Thu. Oct 1st, 2026

NEAR Intents Incident Hits HOT Bridge Treasury as $3.8M Theft Raises Multi-Chain Risk Questions

ByJohan Shamshad

October 1, 2026 #NEAR Intents
HackHack

A reported $3.8 million-plus theft involving infrastructure used by NEAR Intents is raising a more important question than the initial loss figure: whether attackers compromised a single BNB Chain deployment or a component shared across HOT Bridge’s cross-chain withdrawal system.

On-chain investigator ZachXBT reported on October 1 that a wallet he described as a NEAR Intents BSC hot wallet experienced multiple irregular outflows before it stopped processing transactions. He identified the receiving address as 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37 and said the stolen assets were immediately transferred to KuCoin before being bridged into Bitcoin.

The KuCoin-to-Bitcoin leg remains attributed to ZachXBT rather than independently reconstructed transaction by transaction. There is also no public postmortem yet identifying the original vulnerability.

Official records, however, add an important distinction to the incident. NEAR Intents’ treasury-address documentation identifies 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd as the HOT Bridge treasury across major EVM networks. The separate NEAR Intents EVM treasury is 0x2CfF890f0378a11913B6129B2E97417a2c302680.

That makes it premature to describe the event as an exploit of NEAR Intents’ core intent or verifier contracts. Based on the evidence available so far, the affected infrastructure is more specifically associated with HOT Bridge, which NEAR Intents uses as part of its cross-chain settlement stack.

The Same HOT Bridge Address Appears Across Major EVM Networks

The distinction matters because the affected HOT Bridge treasury address is listed for a broad group of EVM networks including BNB Chain, Ethereum, Arbitrum, Avalanche, Base, Gnosis, Optimism, Plasma and Polygon.

ZachXBT said NEAR Intents’ status system was showing an ongoing incident affecting multiple EVM chains. At the time of the latest check, the NEAR Intents explorer was still displaying an ongoing incident, with Plasma appearing in the current alert.

There is no confirmed evidence yet that attackers successfully removed funds from chains other than BNB Chain. Nor does reuse of the same EVM address mean assets on all those networks sit in one common balance. Each blockchain maintains its own state.

But the repeated address makes the nature of the compromise much more important. A vulnerability isolated to a BNB Chain contract would have a fundamentally different risk profile from compromise of signing credentials, validator infrastructure or another control layer reused across several networks.

HOT Bridge’s Architecture Makes the Root Cause Critical

HOT Bridge documentation describes a system in which bridged assets are backed 1:1 by native assets locked on their originating networks.

The architecture uses locker contracts on individual supported chains to hold native assets and process deposits and withdrawals. A HOT OMNI Balance contract on NEAR handles the minting and burning of corresponding omni-assets, while HOT Protocol operates MPC validator networks that validate cross-chain messages.

In a normal withdrawal, an omni-asset is burned, withdrawal data is recorded and a nonce is generated. HOT’s MPC validators verify that withdrawal before producing the proof used on the destination chain. The locker contract then verifies the signature and nonce before releasing native assets.

That leaves several technically different failure scenarios on the table.

An attacker could have found a BSC-specific flaw in a locker or treasury deployment. Alternatively, credentials or infrastructure controlling withdrawals could have been compromised. A vulnerability involving HOT’s MPC validation layer would raise a still broader set of questions because that component participates in cross-chain authorization.

None of those scenarios has been confirmed, and there is currently no basis for claiming that the MPC validator network itself was breached.

The Wallet Was Already a Known Operational Treasury

The 0x233c address did not suddenly appear during the October 1 incident.

An unrelated BitOK investigation into the roughly $3.9 million B² Network exploit in July traced some of the stolen funds into NEAR Intents infrastructure and independently identified the same address as the HOT Bridge Treasury.

At the time, BitOK specifically described it as an operational service address rather than an attacker-controlled wallet. The investigation also warned that NEAR Intents aggregates deposits through operational infrastructure, meaning an incoming deposit cannot automatically be matched with a particular outgoing withdrawal.

That earlier work provides useful corroboration today. It establishes that 0x233c had been functioning as established HOT Bridge infrastructure well before the suspicious October outflows.

The incident therefore looks less like an attribution mistake involving a random wallet and more like unauthorized asset movement from a recognized bridge treasury.

The $3.8 Million May Not Be the Most Important Number

The immediate loss is significant, but the real issue for users and investors is the potential blast radius.

A $3.8 million BSC drain caused by an isolated contract flaw is one type of incident. A compromise of infrastructure responsible for approving withdrawals across several chains would be a very different event.

It is important not to jump from today’s outage to the second conclusion. There is not enough public evidence to say that every HOT Bridge deployment was exposed or that the $3.8 million successfully extracted represents only a fraction of assets technically at risk.

But the multi-chain interruption suggests the team itself is treating the problem cautiously enough to restrict operations beyond the first observed BSC outflows.

NEAR’s own security program reinforces why that distinction matters. Its bridge bug-bounty scope treats MPC networks, bridge protocols, supporting relayers and smart contracts as critical infrastructure and offers rewards of as much as $300,000 for qualifying vulnerabilities.

SHIELD Could Stop Hackers Without Protecting the Bridge Itself

The timing makes the incident particularly striking.

Only days earlier, NEAR Intents’ SHIELD risk system was credited with rejecting more than $50 million in attempted transfers connected to the $387.5 million Bitget breach. NEAR Intents said roughly $503,000 was frozen during execution while about $166,000 in suspected attacker-linked funds made it through.

That showed one security layer functioning as intended: screening addresses and transaction flows before processing them.

The October 1 incident highlights a completely different layer.

SHIELD can identify a suspicious customer or reject a quote linked to stolen funds. It cannot necessarily protect a bridge treasury if the vulnerability sits in a locker contract, signing system, MPC network or operational control environment underneath the transaction-screening layer.

That distinction is increasingly important across crypto infrastructure. The Bitget attack itself reportedly involved manipulation of backend withdrawal infrastructure rather than theft of wallet private keys, while the attackers subsequently moved assets through multiple cross-chain services. Dave Finances has also tracked cases in which Chainflip-linked infrastructure rejected attacker funds during those laundering attempts.

Security at the transaction-screening layer and security at the custody or bridge layer solve different problems.

KuCoin Could Become the Most Important Off-Chain Choke Point

ZachXBT’s claim that the stolen assets were immediately sent to KuCoin before being converted or bridged into Bitcoin creates another potentially important investigative path.

If the relevant exchange deposit accounts can be conclusively identified, KuCoin may hold information unavailable from public blockchains, including account-registration data, login records, IP information and the withdrawal instructions associated with any subsequent Bitcoin movement.

That does not mean the exchange necessarily knows the attacker’s real identity. Stolen or purchased identities, compromised accounts and layered intermediary wallets are common in crypto laundering investigations.

But centralized exchanges can become attribution choke points precisely because they collect information that permissionless bridges do not.

This has already become relevant during efforts to trace assets stolen in the Bitget hack, where the recoverability of funds has depended heavily on whether they remain on native blockchains or eventually enter services capable of restricting accounts.

The Next Disclosure Matters More Than the Initial Hack Alert

The most useful next update will not simply be a revised dollar-loss estimate.

Investigators need to establish which component authorized the unauthorized withdrawals, whether the compromise was limited to BNB Chain, whether any other HOT Bridge treasury deployments experienced irregular transfers and whether signing credentials or the MPC validator layer were involved.

It will also matter whether HOT or NEAR rotates the affected treasury infrastructure, changes validator or signer configurations, patches individual locker contracts, or resumes different chains independently. Those actions could provide clues about which part of the architecture actually failed.

For now, the evidence supports a narrower conclusion than the first “NEAR Intents hack” headlines suggest: approximately $3.8 million or more appears to have been removed from a BNB Chain address that official NEAR Intents documentation identifies as HOT Bridge’s treasury, while services have been disrupted across a wider cross-chain environment.

The key question is no longer whether 0x233c belongs to the infrastructure. That is established.

The question is what had to be compromised to make that infrastructure release the money — and whether the same component controls anything beyond BNB Chain.

Financial Markets Analyst and Journalist at  |  More Posts

Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.

His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.

Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

Leave a Reply

Your email address will not be published. Required fields are marked *