A thief took $3.87M from NEAR Intents. Then used NEAR Intents to move it
On the night of 30 September someone took $3.87 million out of the vault NEAR Intents uses on BNB Chain. We followed the money across 6 chains to see where it ended up, and which services carried it there.
- $3.87M
- 750 BNB
- 34.69 BTC
- $802k
- 3 rejected
- $90k
01 · A 10 USDT testIt started with a withdrawal of 10 USDT
On the evening of 30 September, a fresh wallet pulled 10 USDT out of a vault on BNB Chain. About an hour later it took 11 more. Nobody had a reason to look. It had put 10 USDT into the same vault 2 days earlier, through a second wallet.
Just before midnight UTC the wallet came back and took 800,000 USDT. Within the hour came 2 bigger withdrawals.
The vault is part of the plumbing behind NEAR Intents, a swap service. You send it a coin on one chain and it pays you a different coin on another, with no bridge to click through. To do that it keeps vaults of coins on the chains it serves. This one held users' money on BNB Chain.
By the next morning the wallet had taken $3.87 million in 5 withdrawals. Around midday NEAR Intents said it had stopped its services after a security incident. It blamed a bug in how its deposit and withdrawal system talks to its smart contract, put the loss at about $3.8 million, and said users would be repaid in full. Within the hour the compliance firm AMLBot had flagged the withdrawals. The investigator ZachXBT reported money heading for KuCoin and Bitcoin.
Bitquery indexes BNB Chain, Ethereum and Bitcoin, so we followed the money to the end and can account for 99% of it. Most is now Bitcoin, sitting in 4 wallets that have not spent a satoshi. The rest reached KuCoin, apart from a small detour into Monero. And on the way out, about a fifth of the loot was swapped through NEAR Intents itself, while the vault was still paying the thief. How the bug worked is not something the chains we read can show. Where the money went is.
02 · What was hitThe vault paid because every request came with a signed note
A vault like this is a smart contract that holds deposits. Our labels mark it as a HOT Protocol contract, and NEAR Intents calls the system around it Omni.
Money goes in the simple way. You send coins to the vault, and the service adds them to your balance. Getting money out takes a signed note. When you ask to withdraw, NEAR Intents' side signs a short message that says how much to pay and to which wallet. That note goes to the vault, and the vault pays.
Nothing in that request tells the vault your balance. NEAR Intents' side keeps it, and the note is how that side tells the vault what you are owed.
All 7 of the thief's withdrawals, the 2 tests and the 5 big ones, came with a note in the same form as everyone else's. That fits what NEAR Intents said. By its account the bug was on the side that decides who is owed what, and the vault did as it was told. On BNB Chain, the only deposit we can tie to the thief before the theft is that 10 USDT. What balance that side believed the thief had, we can't see. The company has promised a full report.
One detail did stand out. In the week to 1 October, nearly every withdrawal was handed to the vault by a single relay wallet, and only a small number of wallets delivered their own. The thief was one of them, which means the thief was holding the signed notes.
03 · The theftFive withdrawals took $3.87M in about 6 hours
The wallet was set up 2 days early. It got a little BNB for gas on 28 September, swapped some of it for USDT, and that evening the 10 USDT deposit went in. Then it sat still for nearly 2 days.
The tests came on the evening of the 30th, and both worked. The real withdrawals began 5 hours after the first test.
The first 3 came inside an hour and took most of the money. A smaller one followed about an hour later. The last, for 35,000 USDT, came soon after 6 in the morning UTC. In the 2 days before the theft, the vault's biggest single stablecoin payout had been under 400,000.
| Time, UTC | USDT | Transaction |
|---|---|---|
| 30 Sep 18:57 | 10 (test) | 0x4f426e…28d5 |
| 30 Sep 20:05 | 11 (test) | 0xc002bd…fdbf |
| 30 Sep 23:54 | 800,000 | 0x9fe58e…6c4c |
| 1 Oct 00:24 | 1,200,000 | 0x038126…8220 |
| 1 Oct 00:50 | 1,500,000 | 0x69d1c6…cceb |
| 1 Oct 01:46 | 330,000 | 0x9c10b9…003a |
| 1 Oct 06:08 | 35,000 | 0x16ddfa…0c02 |
AMLBot's alert listed 4 of the 5, which add up to $3.83 million. The fifth is small, but it matters for the timeline. It shows the vault was still paying this wallet more than 6 hours after the first big withdrawal.
NEAR Intents' statement came about 13 hours after that first one. It does not say when the services were stopped.
04 · Out of BNB ChainThe USDT became BNB within minutes, then spread across 32 wallets
Stolen USDT is risky to hold, because Tether can freeze it at any address. BNB has no issuer with a freeze button. So the thief did what thieves do with stables and swapped, starting 3 minutes after the first big withdrawal landed.
The swaps ran through the swap built into MetaMask and through CoW Swap, a DEX aggregator. The main wallet did most of them and passed the rest to helper wallets, which did the same. Then the BNB was cut into pieces, most of them between 100 and 250 BNB, and sent to 32 wallets that had never been used before. Each did one job and went quiet.
Even a thief gets dusted. Within minutes, address-poisoning bots were spraying these wallets with look-alike tokens, hoping for a careless paste.
From those wallets the money left BNB Chain by 7 doors.
The biggest door was a cross-chain swap service, and 23 of the wallets used it the same way. Each one swapped its BNB for USDT or USDC, and a few seconds later sent the stables into the service's router. We have no label for this service. It moved the USDT to Ethereum and the USDC to Base, and it paid the thief out in ETH and in Bitcoin.
The other 6 were smaller. KuCoin took 800 BNB directly, and MetaMask's bridge carried about as much to Ethereum. One early batch crossed to Arbitrum. A little went to 2 instant-swap desks. The last 2 doors led somewhere we did not expect.
05 · Back through the front doorThe thief swapped loot through NEAR Intents while its vault was still paying out
An hour and 20 minutes into the theft, the main wallet sent 650 BNB to CoW Swap in 2 orders and asked for ETH on Ethereum. CoW Swap leaves the bridging to a partner, and its order records name NEAR Intents as the partner on both.
So the BNB was paid into the same vault the thief was draining, and seconds later NEAR Intents' hot wallet on Ethereum paid the thief 185.5 ETH.
It happened again. About an hour later a helper wallet put 100 BNB straight into the vault. On the Ethereum side 2 more deposits followed, 91.7 ETH between them. The service paid all 3 out in Bitcoin, to the same addresses that were collecting the rest of the loot.
Add it up and about $822k of the loot, roughly a fifth, was handled by NEAR Intents' own swap service. Of that, 750 BNB was paid to the vault that was being drained. After the first of those deposits, the vault paid the thief twice more.
None of this says what NEAR Intents knew, or when. Swaps like these are filled by machines, and a thief's BNB looks like anyone's. What the chain gives us is the order of events.
06 · Into BitcoinThree quarters of the money is now Bitcoin, in 4 wallets
Most of the doors paid out ETH on Ethereum, to the same addresses the thief used on BNB Chain. About 955 ETH arrived there across 6 wallets. None of it stayed.
The thief wanted Bitcoin, and reached for swap protocols with no sign-up, where ETH goes in and native BTC comes out. The first pick was Chainflip. Over 2 hours it took 17 deposits and paid every one out.
Then the door shut. Chainflip's records show the next 3 deposits were rejected by the broker, the front end that opens a swap, and the ETH was sent back. The second was a smaller amount. The third, an hour later, was a single ETH through a different front end. The records do not say why they were turned away. Within 10 minutes of the last one, 1 ETH went into THORChain as a test, and when that went through the rest followed. The Bitget thief leaned on the same 2 protocols the week before.
Every payout, from every service, went to one of 2 Bitcoin addresses, and the smaller of the two emptied into the larger. That hub took in 34.69 BTC and kept none of it.
At 06:40 UTC the hub began to pay out. The first 2 payments went to 2 new wallets, one exactly half the size of the other. Minutes later it split a smaller sum the same way, 2 to 1. A fixed share like that is what a split between partners looks like, or a fee paid to someone who helped. We can't tell which, and it may be neither.
| Bitcoin wallet | BTC held |
|---|---|
| bc1qzsrxkz…vtn8 | 15.7675 |
| bc1qjkdzyt…zmrc | 9.5757 |
| bc1qkm5d88…zktz | 8.6713 |
| bc1q4kddgq…ljen | 0.6750 |
| Total | 34.69 |
By the afternoon the Bitcoin sat in those 4 wallets. None of them has sent a transaction.
07 · KuCoinA fifth of the money went to KuCoin, by 2 routes
The second-biggest destination was an exchange. In the first 4 hours, 5 of the fresh wallets sent their BNB to a single address, 800 BNB in all. That address behaves like a KuCoin deposit address. A KuCoin wallet has topped it up with gas before, and every deposit was swept within 2 minutes into wallets our labels mark as KuCoin's.
This address is older than the theft. It took its first deposit on 6 August, 8 weeks earlier, and a few small ones since. An exchange deposit address belongs to one account, and KuCoin knows whose.
The second route ran on Ethereum and is harder to see. The thief sent 70 ETH to wallets that passed it along, hop by hop, into 3 more addresses that sweep into KuCoin. Those 3 are busy. Each has taken ETH from at least 16 senders since 25 September. And 2 of the wallets in between were receiving withdrawals from Gate, another exchange, in the hours before the theft began. That looks more like an OTC desk, someone who cashes out crypto for other people, than a set of wallets made for this theft.
Together the 2 routes carried about $802k.
08 · A detour into MoneroThe first $90k went looking for Monero
One batch took a different road. An hour into the theft, before any of the Bitcoin swaps, 120 BNB was swapped and bridged to Arbitrum as USDC. It landed, and 13 seconds later it was on its way to Hyperliquid through the exchange's bridge. Within half a minute of arriving, all of it had been spent on XMR1, a token on Hyperliquid's spot market that stands for Monero.
Monero is the coin people reach for when they want a trail to end. If that was the plan, it stalled. When we last checked, 165.3 XMR1 was still sitting in the Hyperliquid account, untouched. The thief never used this route again. Everything after it went to Bitcoin or KuCoin.
09 · The whole routePut together, 99% of the money is accounted for
Lay the routes side by side and very little is missing.
The Bitcoin, the KuCoin deposits and the Monero token add up to 99% of what was taken. The last 1% is swap and bridge costs, plus some rounding in the prices we used. The teal bands are the part NEAR Intents carried.
10 · Open questionsWho did it is not on the chain
Nothing here names the thief. The strongest lead is KuCoin, which holds the identity behind each of those deposit addresses. If the second route was an OTC desk, the desk knows who paid it.
One thing that looks like a clue is no such thing. On the afternoon of 1 October, after the theft was public, 2 of the thief's wallets sent their leftover dust to an address the US Treasury lists under North Korea's Lazarus Group. Anyone can send dust to any address. It could be a joke or a false flag, and it proves nothing about who is behind this.
A couple of smaller questions are open. The company put the loss at about $3.8 million and we count $3.87 million, so its report may show whether the last, small withdrawal is in its figure. And the swap service that carried the largest share is still unnamed.
So the vault that paid 10 USDT to a stranger on the evening of 30 September had paid the same wallet $3.87 million by the next morning. When we last looked, 34.69 BTC of it was waiting in 4 wallets that have never spent. The next move, when it comes, will be on a public ledger.
11 · How we traced itMethod
We read every transfer in and out of the thief's wallets on BNB Chain, Ethereum and Base, and every payment to the Bitcoin addresses. Where the money crossed a bridge or a swap protocol, we matched each deposit to its payout using the protocol's own public record of the swap. A few payouts have no such record, and those we matched by time and size. Balances were checked again at 14:30 UTC on 1 October. Dollar figures use the prices the thief got in their own swaps.
The same trail can be followed with the Bitquery MCP. If you need a case like this traced for you, that is what our investigations team does.
12 · The recordAddresses and transactions behind this story
| What | Address or transaction |
|---|---|
| Thief's wallet | 0x09fd1f…ad37 |
| Vault drained | 0x233c53…b4cd |
| First test | 0x4f426e…28d5 |
| First big withdrawal | 0x9fe58e…6c4c |
| Last withdrawal | 0x16ddfa…0c02 |
| Helper wallet 1 | 0xde85b9…6b1c |
| Helper wallet 2 | 0x62eb7a…98af |
| Helper wallet 3 | 0x36b4ed…de7a |
| Helper wallet 4 | 0x168f36…f3b7 |
| Swap service router | 0xadd2b3…2d1d |
| KuCoin deposit, BNB | 0xcd87c2…b262 |
| KuCoin deposit, ETH | 0xecf238…d7a8 |
| KuCoin deposit, ETH | 0x1b181e…8324 |
| KuCoin deposit, ETH | 0x25b482…c2a5 |
| NEAR Intents payout 1 | 0x383ee2…8c6f |
| NEAR Intents payout 2 | 0x1b589d…73c9 |
| Chainflip vault | 0xf5e103…2bcc |
| THORChain router | 0xd37bbe…7146 |
| Bitcoin hub | bc1qsyrcml…tsn8 |
| Hyperliquid account | 0x0e77cb…8616 |
FAQ
How much was stolen in the NEAR Intents hack?
About $3.87 million in USDT left the vault NEAR Intents uses on BNB Chain, in 5 withdrawals between the night of 30 September and the morning of 1 October 2026. NEAR Intents put the loss at about $3.8 million and said users would be repaid in full.
Where did the stolen money go?
About three quarters is now Bitcoin, 34.69 BTC held in 4 wallets that have not spent. About a fifth reached KuCoin deposit addresses. A small part was turned into a Monero token on Hyperliquid. Together that is 99% of the money.
Did the thief use KuCoin?
Yes. 800 BNB went to a deposit address on BNB Chain that sweeps into KuCoin's wallets, and 70 ETH reached 3 more KuCoin deposit addresses on Ethereum through other wallets. The BNB Chain address had been in use since 6 August. Whether the accounts belong to the thief or to an OTC desk is something only KuCoin can see.
Did the thief really use NEAR Intents to move the money?
Yes. About $822k of the loot was swapped on NEAR Intents' own service during the theft. Part of it was BNB paid straight to the vault that was being drained, and NEAR Intents paid the thief ETH and Bitcoin in return.
Is the Lazarus Group behind the NEAR Intents hack?
Nothing on the chain shows that. After the theft became public, 2 of the thief's wallets sent leftover dust to an address the US Treasury lists under the Lazarus Group. Anyone can send dust to any address, so it proves nothing.
Will NEAR Intents users get their money back?
NEAR Intents said the funds would be compensated in full, that the contract-side bug had been patched, and that a detailed report would follow. That is the company's statement. The chain cannot confirm it.
All balances are as of 14:30 UTC on 1 October 2026. The Bitcoin wallets and the Hyperliquid account can move at any time.
Dollar figures use flat prices taken from the thief's own swaps, about $766 per BNB, $2,700 per ETH and $84,500 per BTC. Coin amounts are exact.
Chainflip, THORChain, Mayan, Relay and CoW Swap publish a record of each swap, and those records tie deposits to payouts. The Bitcoin payouts from the unnamed swap service and from NEAR Intents, and one Relay order, have no public record. They are matched by time, size and the wallet that paid.
KuCoin and Gate wallets, NEAR Intents' wallet on Ethereum and the MetaMask swap and bridge contracts are identified by Bitquery's address labels and by how the addresses behave. A deposit address shows which exchange received money. It does not show who owns the account.
The same vault address on Polygon and Optimism shows no large unusual payout in the same hours. We did not check the other networks NEAR Intents named, among them TON, Avalanche, Stellar and Monad.
The cause of the incident is taken from NEAR Intents' statement. Nothing in this article is a finding about how the bug worked.
This article is provided for informational and educational purposes only and reflects analysis of publicly available on-chain data as of the dates indicated. It does not constitute legal, financial, compliance, or investment advice, and nothing in it is a recommendation to buy, sell, or hold any token or asset.
The findings describe transfers, swaps and balances observed on BNB Chain, Ethereum, Base, Arbitrum, Hyperliquid and Bitcoin on 30 September and 1 October 2026, together with the public swap records of the protocols named. Attributions come from Bitquery's address labels and from on-chain behaviour; they may be incomplete or incorrect and may be revised as more data becomes available.
References to NEAR Intents, HOT Protocol, KuCoin, Gate, Chainflip, THORChain, CoW Swap, MetaMask, Hyperliquid or any other named company or protocol describe what the record shows about addresses and swaps linked to them. They are not statements about any party's security practices, compliance, solvency or conduct, and nothing here asserts that any party acted unlawfully or negligently. The wallets that received the stolen funds are described by their behaviour and attributed to nobody.
Nothing herein should be relied upon as a definitive determination of fact. Readers should conduct their own independent verification before taking any action. The authors and publisher accept no liability for any loss or damage arising from reliance on this material. All trademarks and company names are the property of their respective owners.
Reported by Gaurav Agarwal for Bitquery Research, with AI tools; every figure was checked against the raw data.
Ask these questions in plain English
The transfers in this story come from Bitquery's data for BNB Chain, Ethereum, Base and Bitcoin. The Bitquery MCP server puts that data behind an AI assistant, so you can ask where a wallet's money came from, where it went, or what labels an address carries, without writing the query yourself.