0x20be4bea20be…20be4bed

ConfirmedSecurity456 vB140 sat/vB2 min decode

NEAR Intents Sets 48-Hour Deadline for Attacker to Return $3.8 Million

NEAR Intents' general manager says the attacker who drained a preliminary $3.8 million has been identified, and set a 48-hour deadline for return. Three addresses posted.

Shevchenko Gives NEAR Intents Attacker 48 Hours
WitnessShevchenko Gives NEAR Intents Attacker 48 HoursAI-generated

Outputs

  1. NEAR Intents attacker drained a preliminary $3.8 million.

  2. The general manager says the attacker has been identified.

  3. A 48-hour deadline was set for returning the funds.

  4. Three return addresses were posted; none had received funds as of early Oct. 2, 2025.

The general manager of NEAR Intents has given an attacker 48 hours to return a preliminary $3.8 million drained from the protocol, stating that the individual behind the exploit has been identified.

The deadline demand came with three on-chain addresses posted publicly for the return of the funds. As of early Oct. 2, none of the three addresses had received any of the stolen money, according to on-chain records referenced in the disclosure.

What happened in the exploit?

The attack drained a preliminary $3.8 million from NEAR Intents, a cross-chain intent-based protocol built on the NEAR blockchain. The figure is described as preliminary, which suggests the final accounting of losses may change as the team continues to trace the affected flows.

The general manager's public statement marks a shift from initial incident response to direct negotiation posture. Publishing return addresses is a common tactic in post-exploit situations, giving an identified attacker a channel to restitution while implicitly signaling that doxxing or legal escalation may follow non-compliance.

Why set a 48-hour deadline?

The 48-hour window functions as a structured ultimatum. Protocol teams that claim to have identified an attacker typically pair that claim with a short deadline to pressure a negotiated return, often in exchange for a bounty or a commitment not to pursue criminal referral.

The general manager did not state in the disclosure what consequences would follow if the deadline passes without restitution. The claim of identification itself carries operational weight: it implies the team has linked on-chain activity to an identifiable party, whether through chain analysis, infrastructure forensics, or third-party investigators.

As of early Oct. 2, the three posted addresses remained empty. That fact alone does not determine the outcome — attackers in prior incidents have returned funds well after deadlines expired, and others have ignored them entirely.

What are the operational consequences?

For NEAR Intents, the immediate priority is recovery of the $3.8 million. Beyond that, the incident will force a review of the protocol's bridge and intent-settlement infrastructure, since the funds were drained from the system rather than lost to a market event.

Key open questions following the disclosure:

  • Whether the attacker returns funds to any of the three addresses before or after the deadline lapses.
  • Whether the identification claim holds up and leads to legal action, either by the protocol or by law enforcement.
  • Whether the preliminary $3.8 million figure is revised as the investigation continues.

The next verifiable checkpoint is the expiration of the 48-hour window. If the posted addresses remain empty after it passes, the matter likely moves toward public disclosure of the attacker's identity, formal law enforcement referral, or both.

via The Defiant (Source)

More from Daniel Okafor

Daniel Okafor

Show full bio

Correspondent covering industry trends and analytics at Mempool Brief.

435 articles