NEAR Intents has publicly claimed it tracked down the attacker responsible for a roughly $3.8 million exploit, issuing the hacker a 48-hour deadline to return the stolen funds before the matter is handed to law enforcement.
## The Breach and the Response The cross-chain protocol confirmed it suffered a security incident that drained approximately $3.8 million in user assets. In an unusually direct public message, NEAR Intents general manager Alex Shevchenko addressed the perpetrator head-on, declaring the team had uncovered the attacker's identity.
Shevchenko's blunt "We have identified you, sir" statement on Friday set the tone for the protocol's hardline approach. Rather than quietly pursuing recovery, the team opted to apply public pressure, offering the hacker a window to make amends before escalating the situation.
"We have identified you, sir."
The 48-hour ultimatum gives the attacker a short runway to return the funds. Should the deadline pass without compliance, NEAR Intents indicated it would pursue the matter through legal and investigative channels.
## What's at Stake The incident adds to a long and growing list of exploits targeting the crypto sector, where cross-chain and intent-based protocols have become frequent targets due to the complexity of their smart contract systems and the value they custody.
For affected users, the central question remains whether any of the lost funds can be recovered. Public identification tactics have occasionally pressured attackers into returning stolen assets in exchange for avoiding prosecution, though outcomes vary widely across incidents.
Key points surrounding the situation include:
- An estimated $3.8 million was drained in the exploit
- NEAR Intents says it has identified the attacker
- The hacker has 48 hours to return the funds
The coming days will test whether the protocol's confidence in identifying the hacker translates into actual recovery, or whether the stolen funds join the billions already lost to crypto exploits in recent years.
