0x2fb8def72fb8…2fb8defa
Near Intents Recovers $3.8M After 48-Hour Ultimatum to Exploiter
Near Intents recovered $3.8 million in exploited funds after a 48-hour public ultimatum that named the receiving address, in a negotiation-driven pattern spreading across intent-based exchanges.

Outputs
Near Intents recovered $3.8 million in previously exploited funds
The recovery followed a 48-hour public ultimatum directed at the receiving address
The team's on-chain message read: 'We have identified you, sir'
The recovery was disclosed in a Decrypt report citing a Near Intents statement
A full technical post-mortem on the exploit vector has not yet been published
The intent-based settlement layer operated by NEAR Protocol returned $3.8 million in previously exploited funds after a 48-hour public ultimatum, according to a statement from Near Intents reported by Decrypt.
In a message directed at the wallet it accused of receiving the proceeds, the team wrote: "We have identified you, sir." The warning — issued through Near Intents' official channels and on-chain — preceded the return of the $3.8 million within the two-day window. The sequence fits an emerging playbook of negotiation-driven recoveries rather than traditional law-enforcement seizure.
What is Near Intents?
Near Intents is the trading layer built on NEAR Protocol that lets users, wallets and aggregators express a desired outcome — typically a token swap, a cross-chain transfer or a limit-style fill — and have a network of competing "solvers" bid to execute it. Settlement then spans chains, with NEAR's chain-abstraction features routing the resulting flows back to the user.
Because settlement crosses networks and relies on solver-provided liquidity, exploits typically target one of three layers:
- Cross-chain message authentication, where a forged proof misleads the settlement engine
- Solver collateralization, where an attacker manipulates inventory posted against a quoted price
- Solver front-running or sandwiching, where an MEV searcher trades ahead of a solver's fill
The team did not, in materials reported by Decrypt, disclose which vector the recent incident exploited, and a full technical post-mortem has not yet been published.
How did the ultimatum work?
The recovery followed a roughly 48-hour window during which Near Intents publicly disclosed identifying information about the address that received the exploited funds. The communication treated the wallet as a known counterparty rather than an anonymized attacker. The framing is common across recent crypto recovery operations, in which the cost of holding illicit proceeds is weighed against the cost of legal contest by the holder.
Two structural conditions typically make such negotiations succeed:
- The exploit sum is small enough that protracted civil litigation is not economically rational
- The identifying information is concrete enough to be actionable but stops short of fully doxxing an individual, preserving a face-saving route for return
The $3.8 million figure sits within both conditions.
What changes for solver-based exchanges?
The case adds to a small but consistent ledger of intent-system recoveries that underscore two operational realities now under sharper industry focus.
First, solvers carry capital-at-risk across chains in ways traditional centralized exchanges do not. Every fill exposes them to MEV-style sandwiching and authorization-flavored exploits, and the race to provide quotes in intent exchanges compresses the window in which a malicious quote can be detected.
Second, identifying the operator of an address — even pseudo-anonymously — has proven sufficient to compel a return when the exploit sum sits below a litigation-cost threshold.
The 48-hour window itself has now become an operational template. A future Near Intents exploit of comparable size is likely to trigger a similar ultimatum, and competing intent layers — UniswapX, 1inch Fusion, Across, deBridge — will be measured by whether they adopt comparable recovery playbooks or default to slower law-enforcement paths.
What comes next?
The near-term deliverable to watch is Near Intents' full technical post-mortem. The team has signaled the write-up would follow, and the NEAR Protocol Foundation's open governance forum is the most likely venue for any rule changes.
Solvers on the layer should expect tighter KYC and treasury-segregation requirements on bounty resolutions. Institutional market-makers evaluating intent systems will treat the recovery as a narrow but positive data point on operational resilience. The published 48-hour timeline sets an informal benchmark against which future intent-system exploits will be measured.
via Google News - Crypto Hack Exploit (Source)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles