0x7998c15c7998…7998c15f
NEAR Intents Says It Identified Hacker Behind $3.8M Exploit
NEAR Intents says it identified the hacker behind a $3.8 million exploit and gave them 48 hours to return the funds before escalating to legal action.

Outputs
NEAR Intents says it identified the hacker behind a $3.8 million exploit
The protocol gave the attacker 48 hours to return the stolen funds
A missed deadline would likely trigger legal action and public identification
NEAR Intents, the cross-chain swap protocol built on the NEAR blockchain, says it has identified the individual responsible for a recent exploit that drained approximately $3.8 million from the platform. The team has given the attacker 48 hours to return the stolen funds before it pursues further action.
The disclosure, reported by CryptoRank, marks an unusually aggressive posture for a DeFi protocol recovering from an exploit. Rather than quietly negotiating through an intermediary or waiting for law enforcement to act, NEAR Intents has publicly confirmed it knows who carried out the theft and has set a hard deadline for restitution.
The 48-hour window is the latest instance of a growing practice among exploited protocols: offering attackers a defined grace period to return funds, typically paired with an implicit or explicit threat of legal exposure, law enforcement referral, or public identification. If the attacker complies within the window, protocols sometimes offer a bounty or waive pursuit entirely. If the deadline passes, the calculus shifts toward doxxing, criminal referral, and on-chain tracing in cooperation with analytics firms.
For NEAR Intents, the stakes are operational as much as financial. The protocol facilitates cross-chain transactions, a segment of decentralized finance where user confidence in bridge and swap infrastructure is fragile. A swift, public resolution — funds returned, attacker named or neutralized — would limit reputational damage and reduce the likelihood of sustained outflows. A protracted standoff could do the opposite, compounding the initial $3.8 million loss with eroded liquidity and user attrition.
The decision to name a deadline also signals that the team believes its forensic trail is strong. Protocols rarely commit publicly to having identified an attacker unless on-chain tracing, exchange deposit addresses, or off-chain data have converged on a plausible real-world identity. That claim, if accurate, materially raises the pressure on the attacker: moving funds through centralized exchanges becomes riskier once a victim protocol has flagged specific addresses and signaled intent to escalate.
Cross-chain infrastructure remains one of the most targeted categories in crypto. Bridge and intent-based protocols custody or route user assets across networks, creating concentrated pools of capital and complex messaging surfaces that attackers have repeatedly exploited. Incident response in this segment now follows a fairly standardized playbook — pause affected contracts, trace flows, contact exchanges and analytics providers, and issue a public ultimatum — and NEAR Intents appears to be executing precisely that sequence.
What happens at the end of the 48-hour window will determine the next phase. A return of funds would close the incident quickly and relatively cheaply. A missed deadline would likely trigger law enforcement involvement, public identification of the suspect, and a longer recovery process dependent on courts and blockchain analytics rather than negotiation.
The clock is now running. By the time the deadline lapses, the market will know whether NEAR Intents' identification claim was leverage enough to recover the $3.8 million — or the opening move in a formal prosecution.
via Google News - Crypto Hack Exploit (Source)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles