NEAR Intents incident—so far, it seems the main cause was a bug in a cross-chain deposit and withdrawal layer. The official statement says: There was a bug in the interaction between the Omni deposit and withdrawal infrastructure and the NEAR Intents smart contract. The contract-side vulnerability has been patched. The initial loss is estimated at around $3.8 million, and they’ve promised full compensation. Before analyzing the cause, let’s first understand what Intents actually are. Intents, often referred to as “intentions” in Chinese, are different from regular DEX trades. In a regular DEX trade, each transaction is precise. For example, you specify which pool to use, how many hops, the slippage limit, which chain to execute on, and then sign a specific transaction. Intent-based trading, on the other hand, is declarative. Users only state what they want, leaving the path completely open. What they sign is the condition they want to achieve. For example: “Swap 1 ETH for at least 2,500 USDC, valid for 30 minutes.” What’s signed is this condition, not a specific swap. The path, counterparty, whether to split the trade, etc., are not part of the signature. So, if users don’t sign specific transactions, who ensures their desired outcome is achieved? This is where the role of a Solver comes in. Solvers can be market makers, arbitrage bots, cross-chain bridges, etc. They compete with each other, and whoever can fulfill the user’s conditions most efficiently takes the task. Users don’t care about the path; they only care whether their conditions are met. Settlement still happens on-chain via smart contracts. Currently, platforms like CoW Swap and UniswapX use this model, primarily on single chains. NEAR Intents is a cross-chain version built on NEAR: users express their intent on one chain, and solvers search for liquidity across multiple chains. Asset transfers rely on the Omni deposit and withdrawal layer. The address from which funds were taken is labeled in the documentation as the HOT Bridge vault on BNB Chain, not the main EVM vault of NEAR Intents itself. The attack targeted the interface between this deposit and withdrawal channel and the Intents contract. The affected component is this cross-chain channel, not NEAR L1. Whether the issue was bypassed validation, double-counted limits, or misconfigured withdrawal permissions, we’ll need to wait for the official post-mortem to know for sure.