NEAR Intents General Manager Issues 48-Hour Ultimatum to $3.8M Attacker
NEAR Intents management identified the perpetrator behind a $3.8 million exploit and provided a two-day deadline for returning stolen funds.

The NEAR Intents exploit ultimatum was officially delivered by the protocol's general manager, Kendall Shevchenko, after an unauthorized intruder drained an estimated $3.8 million from the decentralized trading system. Shevchenko publicly disclosed that security investigators had established the real-world identity of the exploiter and published three designated wallet addresses to facilitate the restitution of the missing capital.
According to reporting from The Defiant, the recovery deadline gives the attacker a strict 48-hour window to return the extracted assets before law enforcement referrals and legal proceedings commence. As of early October 2, blockchain records indicated that none of the specified restitution addresses had received any transfers from the exploiter's addresses.
Intent-based decentralized architectures have seen rapid adoption across decentralized finance by enabling users to specify desired trade outcomes that specialized market makers fulfill off-chain. However, rapid deployment of complex settlement logic has occasionally exposed smart contract vulnerabilities, making emerging cross-chain protocols prime targets for sophisticated exploiters seeking liquidity drainage.
Protocol leaders frequently utilize time-bound recovery windows and white-hat bounty arrangements to negotiate capital recovery without resorting to protracted international legal disputes. If the attacker fails to remit the funds within the specified timeframe, the protocol team signaled its intent to share gathered identification data directly with federal cybercrime authorities.
Decentralized finance analysts are monitoring on-chain transaction flows across multiple networks to track whether the attacker attempts to obscure funds through privacy protocols or decentralized mixers. The outcome of the negotiation will test the efficacy of public identification disclosures in resolving major decentralized liquidity breaches.
Key takeaways
- NEAR Intents GM issued a 48-hour deadline to recover $3.8 million drained during a security exploit.
- Security investigators claim to have identified the individual responsible for draining protocol liquidity.
- No stolen funds were returned to the three designated restitution addresses as of early October 2.
