NEAR Intents Loses $3.8M to a Deposit Bug, Days After Helping Bitget
NEAR Intents got hit for $3.8 million through a bug in its deposit and withdrawal flow, shortly after the team helped Bitget work through its own breach. The platform says it'll compensate users. The real cost isn't the payout, it's the trust question hanging over the whole intent sector.
NEAR Intents just lost $3.8 million. The exploit hit the platform's deposit and withdrawal flow, a bug that let someone walk off with funds that were supposed to be moving cleanly between chains. The team says affected users will get compensated. That's the right call, and it's also the expensive one.
Here's the part that stings. The attack landed shortly after NEAR Intents stepped in to help Bitget deal with its own security breach. Two incidents, one week, same corner of the market. The people cleaning up someone else's mess got their own door kicked in while they were busy. The story the pitch deck won't tell you is that intent-based systems are young, and young means unfinished.
Numbers first. $3.8 million isn't fatal for a protocol of NEAR's size. It isn't nothing either. Compensation payouts come straight off the balance sheet, and they carry a second bill, the one you can't see, which is the trust tax. Users who got burned don't just want their money back. They want to know why the deposit path was the weak link in the first place.
And that's the uncomfortable question for the whole intent sector. Intents promise a cleaner experience by letting solvers figure out the messy parts, and that convenience is the product. It's also the attack surface. Every layer you abstract away from the user is a layer somebody has to secure, and right now these systems are shipping faster than they're being hardened.
NEAR Intents handled this the way a serious team should. Own it, pay it, move on. But $3.8 million is the kind of number that gets quoted back at you on every investor call for a year.
Watch the compensation timeline and whether NEAR publishes a full post-mortem. Teams that skip that step tend to meet the same bug twice.