NEAR Intents Hacked for $3.8 Million in Latest Crypto Exploit

fiverr


Set as Google Preferred SourceFollow on Google News

TLDR

  • NEAR Intents, a cross-chain crypto trading platform, lost about $3.8 million in an exploit on Thursday.
  • The bug came from how the Omni deposit and withdrawal system interacted with the NEAR Intents smart contract.
  • The platform paused services and froze deposits and withdrawals on eleven blockchain networks.
  • NEAR Intents says all lost funds will be fully reimbursed to affected users.
  • Investigator ZachXBT traced the stolen funds to KuCoin, then into bitcoin.

NEAR Intents, a platform that lets people swap crypto across different blockchains, was hit by a security exploit on Thursday. The attack caused losses of roughly $3.8 million.

The platform paused its services shortly after the exploit was discovered. Deposits and withdrawals were also disabled on several networks while the team worked on a fix.

What Caused the Exploit

NEAR Intents said the issue came from a bug in its Omni deposit and withdrawal system. This system did not interact properly with the NEAR Intents smart contract, creating an opening for attackers.

The team said the contract flaw has since been patched. Core services were expected to resume within about an hour of the announcement.

However, deposits and withdrawals on eleven networks faced a longer wait. These included BNB Smart Chain, Polygon, Optimism, Avalanche, Stellar, TON, Monad, X Layer, ADI, Scroll, and Plasma.

NEAR Intents pledged to reimburse all affected users in full. The company said it is working with blockchain analytics firms and has reported the incident to law enforcement.


Betpanda


A post-mortem report is expected in the coming days.

How the Stolen Funds Moved

Blockchain investigator ZachXBT shared details about the attack on Telegram. He said the exploit began with unusual withdrawals from a BNB Chain hot wallet linked to NEAR Intents.

According to ZachXBT, the stolen funds were sent to the crypto exchange KuCoin. From there, they were bridged into bitcoin.

The Block reached out to KuCoin for comment but did not receive a response at the time of reporting.

NEAR Intents works by letting users specify the trade they want. Independent market makers, called solvers, then compete behind the scenes to complete that trade. The platform has processed more than $30 billion in volume across 35 blockchains, according to its website.

The native NEAR token, closely tied to the NEAR Intents platform, dropped about 6% to 6.7% in the twenty four hours following the exploit. It was trading near $4.96 at the time of writing.

The timing also affected the newly launched Bitwise NEAR exchange traded fund, which began trading just two days earlier. That fund fell about 6.4%, erasing gains from the prior day.

This exploit adds to a difficult year for crypto security. Just last week, the exchange Bitget suffered a separate exploit resulting in over $350 million in stolen assets.

Other large incidents this year include Liquid Network at about $320 million, Drift at $295 million, and Kelp at $293 million, according to data from DefiLlama.

The NEAR Intents exploit comes about six weeks after the platform announced it had crossed $25 billion in lifetime trading volume. NEAR Intents said it expects to release more details on the cause and response in its upcoming post-mortem report.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*