NEAR Intents Probes $3.8M HOT Bridge Treasury Security Incident

1 hour ago 2 sources negative

Key takeaways:

  • NEAR Intents' suspected $3.8M HOT Bridge exploit may pressure NEAR and cross-chain omni-asset trust.
  • HOT Bridge Treasury's prior B² hack link suggests recurring operational wallet exposure for NEAR.
  • Watch KuCoin withdrawal trail and Bitcoin bridging to gauge HOT Bridge exploit scope.

NEAR Intents is investigating a security incident involving more than $3.8 million in suspected stolen funds after on-chain investigator ZachXBT reported irregular outflows from a BNB Smart Chain wallet associated with the protocol. The affected address, 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd, is not listed in NEAR Intents' own documentation as its principal EVM treasury. Instead, it is officially identified as the HOT Bridge Treasury.

ZachXBT identified the suspected theft address as 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37 and said the stolen assets were rapidly transferred to KuCoin and subsequently bridged into Bitcoin. NEAR Intents' status system showed an ongoing incident affecting multiple EVM chains.

The distinction matters because there is not yet public evidence that NEAR Intents' core intent-settlement contracts were compromised. HOT Bridge documentation describes native assets held in chain-specific locker contracts and represented 1:1 by omni-assets. Deposits and withdrawals depend on HOT Protocol's multi-party computation validator network, which validates cross-chain messages and produces withdrawal signatures. A vulnerability could therefore be isolated to the BNB Chain locker, an operational treasury, or shared signing and validator infrastructure.

The protocol has processed more than $30 billion in all-time volume across 35 chains, according to its website. The same HOT Bridge Treasury also appeared in an earlier investigation of the roughly $3.9 million B² Network hack, when blockchain analytics firm BitOK traced part of the stolen proceeds into NEAR Intents. The firm described the wallet as an operational service node rather than an attacker-controlled wallet.

Days earlier, NEAR Intents said its SHIELD risk-intelligence system had identified more than $50 million in attempted transactions associated with the September 24 Bitget hack. Most were rejected before execution, about $503,000 was frozen and roughly $166,000 passed through. ZachXBT separately said Bitget-related attackers had begun shielding approximately 2,700 ZEC worth around $3.8 million in Zcash's Ironwood pool, a movement that should not be conflated with the NEAR Intents incident.

The immediate priority for investigators is identifying the KuCoin deposit addresses, corresponding accounts and Bitcoin withdrawal transactions. The postmortem will need to determine whether the attack involved contract logic, privileged access, validator/signing infrastructure or another operational layer.

Separately, the FBI has told employees to assume that personal data may have been stolen from every staffer after a claimed breach of its jobs site, FBIjobs.gov. The cybercrime group ShinyHunters says it holds 2 to 3 terabytes of data on agents, job applicants and some spouses. The FBI has not confirmed the scale, though Cyber Division Chief Brett Leatherman posted a video telling the hackers, "We know how to find you." ShinyHunters later said it does not plan to publish the data.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.