🚨 GoPlus Security Alert:
@near_intents HOT Bridge Treasury (BSC hot wallet) was exploited for ~$3.87M. Team committed | Hanami
🚨 GoPlus Security Alert:
@near_intents HOT Bridge Treasury (BSC hot wallet) was exploited for ~$3.87M. Team committed to making users whole.
Root cause: a bug in the Omni deposit/withdrawal infra when it interacts with the NEAR Intents contracts. Early assessment points to a withdrawal authorization bypass.
Exploit isolated to NEAR Intents and the Omni/HOT Bridge deposit/withdrawal stack — not NEAR Protocol mainnet contracts, not an L1 compromise. Contract-side vuln is patched. Omni-side fix still underway.
Victim: 0x233c5370CCfb3cD7409d9A3fb98ab94dE94Cb4Cd
Attacker: 0x09fd1f5d9f185067a92493e43aa259ea4ab3ad37
Flow: BSC hot wallet → fast CEX routing through KuCoin → bridged to BTC.
ZachXBT follow-up: attacker address interacted with a Lazarus-labeled address (0x098B7…E2f96). Classic DPRK laundering pattern — speed-run into a CEX, then flip to BTC.
NEAR Intents has not confirmed attribution. DPRK ties remain unconfirmed.