly communicate with the NEAR Intents smart contract, leaving an exploitable weakness.

The development team confirmed that the smart contract vulnerability has been addressed and resolved. Primary platform services were anticipated to be restored approximately one hour following the initial disclosure.

Nevertheless, deposit and withdrawal capabilities on eleven blockchain networks remained temporarily disabled. The affected networks encompassed BNB Smart Chain, Polygon, Optimism, Avalanche, Stellar, TON, Monad, X Layer, ADI, Scroll, and Plasma.

NEAR Intents announced its commitment to provide complete restitution to every user impacted by the security incident. The organization confirmed collaboration with blockchain forensics specialists and has filed formal reports with relevant law enforcement authorities.

A comprehensive post-incident analysis is scheduled for publication in the near future.

Tracking the Stolen Assets

On-chain investigator ZachXBT published findings about the attack through Telegram. He identified that the breach originated with suspicious withdrawal activity from a BNB Chain hot wallet associated with NEAR Intents.

ZachXBT’s analysis revealed that the compromised funds were transferred to cryptocurrency exchange KuCoin. Subsequently, the assets were converted and bridged into bitcoin.

The Block contacted KuCoin requesting commentary but had not received any response by publication time.

NEAR Intents operates as an intent-based exchange where users define their desired transactions. Specialized market makers known as solvers then competitively execute these trades behind the scenes. The platform claims to have facilitated over $30 billion in total transaction volume spanning 35 different blockchain networks, based on information from its official website.

The NEAR token, which maintains close associations with the NEAR Intents ecosystem, experienced a decline of approximately 6% to 6.7% during the twenty-four hour period after the breach became public. The token was valued around $4.96 as of press time.

The incident’s timing also impacted the recently introduced Bitwise NEAR exchange traded fund, which had commenced trading merely forty-eight hours prior. The ETF declined approximately 6.4%, eliminating previous session gains.

This security incident contributes to an ongoing pattern of cryptocurrency vulnerabilities throughout the year. The previous week saw exchange platform Bitget experience a separate breach involving more than $350 million in compromised assets.

Additional significant breaches this year include Liquid Network at approximately $320 million, Drift at $295 million, and Kelp at $293 million, based on DefiLlama’s compiled data.

The NEAR Intents security breach occurred roughly six weeks following the platform’s milestone announcement of surpassing $25 billion in cumulative trading volume. NEAR Intents has indicated it will provide additional information regarding the incident’s technical details and remediation efforts in its forthcoming comprehensive post-mortem analysis.

The post NEAR Intents Suffers $3.8M Security Breach in Smart Contract Vulnerability appeared first on Blockonomi.