In a striking and deeply ironic sequence of events, NEAR Intents — the intent-based cross-chain trading protocol built on the NEAR Protocol ecosystem — has been exploited for $3.8 million through a deposit/withdrawal vulnerability, forcing the platform to halt all services. The timing is particularly damning: the breach occurred just days after NEAR Intents had intervened to freeze funds connected to a hack on Bitget, the centralized cryptocurrency exchange. A protocol that had positioned itself as part of the solution to industry theft now finds itself the victim of the very problem it sought to contain.

The Exploit Unpacked

According to available reporting, attackers identified and weaponized a flaw in NEAR Intents' deposit and withdrawal mechanics. This class of exploit — often involving the manipulation of accounting logic between incoming and outgoing fund flows — has become one of the most recurrent attack surfaces in decentralized finance (DeFi). By carefully crafting transactions that abuse the protocol's handling of these two functions, bad actors were able to drain $3.8 million before the system could detect or interrupt the anomaly. NEAR Intents responded by shutting down services entirely, the standard emergency containment move for DeFi protocols caught mid-breach, but one that also signals the severity of what occurred.

The Bitget Connection

What makes this incident more than a routine DeFi theft story is the context surrounding it. In the days immediately prior to its own hack, NEAR Intents had taken the notable step of freezing funds connected to a separate exploit targeting Bitget. That action placed the protocol in the role of a de facto on-chain enforcer — an increasingly common posture for DeFi infrastructure as the industry grapples with how to respond to theft without centralized authorities. Protocols that can freeze or blacklist funds associated with known exploits carry a dual-edged responsibility: they demonstrate that blockchain systems are not entirely lawless, but they also draw attention to their own architecture and control mechanisms. Whether the proximity of these two events is coincidental or whether the Bitget freeze drew adversarial scrutiny toward NEAR Intents' own codebase remains an open and pressing question.

A Pattern the Industry Cannot Ignore

The $3.8 million loss at NEAR Intents lands against a broader landscape of persistent DeFi security failures. Deposit/withdrawal exploits in particular have a long and costly history across the sector. The attack vector typically thrives when protocols lack sufficient re-entrancy guards, when balances are updated in the wrong sequence relative to asset transfers, or when edge cases in multi-asset routing logic go unaudited. Intent-based architectures — which abstract transaction execution away from users by allowing solvers or relayers to fulfill orders — introduce additional complexity that can obscure subtle bugs in the settlement layer. Each new architectural innovation in DeFi has historically introduced new surfaces for exploitation, and the intent model is no exception.

Halting Services: Necessary but Costly

The decision to suspend operations is the correct one from a risk-containment standpoint, but it carries real costs beyond the immediate $3.8 million loss. User trust in intent-based protocols is still being established. NEAR Intents represented a meaningful piece of infrastructure connecting liquidity and users across chains within the NEAR ecosystem. A forced shutdown, however temporary, disrupts trading activity, strands pending transactions, and raises uncomfortable questions about whether the protocol's security architecture was adequately stress-tested before deployment or upgrade. The DeFi space has seen enough post-mortems to recognize the pattern: a protocol moves fast, gains users and locked value, and then faces an exploit that could have been caught by more rigorous auditing or staged rollout procedures.

What This Means for NEAR's Ecosystem Credibility

For the broader NEAR ecosystem, the timing of this incident is a credibility problem that demands a transparent response. NEAR Protocol has worked to position itself as a developer-friendly, high-throughput blockchain capable of supporting serious financial applications. A high-profile exploit of one of its flagship DeFi products — especially one that follows so closely on the heels of a publicized act of good faith in freezing Bitget-linked stolen funds — risks undermining that narrative. The community and the development teams will need to deliver a thorough, public incident report that explains not just what failed technically, but what oversight processes were in place and how they will be strengthened. Partial transparency or delayed disclosure, which has plagued other protocols in similar situations, would only compound the reputational damage.

The $3.8 million extracted from NEAR Intents is a number large enough to matter to users and small enough to be dismissed by those who track nine-figure DeFi heists — but the real significance here is structural. A protocol that was actively participating in the ecosystem-wide response to crypto theft has itself become a theft target within the same news cycle. That sequence should prompt every DeFi team operating intent-based or cross-chain settlement infrastructure to revisit their deposit and withdrawal logic immediately, before the next attacker finds the same flaw somewhere else.

Written by the editorial team — independent journalism powered by Bitcoin News.