NEAR Intents Executive Issues 48-Hour Deadline to Hacker Following $3.8 Million Exploit

Ultimatum Issued Following Multi-Million Dollar Drain

In a dramatic turn of events following a major decentralized finance security breach, the general manager of NEAR Intents, known publicly as Shevchenko, has issued a strict 48-hour ultimatum to the perpetrator behind a recent exploit. The security incident resulted in an estimated loss of $3.8 million from the protocol, dealing a significant blow to the project’s reserves and user confidence.

According to public announcements made by protocol leadership, security researchers and on-chain intelligence teams have successfully identified the individual or group responsible for the breach. As part of the ultimatum, Shevchenko published three designated wallet addresses intended for the full restitution of the stolen funds. The protocol leadership signaled that returning the assets within the specified window could open a path toward resolving the incident without immediate escalation to global law enforcement agencies.

Despite the explicit warning and public identification, on-chain tracking data indicated that as of early October 2, none of the designated return wallets had received any transferred assets. The lack of movement suggests the attacker has not yet accepted the terms of the grace period, leaving the future of the funds and potential criminal proceedings in suspense.

Anatomy of the Security Breach and On-Chain Forensics

While full technical post-mortems remain underway, preliminary findings suggest that the attacker exploited vulnerabilities within the transaction routing or smart contract execution layer of NEAR Intents. The total initial damage was pegged at approximately $3.8 million, comprised of various high-liquidity crypto assets that were rapidly drained and moved across secondary addresses.

The rapid identification of the culprit highlights the increasing sophistication of modern blockchain forensic tools. Security teams routinely track IP addresses, cross-chain bridge activity, centralized exchange interactions, and privacy mixer usage to deanonymize exploiters. Key methods utilized by security firms during such investigations include:

  • Tracing gas fee funding sources back to centralized exchanges requiring Know Your Customer (KYC) verification.
  • Analyzing off-chain metadata associated with transaction relayers and RPC nodes.
  • Monitoring real-time liquidity pools for slippage and exit routes across EVM and non-EVM chains.
  • Collaborating with global analytics platforms to tag and freeze attacker-linked wallets across major central exchanges.

By leveraging these forensic vectors, project leads often gather sufficient identity intelligence to threaten legal consequences, asset seizures, and international police involvement if perpetrators refuse to communicate.

Understanding NEAR Intents and the Intent-Centric Paradigm

NEAR Intents operates within the broader NEAR Protocol ecosystem, designed to streamline cross-chain transactions and complex decentralized finance operations. Unlike traditional smart contract interaction, where users must manually specify every step of a transaction sequence, intent-based architectures allow users to simply express a desired outcome, or intent.

Off-chain actors known as solvers or searchers then compete to fulfill these user intents in the most efficient manner possible. While this paradigm drastically improves user experience by abstracting away gas fees, network switching, and complex routing, it introduces new structural vectors of risk. Key considerations surrounding intent architecture include:

  • Solver Reliability: Ensuring off-chain execution agents do not manipulate trade parameters or extract excessive MEV (Maximal Extractable Value).
  • Smart Contract Complexity: Escrow and settlement contracts that manage funds during the intent execution phase require robust access controls to prevent unauthorized withdrawals.
  • Cross-Chain Messaging: Relaying messages between distinct blockchain environments can expose systems to bridge-like vulnerabilities if cryptographic proofs are improperly validated.

The recent security incident underscores the delicate balance between pushing user interface innovation forward and maintaining rigorous security standards across complex off-chain and on-chain interactions.

The Growing Trend of On-Chain Negotiations and White-Hat Bounties

The strategy employed by Shevchenko reflects a growing standard across the Web3 ecosystem when dealing with protocol exploits. Rather than relying solely on traditional legal avenues, which can be slow and geographically complex, project founders often initiate direct on-chain communications via transaction input data or public social channels.

In many past instances, protocols have offered exploiters a official white-hat bounty—typically ranging between 10% and 20% of the drained amount—in exchange for returning the remaining funds. When hackers comply, the protocol generally agrees to cease further investigation, refrain from filing police reports, and view the incident as a security testing service.

However, the success rate of such negotiations varies widely. While several high-profile protocols have successfully recovered tens of millions of dollars using this approach, other attackers choose to ignore deadlines, attempting instead to obfuscate funds using decentralized mixers, privacy-centric blockchains, or peer-to-peer OTC desks. As the 48-hour clock ticks down for NEAR Intents, the community remains on high alert to see whether the attacker will accept the offered off-ramp or risk escalating legal action.

Ecosystem Impact and Security Posture Moving Forward

The exploit has prompted heightened vigilance throughout the NEAR Protocol ecosystem. Decentralized finance applications rely heavily on cross-protocol trust and shared liquidity; consequently, security breaches in core infrastructure components can ripple across lending protocols, decentralized exchanges, and asset bridges.

In response to the incident, development teams are conducting comprehensive audits of all related smart contract modules and off-chain execution infrastructure. The project is expected to implement additional security safeguards prior to fully restoring operational workflows. Recommended measures being evaluated across the community include:

  • Implementing time-locked emergency pause mechanisms for unusual outflow volumes.
  • Enhancing real-time monitoring tools to flag abnormal solver behavior before transactions are finalized.
  • Expanding formal verification processes for core smart contracts governing user deposits.
  • Establishing dedicated insurance or recovery funds to compensate affected users in the event of capital losses.

Conclusion

The $3.8 million exploit of NEAR Intents highlights both the security vulnerabilities inherent in cutting-edge Web3 protocols and the active countermeasures employed by decentralized finance leaders. By establishing a public 48-hour window and asserting that the attacker’s identity is known, NEAR Intents leadership has drawn a clear line between resolution and legal prosecution. As the deadline approaches, the broader crypto community continues to monitor on-chain wallet addresses to see if the funds will be returned or if this incident will transition into an international law enforcement investigation.

Sharing Is Caring:
Musharaf

Hello friends, my name is Musharaf I am the Writer and Founder of this blog and share all the information related to Mobile Phones, Laptops, Tech News, Gadgets, Reviews, and Technology through this website🔁.


Leave a Comment