NEAR Intents is facing a security incident involving more than $3.8 million in suspected stolen funds, but the first hours of on-chain evidence point to a more specific part of its infrastruc

NEAR Intents is facing a security incident involving more than $3.8 million in suspected stolen funds, but the first hours of on-chain evidence point to a more specific part of its infrastructure than the headline suggests. On-chain investigator ZachXBT said Thursday that multiple irregular outflows occurred from a BNB Smart Chain wallet associated with NEAR Intents before the wallet stopped processing transactions. He identified the suspected theft address as
0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37 and said the stolen assets were rapidly transferred to KuCoin and subsequently bridged into Bitcoin. ZachXBT also said NEAR Intents' status system showed an ongoing incident affecting multiple EVM chains. :chatgpt-content-reference{index="0"} The important distinction is that the affected wallet,
0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd, is not listed in
NEAR Intents' own documentation as its principal EVM treasury. It is officially identified as the
HOT Bridge Treasury. NEAR Intents lists a separate EVM treasury address,
0x2CfF890f0378a11913B6129B2E97417a2c302680. The HOT Bridge address is used across numerous EVM networks including BNB Chain, Ethereum, Arbitrum, Avalanche, Base, Optimism, Polygon and Plasma. :chatgpt-content-reference{index="1"}
Was NEAR Intents Exploited, or Was the Failure Inside HOT Bridge?
That distinction matters because there is not yet public evidence showing that NEAR Intents' core intent-settlement contracts were compromised. HOT Bridge documentation describes a system in which native assets are held in chain-specific locker contracts and represented 1:1 by omni-assets. Deposits and withdrawals depend on HOT Protocol's multi-party computation, or MPC, validator network, which validates cross-chain messages and produces signatures used during withdrawals. Each supported chain has its own locker, while the validator infrastructure participates in authorizing movements across the bridge. :chatgpt-content-reference{index="2"} The architecture leaves several materially different possibilities. A vulnerability could be isolated to the BNB Chain locker or withdrawal implementation. An operational treasury could have been compromised. Alternatively, a problem in shared signing, validator or message-validation infrastructure could have consequences across more than one network. There is not enough public evidence to determine which scenario occurred. The live SHIELD status endpoint continues to show an ongoing-incidents section, while ZachXBT specifically described the interruption as affecting multiple EVM chains. :chatgpt-content-reference{index="3"}
Investor Takeaway: The $3.8 million already identified may not be the most important number. The key question is whether the attacker found a BNB Chain-specific weakness or gained access to a component shared across HOT Bridge's EVM infrastructure. Until the root cause is disclosed, the size of the potential exposure cannot be inferred simply from the amount already moved.
The issue is particularly relevant because
NEAR Intents has grown into significant cross-chain infrastructure. Its official website says the protocol has processed more than
$30 billion in all-time volume across 35 chains. :chatgpt-content-reference{index="4"} Bridge infrastructure has repeatedly proved vulnerable to failures outside conventional smart-contract code. FinanceFeeds recently reported on the
$11.58 million Verus-Ethereum bridge exploit, where early analysis focused on message validation, withdrawal logic and access-control weaknesses rather than a simple token contract failure. [FinanceFeeds: Verus-Ethereum Bridge Exploit Drains $11.58 Million](https://financefeeds.com/verus-ethereum-bridge-exploit-drains-11-58-million/?utm_source=chatgpt.com)
The Same HOT Treasury Appeared in an Earlier $3.9M Hack Investigation
The affected address also has an independently documented history that helps establish its role. During an investigation into the roughly $3.9 million B² Network hack earlier this year, blockchain analytics firm BitOK traced part of the stolen proceeds into NEAR Intents. Those funds entered one-time deposit addresses before being collected by the same
0x233c...B4Cd HOT Bridge Treasury. BitOK explicitly described it as an operational service node rather than an attacker-controlled wallet. :chatgpt-content-reference{index="6"} That history is useful because it confirms the wallet was established operational infrastructure before Thursday's incident. It also demonstrates how much cross-chain flow can converge through the HOT service layer. However, the previous B² case should not be interpreted as evidence that the wallet was already compromised. In that incident, stolen assets from an unrelated exploit merely passed through the bridge. BitOK cautioned that NEAR Intents pools deposits and processes them through operational wallets, meaning a deposit into the infrastructure cannot automatically be matched with a particular outgoing withdrawal. :chatgpt-content-reference{index="7"}
KuCoin Could Become the Most Important Off-Chain Choke Point
ZachXBT said Thursday's stolen funds were
immediately sent to KuCoin and bridged into Bitcoin. That part of the transaction trail remains an investigator attribution rather than a conclusion publicly confirmed by NEAR Intents, HOT Protocol or KuCoin. :chatgpt-content-reference{index="8"} If the KuCoin deposits are confirmed, however, they could create one of the clearest recovery and attribution opportunities in the case. A centralized exchange may hold information associated with deposit accounts, login activity and subsequent withdrawals that cannot be obtained solely from public blockchain records. The conversion into Bitcoin also matters because it can make subsequent tracing more difficult if the funds are fragmented, routed through additional services or combined with other flows. The immediate priority for investigators will therefore be identifying the specific KuCoin deposit addresses, corresponding accounts and Bitcoin withdrawal transactions. For now, reporting should avoid presenting the final Bitcoin destinations as independently verified unless the transaction chain is published or reconstructed on-chain.
The Incident Comes Days After NEAR Intents Touted Its Ability to Stop Hackers
The timing adds another layer to the story. Only days earlier, NEAR Intents said its SHIELD risk-intelligence system had identified more than
$50 million in attempted transactions associated with the September 24 Bitget hack. According to NEAR Intents General Manager Alex Shevchenko, most of those transactions were rejected before execution, approximately $503,000 was frozen during execution and roughly $166,000 passed through. :chatgpt-content-reference{index="9"} FinanceFeeds separately reported that the Bitget breach ultimately reached about
$387.5 million after reconciliation, with the attacker exploiting a zero-day vulnerability in a third-party security product and inserting fraudulent withdrawal instructions into wallet backend systems. [FinanceFeeds: Bitget Hacker Used Zero-Day and Test Transfers Before $388M Drain](https://financefeeds.com/bitget-hacker-used-zero-day-and-test-transfers-before-388m-drain/?utm_source=chatgpt.com) The two events expose different layers of security. SHIELD is designed to inspect and reject suspicious transaction flows attempting to use NEAR Intents. That can help prevent known stolen assets from being routed through the service. It does not necessarily protect the underlying bridge treasury, locker contracts, MPC validators, signing systems or operational credentials from being compromised themselves.
Investor Takeaway: Transaction screening and infrastructure security solve different problems. A system may successfully identify malicious users while remaining vulnerable to an attack against the machinery that actually holds or releases assets. The postmortem will need to establish whether Thursday's incident involved contract logic, privileged access, validator/signing infrastructure or another operational layer.
There is also an easy source of confusion in the amounts being reported. Immediately before Thursday's NEAR Intents alert, ZachXBT separately said attackers linked to the Bitget breach had begun shielding approximately
2,700 ZEC worth around $3.8 million in Zcash's Ironwood pool. That is a separate movement of Bitget-related funds and should not be conflated with the roughly $3.8 million attributed to the NEAR Intents/HOT Bridge incident. :chatgpt-content-reference{index="11"}
What the Postmortem Needs to Answer
The next disclosure from NEAR Intents or HOT Protocol will determine whether this remains a relatively contained treasury loss or becomes a broader infrastructure story. The most important unanswered questions are which component was compromised; whether unauthorized withdrawals occurred on networks other than BNB Chain; whether the HOT MPC validator or signing layer was involved; the exact token-by-token loss; whether keys, contracts or validator configurations are being rotated; and whether KuCoin has identified or restricted the accounts that received the stolen assets. Until those questions are answered, the technically accurate framing is narrower than simply saying the entire NEAR Intents protocol was hacked. The available evidence shows that an officially documented
HOT Bridge treasury used by NEAR Intents suffered irregular BSC outflows exceeding $3.8 million, followed by a broader service incident. Whether the weakness sits in one chain-specific component or in shared cross-chain infrastructure is now the central issue for users, counterparties and investigators.