NEAR Intents exploit: 3.87M USDT in seven withdrawals, and one KuCoin account that took ~590 BNB

PublicAML · On-chain investigation · 2 October 2026

NEAR Intents says a bug in how its Omni deposit-and-withdrawal layer talks to its contract let an attacker take about $3.8 million in USDT on BNB Chain. The team has published no addresses. BscScan has tagged the exploiter, and we followed it. The money left the bridge’s treasury in seven withdrawals over eleven hours, between 18:57 UTC on 30 September and 06:08 UTC on 1 October — 3,865,031 USDT in all. Almost all of it was swapped to BNB within hours and split across bridges, swap services and exchange deposits. The clearest lead: about 590 BNB was routed through four relay wallets into one single KuCoin deposit account.

3,865,031 USDT

withdrawn to the exploiter in 7 transactions

11 hours

30 Sep 18:57 → 1 Oct 06:08 UTC

~590 BNB

into one KuCoin deposit account, via 4 relays

~760 BNB

sent out through MetaMask Bridge

What happened

NEAR Intents moves funds between chains through its Omni layer; on BNB Chain the money sits with the bridge treasury, 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd (tagged “HOT Bridge: Treasury”). According to NEAR Intents, a bug in how that layer’s deposits and withdrawals interacted with its smart contract let one account withdraw money it was not owed. The team fixed it within an hour of noticing, paused service, promised to repay users in full, and has asked the attacker to return the funds.

The withdrawals went to 0x09Fd1f5d9F185067A92493E43AA259ea4AB3ad37, which BscScan tags “Near Intents Exploiter 1”. It was active from 28 September. The first withdrawal landed at 18:57 UTC on 30 September; more followed at 20:05, 23:54, 00:24, 00:50, 01:46 and finally 06:08 UTC on 1 October. Our trace counts 3,865,031 USDT received.

Two days before, NEAR Intents had publicly refused a $50 million swap from the Bitget attacker. Whether the two are linked is not known; nothing on chain here connects them.

Where the money went

The USDT did not stay USDT for long. About 1.5M was sold through CoW Protocol and about 1.07M through MetaMask Swap, directly or via short-lived intermediate wallets, for BNB. From there it scattered:

One KuCoin account. Four relay wallets — such as 0xD97023F912C15545867083c54a4fF633F66554eb — each received 100–250 BNB from the exploiter and passed it on to the same address, 0xcd87C2e1F53B7dF97f1db56aEC6c63cBd60BB262, which forwards everything to KuCoin’s hot wallet. Together about 590 BNB went into that one deposit account. A deposit account belongs to one KuCoin customer, and KuCoin knows who that is.

Bridges. About 760 BNB went out through MetaMask Bridge, 0xaEc23140408534b378bf5832defc426dF8604B59, directly and through one intermediate address; 120 BNB went through LI.FI from 0x0E77CBf891b90C73e2fC5dfF6D78EC2E383c8616. This is the “bridged to Bitcoin” leg other reports describe; we did not follow it off BNB Chain.

CoW Protocol. 650 BNB were sold through CoW Protocol’s ETH-flow contract, 0xbA3cB449bD2B4ADddBc894D8697F5170800EAdeC, in two orders.

A swap service’s deposit addresses. Eight addresses, such as 0xB2dF55EC8f0D33Db37E43A5814D0d75BF65c84da, each received 85–100 BNB — about 775 BNB in all. They look parked, but they are deposit forwarders of one service: all were created by the same factory and all sweep into one hub, and they carry other customers’ USDT as well. The service is not publicly labelled, so we do not name it.

Back into the same bridge. One intermediate wallet, 0x554B7dd2f5b1521ecd2f4FCc628CFf0E1bF2447e, deposited 100 BNB into the HOT bridge treasury — the infrastructure the money came from.

When (UTC, 2026)FromToAmountTx
30 Sep 18:570x233c53…4Cb4Cd0x09Fd1f…B3ad37USDT (1st of 7)
first withdrawal from the bridge treasury
0x4f426e…1428d5
1 Oct 06:080x233c53…4Cb4Cd0x09Fd1f…B3ad37USDT (7th of 7)
seventh and last withdrawal
0x16ddfa…b90c02
1 Oct0x09Fd1f…B3ad370xD97023…6554eb250 BNB
to a relay wallet
0x3001f1…fd916f
1 Oct0xD97023…6554eb0xcd87C2…0BB262150 BNB
relay → KuCoin deposit account
0x3b995d…f15742
1 Oct0x09Fd1f…B3ad370xaEc231…604B59200 BNB
into MetaMask Bridge
0xa55688…f6cc27
1 Oct0x0E77CB…3c86160x1231DE…6F4EaE120 BNB
out through LI.FI
0x145e13…4bbb57
1 Oct0x09Fd1f…B3ad370xbA3cB4…0EAdeC350 BNB
sold through CoW Protocol
0xde3123…e663ff
1 Oct0x09Fd1f…B3ad370xB2dF55…5c84da100 BNB
into a swap service’s deposit address
0x1eedc8…d1b7ce
1 Oct0x554B7d…F2447e0x233c53…4Cb4Cd100 BNB
deposited back into the HOT bridge
0xa11b8b…b5270a

What this means for recovery

Almost nothing is left on the attacker’s own addresses: the exploiter wallet and its relays are empty. What remains recoverable sits with the services the money passed through — above all the KuCoin deposit account, which received about 590 BNB in a handful of transfers, and the swap service whose deposit addresses received about 775 BNB. Both can identify the account holder.

The exploiter’s history is now flooded with fake “USDT” tokens and dust from look-alike addresses — address poisoning aimed at anyone who copies an address from it. They are not part of the trail. If you are checking an address from this incident, copy it from this page or BscScan’s tag, not from a recent transaction.

What this page does not say

It names nobody and does not say who controls any wallet. The exploiter address is the one BscScan tags publicly; the cause of the bug is NEAR Intents’ own account. Amounts per destination are from on-chain transfers on 30 September – 2 October 2026; the bridged BNB was not followed onto other chains.

Sources: BNB Chain data read on BscScan (including its public tag “Near Intents Exploiter 1”) and through PublicAML’s trace, 2 October 2026; NEAR Intents’ statements for the cause and the compensation; ZachXBT for first reporting the KuCoin and Bitcoin route. Only the real BSC-USD contract (0x55d398326f99059ff775485246999027b3197955) and native BNB are counted. This is an information resource about transactions between addresses, not financial or legal advice, and it names no individual as responsible for anything.