A DeFi protocol exploited for $3.8 million — on paper, that’s a disaster. But what happened in the hour following the attack on NEAR Intents left the crypto community stunned.
From a bug fix deployed in under 60 minutes, to transparent communication and a commitment to full reimbursement of affected users, the team turned a potentially fatal crisis into a textbook example of incident management. Yet the underlying question remains wide open: is the security of cross-chain protocols still up to the challenge?
A deep dive into a hack that, paradoxically, could end up strengthening confidence in the NEAR ecosystem.
A Surgical Exploit Targeting NEAR’s Cross-Chain Infrastructure
NEAR Intents is the cross-chain asset trading infrastructure built on the NEAR protocol. It allows users to swap tokens across different blockchains through a system of decentralized market makers. It was precisely this interoperability layer that the attacker chose to target.
According to initial on-chain analysis, the exploit drained $3.8 million by taking advantage of a vulnerability in the transaction validation logic. The exact attack vector has not yet been fully disclosed publicly — a standard precaution to prevent copycat attacks on similar protocols. Funds were extracted across multiple tokens, with a portion quickly converted through DEXs to obscure the trail.
This type of attack on bridges and interoperability protocols is nothing new: Ronin Network ($625M), Wormhole ($320M), Nomad ($190M) — the list of cross-chain exploits is long and painful. NEAR Intents escaped with a significantly smaller loss, but the nature of the vulnerability raises structural questions about the security of cross-chain abstraction layers.
Patched in 1 Hour, Full Repayment Guaranteed: The Hack That Redefines Crisis Management
What sets this incident apart is the speed and transparency of the response. The NEAR team detected the anomaly, identified the vulnerability, and deployed a fix in under 60 minutes — an exceptional turnaround in an industry where teams sometimes take days to react, watching funds drain away in real time.
Shortly after, the protocol officially announced full reimbursement of all users affected by the exploit. This decision, while costly, sends a powerful signal: the protocol’s treasury absorbs the blow rather than passing it on to victims. It is a rare commitment, especially at this scale.
The communication was equally exemplary: real-time updates across social media, a post-mortem announced, and zero attempt to downplay the incident. In an ecosystem where crisis management too often amounts to radio silence or contradictory statements, this approach stands in sharp contrast. Some observers are already calling it a “bullish hack” — a provocative phrase meant to highlight that a well-handled crisis can paradoxically strengthen a protocol’s credibility with institutional investors and advanced users alike.
NEAR: What Impact on the Token and Ecosystem Confidence?
Markets reacted with restraint. The NEAR token faced immediate selling pressure when the hack was announced — the market’s classic knee-jerk reaction to this kind of event. But the speed of the team’s response limited the drawdown, preventing the brutal collapse typically seen when exploits are poorly managed.
The real medium-term question is one of TVL (Total Value Locked) on NEAR Intents. A hack, even a well-handled one, leaves a mark on risk perception. Market makers and liquidity providers will be reassessing their exposure to the protocol over the coming weeks. Whether TVL holds or recovers will be the true measure of restored confidence.
For the broader NEAR ecosystem, this incident highlights a structural challenge: cross-chain interoperability multiplies the attack surface. As NEAR continues to push its chain abstraction agenda — with Chain Abstraction as a core strategic pillar — the security of these infrastructure layers becomes an existential concern. Regular security audits and robust bug bounty programs are no longer optional: they are the non-negotiable foundation of long-term credibility.