NEAR Intents exploit: 3.87M USDT in seven withdrawals, and one KuCoin account that took ~590 BNB
PublicAML · On-chain investigation · 2 October 2026
NEAR Intents says a bug in how its Omni deposit-and-withdrawal layer talks to its contract let an attacker take about $3.8 million in USDT on BNB Chain. The team has published no addresses. BscScan has tagged the exploiter, and we followed it. The money left the bridge’s treasury in seven withdrawals over eleven hours, between 18:57 UTC on 30 September and 06:08 UTC on 1 October — 3,865,031 USDT in all. Almost all of it was swapped to BNB within hours and split across bridges, swap services and exchange deposits. The clearest lead: about 590 BNB was routed through four relay wallets into one single KuCoin deposit account.
3,865,031 USDT
withdrawn to the exploiter in 7 transactions
11 hours
30 Sep 18:57 → 1 Oct 06:08 UTC
~590 BNB
into one KuCoin deposit account, via 4 relays
~760 BNB
sent out through MetaMask Bridge
What happened
NEAR Intents moves funds between chains through its Omni layer; on BNB Chain the money sits with the bridge treasury, 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd (tagged “HOT Bridge: Treasury”). According to NEAR Intents, a bug in how that layer’s deposits and withdrawals interacted with its smart contract let one account withdraw money it was not owed. The team fixed it within an hour of noticing, paused service, promised to repay users in full, and has asked the attacker to return the funds.
The withdrawals went to 0x09Fd1f5d9F185067A92493E43AA259ea4AB3ad37, which BscScan tags “Near Intents Exploiter 1”. It was active from 28 September. The first withdrawal landed at 18:57 UTC on 30 September; more followed at 20:05, 23:54, 00:24, 00:50, 01:46 and finally 06:08 UTC on 1 October. Our trace counts 3,865,031 USDT received.
Two days before, NEAR Intents had publicly refused a $50 million swap from the Bitget attacker. Whether the two are linked is not known; nothing on chain here connects them.
Where the money went
The USDT did not stay USDT for long. About 1.5M was sold through CoW Protocol and about 1.07M through MetaMask Swap, directly or via short-lived intermediate wallets, for BNB. From there it scattered:
One KuCoin account. Four relay wallets — such as 0xD97023F912C15545867083c54a4fF633F66554eb — each received 100–250 BNB from the exploiter and passed it on to the same address, 0xcd87C2e1F53B7dF97f1db56aEC6c63cBd60BB262, which forwards everything to KuCoin’s hot wallet. Together about 590 BNB went into that one deposit account. A deposit account belongs to one KuCoin customer, and KuCoin knows who that is.
Bridges. About 760 BNB went out through MetaMask Bridge, 0xaEc23140408534b378bf5832defc426dF8604B59, directly and through one intermediate address; 120 BNB went through LI.FI from 0x0E77CBf891b90C73e2fC5dfF6D78EC2E383c8616. This is the “bridged to Bitcoin” leg other reports describe; we did not follow it off BNB Chain.
CoW Protocol. 650 BNB were sold through CoW Protocol’s ETH-flow contract, 0xbA3cB449bD2B4ADddBc894D8697F5170800EAdeC, in two orders.
A swap service’s deposit addresses. Eight addresses, such as 0xB2dF55EC8f0D33Db37E43A5814D0d75BF65c84da, each received 85–100 BNB — about 775 BNB in all. They look parked, but they are deposit forwarders of one service: all were created by the same factory and all sweep into one hub, and they carry other customers’ USDT as well. The service is not publicly labelled, so we do not name it.
Back into the same bridge. One intermediate wallet, 0x554B7dd2f5b1521ecd2f4FCc628CFf0E1bF2447e, deposited 100 BNB into the HOT bridge treasury — the infrastructure the money came from.
| When (UTC, 2026) | From | To | Amount | Tx |
|---|---|---|---|---|
| 30 Sep 18:57 | 0x233c53…4Cb4Cd | 0x09Fd1f…B3ad37 | USDT (1st of 7) first withdrawal from the bridge treasury | 0x4f426e…1428d5 |
| 1 Oct 06:08 | 0x233c53…4Cb4Cd | 0x09Fd1f…B3ad37 | USDT (7th of 7) seventh and last withdrawal | 0x16ddfa…b90c02 |
| 1 Oct | 0x09Fd1f…B3ad37 | 0xD97023…6554eb | 250 BNB to a relay wallet | 0x3001f1…fd916f |
| 1 Oct | 0xD97023…6554eb | 0xcd87C2…0BB262 | 150 BNB relay → KuCoin deposit account | 0x3b995d…f15742 |
| 1 Oct | 0x09Fd1f…B3ad37 | 0xaEc231…604B59 | 200 BNB into MetaMask Bridge | 0xa55688…f6cc27 |
| 1 Oct | 0x0E77CB…3c8616 | 0x1231DE…6F4EaE | 120 BNB out through LI.FI | 0x145e13…4bbb57 |
| 1 Oct | 0x09Fd1f…B3ad37 | 0xbA3cB4…0EAdeC | 350 BNB sold through CoW Protocol | 0xde3123…e663ff |
| 1 Oct | 0x09Fd1f…B3ad37 | 0xB2dF55…5c84da | 100 BNB into a swap service’s deposit address | 0x1eedc8…d1b7ce |
| 1 Oct | 0x554B7d…F2447e | 0x233c53…4Cb4Cd | 100 BNB deposited back into the HOT bridge | 0xa11b8b…b5270a |
What this means for recovery
Almost nothing is left on the attacker’s own addresses: the exploiter wallet and its relays are empty. What remains recoverable sits with the services the money passed through — above all the KuCoin deposit account, which received about 590 BNB in a handful of transfers, and the swap service whose deposit addresses received about 775 BNB. Both can identify the account holder.
The exploiter’s history is now flooded with fake “USDT” tokens and dust from look-alike addresses — address poisoning aimed at anyone who copies an address from it. They are not part of the trail. If you are checking an address from this incident, copy it from this page or BscScan’s tag, not from a recent transaction.
What this page does not say
It names nobody and does not say who controls any wallet. The exploiter address is the one BscScan tags publicly; the cause of the bug is NEAR Intents’ own account. Amounts per destination are from on-chain transfers on 30 September – 2 October 2026; the bridged BNB was not followed onto other chains.
Sources: BNB Chain data read on BscScan (including its public tag “Near Intents Exploiter 1”) and through PublicAML’s trace, 2 October 2026; NEAR Intents’ statements for the cause and the compensation; ZachXBT for first reporting the KuCoin and Bitcoin route. Only the real BSC-USD contract (0x55d398326f99059ff775485246999027b3197955) and native BNB are counted. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.