A poorly secured smart contract, $3.8 million drained in a matter of moments, and deposits locked across eleven separate networks. NEAR Intents is facing a major crisis that raises serious questions about the resilience of cross-chain protocols.
The team responded quickly by patching the vulnerability and pledging full compensation to affected users. But services remain partially paralyzed, and confidence in the protocol is being put to the test.
Here is everything we know about this exploit, its operational fallout, and what it reveals about the persistent risks embedded in multi-chain DeFi infrastructure.
A Vulnerable Contract, a Surgical Attack
NEAR Intents is an intent-based abstraction protocol that allows users to execute cross-chain transactions in a simplified manner. It is precisely within this execution mechanism that the attacker identified a critical flaw at the level of the underlying smart contract.
According to the information available so far, the exploited vulnerability allowed the attacker to manipulate the intent settlement logic, opening the door to an unauthorized drain of deposited funds. The total amount stolen stands at $3.8 million, a significant sum that places this incident among the most notable DeFi exploits of 2026.
The NEAR Intents team confirmed that it identified and patched the contract-level vulnerability within hours of the attack. This kind of rapid response has become an expected standard across the ecosystem, but it is not enough to undo the damage caused or to immediately restore trust among users and integrators.
Eleven Networks Impacted, Deposits and Withdrawals Still Frozen
The service suspension is not limited to a single network. Deposits and withdrawals remain disabled across 11 blockchains connected to the protocol, illustrating the contagion effect that is inherent to cross-chain infrastructure. When one link in the chain breaks, the entire operational stack can grind to a halt.
This prolonged outage poses a real risk to users who have funds in transit or awaiting settlement. In a DeFi environment where liquidity is often actively deployed, every hour of downtime can generate additional indirect losses, particularly through missed opportunities or positions that cannot be closed.
NEAR Intents has formally committed to full compensation for all users affected by the exploit. The precise terms of this reimbursement — timeline, mechanism, and source of funds — had not yet been publicly disclosed at the time of publication. This is a key point for affected holders to monitor closely in the coming days.
A Wake-Up Call for Intent-Based Cross-Chain Protocols
This incident is part of a broader trend: intent-based protocols have become a prime target for hackers throughout 2025 and 2026. Their architectural complexity — combining resolvers, relayers, and multi-chain contracts — multiplies the potential attack surface. Every abstraction layer added to improve the user experience mechanically introduces new risk vectors.
For the NEAR ecosystem, this exploit comes at a sensitive moment. The network is working to establish itself as a go-to infrastructure for large-scale decentralized applications, particularly through its sharding capabilities and cross-chain ambitions. A security incident of this magnitude can slow institutional adoption and delay integrations that are currently under negotiation.
The team’s response — a swift patch, transparent communication, and a commitment to reimbursement — represents the bare minimum in DeFi crisis management. The real question is one of preventive auditing: had the exploited contract undergone an independent security review before being deployed to production? The answer to that question will largely determine the protocol’s credibility going forward.