NEAR Intents
NEAR Intents Security Review
Medium Potential Funds Stealing From Users Via Repeating Failed Intents
Full reports published with client permission, including findings, evidence, and remediation status.
Each report includes the full findings and severity ratings.
Since September 2026, our reports also include a threat model, security invariants, tests added to your repository and an evidence appendix. The reports below were published before that and use the earlier format.
23 reports
NEAR Intents Security Review
Medium Potential Funds Stealing From Users Via Repeating Failed Intents
NEAR Intents Passkeys Pull Request Security Review
Medium Potential DoS of The Main Functionality Through Malicious Solvers
NEAR Smart Contract Security Review
Critical Race Condition in Borrow Functionality
Web Application Security Review
Critical Vulnerable to React2Shell
Onchain Orderbook and Perpetual Trading Security Review
Critical Order Placement with Negative/Zero Margin Ratio Is Possible
SWEAT NEP-141 Token Security Review
High LookupMap adapter can undercharge storage for selected accounts
Sweat Jars Migration & Refactor Smart Contract Review
Medium Possible Double Claim Through Race Condition
Tiered Jars & Boosters Smart Contract Security Review
Low Possible overflows
Sweat Booster & Step Jars Security Review
Critical Missing Access Control On NFT Transfer Resolver
Jars Refactor Security Review
High Potential DoS of Batch Operations
Burn Model Changes Security Review
Low Error Prone Burn Rate Calculation
Defer Feature Security Review
Low Race Condition Lock Is Not Asserted
Single Chain Smart Contracts Security Review
High Supply Withdrawal Mechanism DoS
Solana Trading Bot Security Review
Medium Incorrect Use of Async in Reward Distribution
Relaychain and Matrixchain Security Review
Critical DoS of Fuel Tank Mutation
Claims Pallet Security Review
Critical DoS of Claiming Functionality
Pallet Pass Security Review
High DoS of The Main Functionality Through Session Key Hijacking
IP and Media Protocol Security Review
Critical Anyone Can Update The NFT Holder In Treasury
Decentralized Investment Platform Security Review
Critical Irrecoverable Denial-of-Service Condition In Vault Contract
Portal for Public Goods and Funding Security Review
Critical DoS of Process Payouts
Smart Router and Farm Security Review
Critical Token Draining Through Invalid Callback Handling
Backend & Frontend Security Assessment
Critical Indexer Crash Due to Invalid UTF-8 Character
Airdrop Script Security Review
Medium Lack of Error Handling in Airdrop Script
No reports match those filters.
Describe your system, main concern, and deadline. We'll reply with scoping questions and a proposed next step.
Discuss your scope