A cross-chain swap protocol hacked for $3.8 million. A bug exploited within hours. And a timing that raises serious questions: the incident occurred just days after Near Intents refused to process funds from a hacker allegedly linked to North Korea — the same individual implicated in the Bitget affair.

Coincidence or escalation? The crypto community is holding its breath. Near Intents immediately froze its operations and pledged to fully reimburse all affected users.

Here is everything we know about this attack and what it reveals about the persistent vulnerabilities in cross-chain DeFi protocols.

A Fatal Bug in Cross-Chain Swaps: How the Attack Unfolded

Near Intents is a protocol designed to facilitate asset exchanges across different blockchains — what the industry refers to as cross-chain swaps. It was precisely within this mechanism that an attacker identified and exploited a critical vulnerability, allowing them to drain approximately $3.8 million in assets from the protocol.

As soon as the exploit was detected, the Near Intents team made the decision to freeze all cross-chain swaps in order to stop the bleeding. This swift response helped limit the scale of the damage, but could not prevent the initial loss. The protocol subsequently issued a public confirmation of the incident and committed to reimbursing every affected user — a strong signal, though one that raises questions about whether the protocol holds sufficient reserves to cover those losses.

The precise technical details of the bug had not yet been publicly disclosed at the time of writing, which is standard practice to avoid enabling similar attacks on other protocols. A full post-mortem audit is expected in the coming days.

The Context That Makes This Hack Particularly Troubling

What makes this incident stand out is its timing. Just days before the hack, Near Intents had refused to process funds belonging to a hacker allegedly linked to North Korea — an individual already implicated in the Bitget affair, a crypto exchange that had itself suffered an attack attributed to North Korean state-sponsored actors, most notably the Lazarus Group.

That refusal, rooted in compliance obligations and anti-money laundering principles, may have exposed Near Intents to targeted retaliation. While no direct link between the two events has been established at this stage, the proximity in timing is fueling speculation across the community. The Lazarus Group is well known for its sophisticated offensive capabilities and its ability to identify vulnerabilities in complex DeFi protocols.

This situation highlights a growing dilemma for decentralized protocols: enforcing compliance measures exposes platforms to the risk of retaliation, while ignoring malicious actors exposes them to regulatory sanctions. Both options carry significant risks for the security and reputation of any platform.

Cross-Chain DeFi: An Attack Surface That Remains a Prime Target

The attack on Near Intents fits into a broader and well-established pattern: cross-chain protocols remain among the most vulnerable targets in the DeFi ecosystem. According to data from CryptoQuant and blockchain security reports, bridges and interoperability protocols accounted for a disproportionate share of hack-related losses in 2023 and 2024, representing several hundreds of millions of dollars stolen.

The inherent complexity of these systems — which must manage state across multiple blockchains simultaneously — multiplies the attack surface considerably. A single bug in the transaction validation logic can be enough to compromise an entire protocol. That appears to be exactly the scenario that played out here.

For Near Intents users, the reimbursement pledge offers short-term reassurance. But it does not resolve the fundamental question: how did a protocol that had already identified malicious actors in its immediate environment fail to strengthen its defenses beforehand? The answer to that question will determine Near Intents’ credibility in the weeks ahead.

Risk Warning : Trading financial instruments and/or cryptocurrencies carries a high level of risk, including the possibility of losing all or part of your investment. It may not be suitable for all investors. Cryptocurrency prices are highly volatile and can be influenced by external factors such as financial, regulatory, or political events. Margin trading increases financial risks.

CFDs (Contracts for Difference) are complex instruments with a high risk of rapid capital loss due to leverage. Between 74% and 89% of retail investor accounts lose money when trading CFDs. You should assess whether you understand how CFDs work and whether you can afford to take the high risk of losing your money.

Before engaging in financial or cryptocurrency trading, you must be fully informed about the associated risks and fees, carefully evaluate your investment objectives, level of experience, and risk tolerance, and seek professional advice if needed. InvestX.fr and the InvestX application may provide general market commentary, which does not constitute investment advice and should not be interpreted as such. Please consult an independent financial advisor for any investment-related questions. InvestX.fr disclaims any liability for errors, misinvestments, inaccuracies, or omissions and does not guarantee the accuracy or completeness of the information, texts, graphics, links, or other materials provided.

Some of the partners featured on this site may not be regulated in your country. It is your responsibility to verify the compliance of these services with local regulations before using them.

Get 6200 USDT with Bitget ! 🔥

Don't miss out on this offer !
Create your account now to unlock this exclusive reward
Open a Bitget account
close-link
Click Me