NEAR Intents was exploited for $3.8 million on October 1, 2026, just days after the team publicly denied links to a North Korea-connected hacker tied to the Bitget breach. Services were halted and full compensation was promised. Here is what is confirmed, what is still unknown, and what a crypto holder can check right now without guessing.
What happened to NEAR Intents on October 1, 2026?
NEAR Intents was hit by a $3.8 million exploit detected around 16:00 UTC on October 1, 2026, according to reporting from Cointelegraph, Decrypt, CoinDesk and The Block. The team halted services in response and has promised full compensation to affected users.
The timing is pointed. The exploit landed days after NEAR Intents denied being connected to a North Korea-linked hacker associated with a breach at the exchange Bitget, per Decrypt and Cointelegraph. Cointelegraph specifically frames the incident as occurring after assistance with the Bitget breach.
Beyond those points, the public record is thin. This story is only hours old, and the four newsrooms agree on the amount and the response but not much more.
What is confirmed right now
- The loss figure is $3.8 million, consistent across all four outlets.
- NEAR Intents halted services after the exploit (The Block).
- The team has promised full compensation (The Block).
- There is a reported connection in time to the Bitget breach and an earlier denial of ties to a North Korea-linked hacker (Decrypt, Cointelegraph).
What is not yet known
Several basic facts are still open, and it is better to say so than to invent them. As of this writing, the headlines do not establish:
- The exact attack vector (contract bug, key compromise, or something else).
- Whether the Bitget-linked attacker is confirmed responsible, or whether the timing is coincidental.
- The timeline or mechanism for the promised compensation.
- When services will resume and in what form.
What is NEAR Intents, and why does the exploit matter?
NEAR Intents is an intent-based execution layer in the NEAR Protocol ecosystem, where users express a desired outcome and solvers compete to fulfill it. An exploit at that layer matters because it sits between a user's request and the settlement of funds, so a compromise there can touch assets in transit rather than only balances at rest.
For retail holders, the practical point is simpler. A $3.8 million exploit plus a service halt is the kind of headline that moves sentiment around the token and the wider ecosystem, regardless of how the technical details settle out later.
This fits a broader pattern CoinDesk calls crypto's rough year of hacks. If you want context on how custody and bridge-style risks have played out elsewhere, our breakdown of the white-hat seizure of 4,000 BTC from Liquid covers how fast funds can move when infrastructure is compromised.
How to check your exposure to NEAR right now
Start by finding out exactly how much you hold and where, because you cannot reason about a position you have not measured. The fastest way is to pull your holdings into one view across every wallet, exchange and account.
Here is a concrete checklist you can run in a few minutes:
- List every venue where you hold NEAR or ecosystem tokens, including exchanges, self-custody wallets and staking.
- Add anything in transit, such as positions sitting inside intent-based or bridge services.
- Calculate NEAR as a percentage of your total crypto and total portfolio, not just the dollar figure.
- Note what you cannot currently access if services are halted, so you are not surprised later.
If you use PortfolioTrackr, you can bring stocks and crypto into a single dashboard and see NEAR's weight against everything else. Our guide on tracking stocks and crypto together in one app walks through adding tokens by manual entry, CSV, text or a broker connection. Connecting a broker is optional; manual and CSV entry work on every plan.
Why a single dashboard beats checking apps one by one
A single dashboard beats app-hopping because exposure math only works when every holding is in one place. During a fast-moving event, flipping between four wallet apps and two exchange tabs is how people miscount, miss a staking balance, or forget a small position that turns out to matter.
- You see total NEAR exposure in one number, in your home currency.
- You spot correlated positions in the same ecosystem you might have overlooked.
- You avoid double-counting the same coins shown differently across venues.
How to set a NEAR price alert so you are not glued to a screen
Set a price alert at a level that matters to you so you hear about a move without watching charts all day. In PortfolioTrackr, every position and every watchlist level is checked once a minute, around the clock, and you hear within a minute of your level being hit.
Alerts report status against your own levels, not advice. The tool will tell you a level you chose has been reached; it will not tell you to buy or sell anything.
- Watchlist and alerts are on every plan: 10 tickers on the free trial and Starter, 50 on Pro and Lifetime.
- Email, WhatsApp, Telegram and push alerts are available on every plan, including the free trial.
- SMS is Pro and Lifetime only.
- A recurring alert for the same target repeats at most once every five minutes, so you are informed without being spammed.
Even if you do not own NEAR, adding it to a watchlist is a low-effort way to follow the aftermath. You get a signal when the price crosses a level you care about rather than refreshing headlines.
How to review your allocation after a security event
Reviewing allocation means looking at how much of your portfolio sits in one token, one ecosystem, or one risk category, then checking that against what you are comfortable holding. This is a measurement exercise, not a trade instruction.
Questions you can answer for yourself today:
- What percentage of your portfolio is NEAR, and does that match what you believed it was?
- How much sits in venues or services that are currently paused?
- Are your largest positions concentrated in a single ecosystem or theme?
- Do your security basics hold up, including hardware wallets and strong two-factor authentication?
On that last point, this event is a reminder that account hygiene matters as much as token selection. Our comparison of SMS versus TOTP two-factor authentication explains why app-based codes are harder to intercept, and our walkthrough on checking whether your portfolio app is actually safe covers what to verify before trusting any tool with your data.
Watch for scams that follow every hack
Expect impersonation attempts in the hours after any exploit, because attackers know users are anxious and searching for answers. Fake support accounts, bogus compensation forms and phishing links tend to spread fast on social channels.
- Treat any unsolicited message about compensation as suspect until verified through official channels.
- Never enter a seed phrase into a form, ever, for any reason.
- Be wary of DMs claiming to be support, a pattern we detail in our guide to how fake support drains crypto accounts.
Comparing your options for staying informed
Here is how common ways of following a breaking exploit stack up for a retail holder.
| Method | Speed | Risk |
|---|---|---|
| Refreshing news sites manually | Slow, you check when you remember | Low, but easy to miss price moves |
| Social media feeds | Fast but noisy | High, scams and rumors spread here |
| Price alert within a minute | Fast on price, hands-off | Low, you set the level yourself |
| Doing nothing | None | You find out late |
What to watch next on the NEAR Intents exploit
Watch for the official post-incident report, because the attack vector and the compensation mechanics are the two biggest open questions right now. Those details will shape how the market reads the event once the initial shock fades.
Concrete things to track in the coming days:
- An official statement confirming the attack vector and whether it is contained.
- Details on the promised compensation: who qualifies, how much, and when.
- Whether the Bitget-linked attacker connection is confirmed or ruled out.
- When NEAR Intents services resume and in what form.
- Any follow-on security advisories for connected protocols.
The bottom line
NEAR Intents lost $3.8 million to an exploit on October 1, 2026, halted services, and promised full compensation, days after denying ties to a North Korea-linked attacker connected to the Bitget breach. Much of the technical detail is still unknown, and that is worth stating plainly rather than filling with guesses.
What you can do today is concrete and advice-free: measure your exposure, set a price alert within a minute on levels you care about, and review your allocation and security hygiene. If you want one place to do the first two, our honest portfolio tracker comparison shows how PortfolioTrackr fits a multi-exchange, multi-asset holder.
Track your portfolio in real time: free for 3 days
Live P&L across stocks, crypto, and global markets. WhatsApp and Telegram price alerts. AI trade import. Unified dividend tracking. No brokerage connection required.
Start Free Trial See the live demo first →Frequently asked questions
How much was stolen in the NEAR Intents hack?
NEAR Intents was exploited for $3.8 million on October 1, 2026, a figure confirmed consistently by Cointelegraph, Decrypt, CoinDesk and The Block. The team halted services in response and has publicly promised full compensation to affected users, though the mechanism and timeline for that compensation are not yet public.
Is the NEAR Intents hack linked to the Bitget breach?
The reporting places the exploit days after NEAR Intents denied ties to a North Korea-linked hacker connected to the Bitget breach, and Cointelegraph notes it followed assistance with that breach. Whether the same attacker is responsible is not confirmed in the current headlines. Treat the connection as reported context, not an established fact.
Will NEAR Intents users get their money back?
The team has promised full compensation, according to The Block's reporting from October 1, 2026. However, the headlines do not yet specify who qualifies, how much each user receives, or when payments will happen. Watch for an official post-incident statement that spells out the compensation process before assuming anything.
How do I check how much NEAR I actually hold across wallets?
List every exchange, self-custody wallet and staking position, then total your NEAR in one place. PortfolioTrackr lets you combine stocks and crypto across accounts into a single dashboard using manual entry, CSV, text or an optional broker connection, so you can see NEAR's exact weight in your portfolio in your home currency.
How fast will a NEAR price alert notify me?
PortfolioTrackr checks every position and watchlist level once a minute, around the clock, so you hear within a minute of your chosen level being reached. Email, WhatsApp, Telegram and push alerts are on every plan including the free trial, with SMS on Pro and Lifetime. Alerts report status against your levels, not trading advice.
