{
  "version": 1,
  "event_id": "evt_1cf36734246e006d",
  "url": "https://xiyu.news/events/evt_1cf36734246e006d/",
  "json": "https://xiyu.news/api/events/evt_1cf36734246e006d.json",
  "type": "security_incident",
  "status": "developing",
  "category": "crypto",
  "title": {
    "zh": "NEAR Intents 遭攻击损失超380万美元并暂停服务",
    "en": "NEAR Intents exploited for over $3.8M and halts services"
  },
  "current_state": {
    "zh": "NEAR Intents 攻击事件持续调查中，攻击者地址被指与朝鲜 Lazarus Group 标记地址交互，攻击者或为 Lazarus Group；此前已确认损失超 380 万美元、暂停 11 个网络充提并承诺赔偿。",
    "en": "Investigation into the NEAR Intents exploit continues; the attacker's address has been linked to a wallet flagged as North Korea's Lazarus Group, suggesting the attacker may be Lazarus Group. Previously confirmed: over $3.8M loss, deposits/withdrawals suspended across 11 networks, and full compensation pledged."
  },
  "first_seen_at": "2026-10-01T15:11:04.403203+00:00",
  "last_updated_at": "2026-10-01T18:31:27.924841+00:00",
  "last_material_change_at": "2026-10-01T18:31:27.924841+00:00",
  "confidence": 0.75,
  "updates_count": 4,
  "sources_count": 9,
  "entities": [
    "alert",
    "bsc",
    "community",
    "group",
    "hacks",
    "halts",
    "intents",
    "lazarus",
    "lazarus-group",
    "loss",
    "million",
    "near",
    "near-intents",
    "reports",
    "services"
  ],
  "identifiers": [],
  "topics": [
    "bsc",
    "cross-chain",
    "crypto-protocols",
    "fund-laundering",
    "hacks",
    "hot-wallet-compromise",
    "lazarus-group",
    "money-laundering",
    "near",
    "near-intents",
    "price-reaction",
    "security-exploit",
    "security-incident"
  ],
  "updates": [
    {
      "update_id": "upd_9c7ebdd858e6b622",
      "event_id": "evt_1cf36734246e006d",
      "occurred_at": "2026-10-01T13:02:44Z",
      "published_at": "2026-10-01T13:02:44Z",
      "first_seen_at": "2026-10-01T15:11:04.403203Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "社区警报：Near Intents 在其 BSC 热钱包后遭利用，损失超 380 万美元",
      "title_en": "Community Alert: Near Intents was exploited for $3.8M+ after its BSC hot wallet",
      "what_changed_zh": "Near Intents 在 BSC 上遭遇热钱包漏洞利用，异常流出超过 380 万美元，促使其在涉及多 EVM 链的事件中暂停交易，被盗资金被转至 KuCoin 并跨链至比特币。",
      "what_changed_en": "Near Intents suffered a hot-wallet exploit on BSC with over $3.8M in irregular outflows, prompting it to halt transactions amid a multi-EVM-chain incident, with the stolen funds routed to KuCoin and bridged to Bitcoin.",
      "current_state_zh": "Near Intents 在 BSC 上遭遇热钱包漏洞利用，异常流出超过 380 万美元，促使其在涉及多 EVM 链的事件中暂停交易，被盗资金被转至 KuCoin 并跨链至比特币。",
      "current_state_en": "Near Intents suffered a hot-wallet exploit on BSC with over $3.8M in irregular outflows, prompting it to halt transactions amid a multi-EVM-chain incident, with the stolen funds routed to KuCoin and bridged to Bitcoin.",
      "detailed_summary_zh": "Near Intents suffered a hot-wallet exploit on BSC with over $3.8M in irregular outflows, prompting it to halt transactions amid a multi-EVM-chain incident, with the stolen funds routed to KuCoin and bridged to Bitcoin.",
      "detailed_summary_en": "Near Intents suffered a hot-wallet exploit on BSC with over $3.8M in irregular outflows, prompting it to halt transactions amid a multi-EVM-chain incident, with the stolen funds routed to KuCoin and bridged to Bitcoin.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.0,
      "references": [],
      "confidence": 0.75,
      "story_ids": [
        "telegram:investigations:365",
        "telegram:theblockbeats:198623",
        "rss:thedefiant.io_api_feed:62cb110372cf4ca6"
      ],
      "sources": [
        {
          "url": "https://partners.near-intents.org/shield/status",
          "label": "investigations",
          "source_type": "telegram",
          "official": false
        },
        {
          "url": "https://m.theblockbeats.info/flash/369943?from=telegram",
          "label": "theblockbeats",
          "source_type": "telegram",
          "official": false
        },
        {
          "url": "https://thedefiant.io/news/hacks/near-intents-halts-services-reports-3-8-million-loss",
          "label": "The Defiant",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_82540b51cf8c4597",
      "event_id": "evt_1cf36734246e006d",
      "occurred_at": "2026-10-01T13:08:02Z",
      "published_at": "2026-10-01T13:08:02Z",
      "first_seen_at": "2026-10-01T15:11:06.096365Z",
      "time_precision": "published",
      "update_type": "confirmation",
      "material_change": true,
      "title_zh": "NEAR Intents确认遭攻击，涉案金额超380万美元",
      "title_en": "NEAR Intents确认遭攻击，涉案金额超380万美元",
      "what_changed_zh": "NEAR Intents 正式确认攻击，指漏洞源于 Omni 充提基础设施与合约交互缺陷；已完成合约修复，预计 1 小时内恢复核心服务，承诺全额赔付受损资产，BSC、Polygon、TON 充提额外暂停约 12 小时，并已报案并展开链上追踪。",
      "what_changed_en": "NEAR Intents formally confirmed the exploit, attributing it to flaws in its Omni deposit/withdrawal infrastructure and contract interactions; it has patched the contract, expects core services back within ~1 hour, pledged full reimbursement of affected assets, paused BSC/Polygon/TON deposits and withdrawals for an additional ~12 hours, and filed a report while pursuing on-chain tracing.",
      "current_state_zh": "Near Intents 已确认其 Omni 充提基础设施与合约交互缺陷导致的攻击，损失超 380 万美元；合约漏洞已修复，核心服务预计 1 小时内恢复，BSC、Polygon、TON 充提额外暂停约 12 小时，承诺全额赔付，并已报案，被盗资金仍流向 KuCoin 并跨链至比特币。",
      "current_state_en": "Near Intents has confirmed an exploit exceeding $3.8M caused by flaws in its Omni deposit/withdrawal infrastructure and contract interactions; the contract flaw is patched, core services are expected to resume within ~1 hour, BSC/Polygon/TON deposits and withdrawals remain paused for an additional ~12 hours, full reimbursement is pledged, a report has been filed, and stolen funds were routed to KuCoin and bridged to Bitcoin.",
      "detailed_summary_zh": "NEAR Intents confirmed an exploit exceeding $3.8M caused by flaws in its Omni deposit/withdrawal infrastructure and contract interactions, has patched the contract and pledged full reimbursement while pausing BSC, Polygon and TON deposits/withdrawals for roughly 12 hours, as on-chain sleuth ZachXBT tracked stolen funds moving to KuCoin and across a bridge to Bitcoin.",
      "detailed_summary_en": "NEAR Intents confirmed an exploit exceeding $3.8M caused by flaws in its Omni deposit/withdrawal infrastructure and contract interactions, has patched the contract and pledged full reimbursement while pausing BSC, Polygon and TON deposits/withdrawals for roughly 12 hours, as on-chain sleuth ZachXBT tracked stolen funds moving to KuCoin and across a bridge to Bitcoin.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.5,
      "references": [],
      "confidence": 0.9,
      "story_ids": [
        "telegram:theblockbeats:198622",
        "telegram:foresightnews:119576",
        "telegram:wublockchainenglish:26247",
        "rss:www.theblock.co_rss.xml:d83b88f3a7aa24d6"
      ],
      "sources": [
        {
          "url": "https://m.theblockbeats.info/flash/369942?from=telegram",
          "label": "theblockbeats",
          "source_type": "telegram",
          "official": false
        },
        {
          "url": "http://near.com/",
          "label": "foresightnews",
          "source_type": "telegram",
          "official": false
        },
        {
          "url": "https://wublockchain.xyz/news/news-21075",
          "label": "wublockchainenglish",
          "source_type": "telegram",
          "official": false
        },
        {
          "url": "https://www.theblock.co/news/ecosystems/2026-10-01-near-intents-halts-services-after-3-8-million-exploit-promises-full-compensation-417404",
          "label": "The Block",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_1f55cddfaa5b71bb",
      "event_id": "evt_1cf36734246e006d",
      "occurred_at": "2026-10-01T14:18:14Z",
      "published_at": "2026-10-01T14:18:14Z",
      "first_seen_at": "2026-10-01T15:11:07.276706Z",
      "time_precision": "published",
      "update_type": "escalation",
      "material_change": true,
      "title_zh": "NEAR Intents 遭 380 万美元漏洞利用，加密行业黑客频发的一年仍在继续",
      "title_en": "NEAR Intents hit by $3.8 million exploit as crypto's rough year of hacks continues",
      "what_changed_zh": "新报道披露受影响网络范围扩大：除 BSC、Polygon、TON 外，Optimism、Avalanche、Stellar、Monad、X Layer、ADI、Scroll 和 Plasma 的充提也出现中断；平台跨链交易量超 300 亿美元、覆盖 35 条链的细节也被提及。",
      "what_changed_en": "New report discloses expanded affected network scope: in addition to BSC, Polygon, and TON, deposit/withdrawal disruptions also affect Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma; details that the platform has processed over $30B across 35 chains are also mentioned.",
      "current_state_zh": "Near Intents 已确认其 Omni 充提基础设施与合约交互缺陷导致的攻击，损失超 380 万美元；合约漏洞已修复，核心服务预计 1 小时内恢复，但充提中断已波及 BSC、Polygon、TON、Optimism、Avalanche、Stellar、Monad、X Layer、ADI、Scroll 和 Plasma 等多条网络，暂停时间可能延长；承诺全额赔付，已报案，被盗资金仍流向 KuCoin 并跨链至比特币，执法与安全公司正在追踪。",
      "current_state_en": "Near Intents has confirmed an exploit exceeding $3.8M caused by flaws in its Omni deposit/withdrawal infrastructure and contract interactions; the contract flaw is patched, core services are expected to resume within ~1 hour, but deposit/withdrawal disruptions now affect multiple networks including BSC, Polygon, TON, Optimism, Avalanche, Stellar, Monad, X Layer, ADI, Scroll, and Plasma, with pauses potentially prolonged; full reimbursement is pledged, a report has been filed, stolen funds were routed to KuCoin and bridged to Bitcoin, and law enforcement and security firms are tracing.",
      "detailed_summary_zh": "NEAR Intents suffered a ~$3.8 million exploit traced to a bug in its Omni system and smart contract, prompting it to pause services, restrict deposits and withdrawals on several networks, and pledge full reimbursement while law enforcement and security firms trace funds routed through KuCoin and converted to bitcoin.",
      "detailed_summary_en": "NEAR Intents suffered a ~$3.8 million exploit traced to a bug in its Omni system and smart contract, prompting it to pause services, restrict deposits and withdrawals on several networks, and pledge full reimbursement while law enforcement and security firms trace funds routed through KuCoin and converted to bitcoin.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.0,
      "references": [],
      "confidence": 0.9,
      "story_ids": [
        "rss:www.coindesk.com_arc_outboundfeeds_rss_:17e8fa98b83b4099"
      ],
      "sources": [
        {
          "url": "https://www.coindesk.com/tech/2026/10/01/near-intents-hit-by-usd3-8-million-exploit-as-crypto-s-rough-year-of-hacks-continues",
          "label": "CoinDesk",
          "source_type": "rss",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_c08682101578dff7",
      "event_id": "evt_1cf36734246e006d",
      "occurred_at": "2026-10-01T15:12:03Z",
      "published_at": "2026-10-01T15:12:03Z",
      "first_seen_at": "2026-10-01T18:31:27.924841Z",
      "time_precision": "published",
      "update_type": "escalation",
      "material_change": true,
      "title_zh": "⚡️NEAR Intents攻击者或为Lazarus Group",
      "title_en": "⚡️NEAR Intents攻击者或为Lazarus Group",
      "what_changed_zh": "调查显示攻击者地址与标记为朝鲜 Lazarus Group 的地址（0x098B7...E2f96）存在交互，攻击者可能为 Lazarus Group。",
      "what_changed_en": "The attacker's address interacted with a wallet flagged as North Korea's Lazarus Group (0x098B7...E2f96), suggesting the attacker may be Lazarus Group.",
      "current_state_zh": "NEAR Intents 攻击事件持续调查中，攻击者地址被指与朝鲜 Lazarus Group 标记地址交互，攻击者或为 Lazarus Group；此前已确认损失超 380 万美元、暂停 11 个网络充提并承诺赔偿。",
      "current_state_en": "Investigation into the NEAR Intents exploit continues; the attacker's address has been linked to a wallet flagged as North Korea's Lazarus Group, suggesting the attacker may be Lazarus Group. Previously confirmed: over $3.8M loss, deposits/withdrawals suspended across 11 networks, and full compensation pledged.",
      "detailed_summary_zh": "The NEAR Intents attacker moved stolen funds to KuCoin and bridged them into BTC, with the attacker's address interacting with a wallet flagged as North Korea's Lazarus Group.",
      "detailed_summary_en": "The NEAR Intents attacker moved stolen funds to KuCoin and bridged them into BTC, with the attacker's address interacting with a wallet flagged as North Korea's Lazarus Group.",
      "background_zh": "NEAR Intents 是一项跨链兑换服务，订单由相互竞争的市场做市商撮合，官方称其已处理超过 300 亿美元、覆盖 35 条区块链的兑换。在本次漏洞利用发生前两天，它拦截了来自 Bitget 黑客的 5000 万美元兑换尝试。Bitget 首席执行官陈雅琪（Gracy Chen）与区块链分析公司 Elliptic 均指朝鲜可能是上周 Bitget 交易所被盗事件的幕后黑手，但同样未获证实。跨链桥接层屡屡成为攻击目标，例如 2022 年 Harmony 跨链桥被盗约 1 亿美元。",
      "background_en": "NEAR Intents is a cross-chain swap service that routes orders through competing market makers and says it has handled more than $30 billion in swaps across 35 blockchains. Two days before the exploit it blocked a $50 million swap attempt from the Bitget hacker. Bitget CEO Gracy Chen and analytics firm Elliptic pointed to North Korea as the likely culprit behind the Bitget exchange hack, which has also not been confirmed. Cross-chain bridging layers have repeatedly been targeted, as in the 2022 Harmony bridge hack that cost about $100 million.",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "该事件直接影响 NEAR 代币以及两天前刚推出的 Bitwise NEAR ETF，二者在漏洞事件后均出现下跌；资金经由 KuCoin 转移并换成 BTC，则涉及交易所托管和跨链桥这一洗钱通道。已披露的约 380 万美元损失相对整体市场流动性规模较小，因此更广泛的影响更可能通过市场对跨链桥与意图（intents）类基础设施的情绪传导，而非系统性的资金流动。",
      "market_impact_en": "The incident bears directly on the NEAR token and on the Bitwise NEAR ETF launched two days earlier, both of which declined after the exploit, while the routing of funds through KuCoin and into BTC touches exchange custody and cross-chain bridging as laundering channels. The disclosed loss of roughly $3.8 million is small relative to overall market liquidity, so any wider effect would travel through sentiment toward bridge and intent-based infrastructure rather than through systemic fund flows.",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://www.kucoin.com/news/flash/near-intents-and-near-com-restore-after-security-incident-affecting-bsc-usdt",
          "title": "NEAR Intents and near.com Restore Following Security... | KuCoin"
        },
        {
          "url": "https://www.binance.com/en/square/post/10-01-2026-near-intents-fixes-vulnerability-in-omni-deposit-and-withdrawal-infrastructure-372609995363193",
          "title": "NEAR Intents Fixes Vulnerability in Omni Deposit and Withdrawal..."
        },
        {
          "url": "https://www.elliptic.co/insights/how-the-lazarus-group-is-stepping-up-crypto-hacks-and-changing-its-tactics/",
          "title": "How the Lazarus Group is stepping up crypto hacks and... | Elliptic"
        }
      ],
      "confidence": 0.95,
      "story_ids": [
        "telegram:theblockbeats:198636"
      ],
      "sources": [
        {
          "url": "https://m.theblockbeats.info/flash/369956?from=telegram",
          "label": "theblockbeats",
          "source_type": "telegram",
          "official": false
        }
      ]
    }
  ]
}
