UPDATE: @NEAR_Intents confirms the $3.8M exploit was caused by a bug in its Omni deposit system, now patched, with affected users to be reimbursed in full as services gradually resume.