NEAR Intents Lost $3.8M to a Hacker, Then Told Him: 'We Have Identified You, Sir'

The hacker thought they got away clean. They didn't.

NEAR Intents was exploited for $3.8 million, and within hours, the protocol's general manager Alex Shevchenko went public with four words that should make any anonymous attacker sweat: "We have identified you, sir."

That's not a bluff most teams can afford to make. If Shevchenko is wrong, he looks desperate. If he's right, the hacker is now sitting on stolen funds with a ticking clock and a paper trail.

The 48-Hour Countdown

NEAR Intents issued a formal ultimatum on Friday: return the funds within 48 hours or face consequences. The protocol has not publicly named the attacker, but the confidence in Shevchenko's statement suggests the team has either traced wallet activity, identified KYC data through a CEX touchpoint, or received off-chain intelligence that points to a real identity.

This playbook isn't new in crypto. Protocols like Euler Finance and Poly Network have used the same pressure tactic, and it has actually worked. Euler recovered nearly all of its $197 million in stolen funds after direct on-chain negotiations. Poly Network's attacker returned everything.

The difference here is the tone. "We have identified you, sir" is unusually direct and personal. This isn't a generic bounty offer. It reads like a warning from someone who already has a name.

What Actually Got Exploited

Details on the specific attack vector are still limited, which is itself a red flag for anyone currently using NEAR-based DeFi products. Until a full post-mortem drops, users with funds in NEAR Intents or adjacent protocols should treat this as an active risk environment. Unexplained exploits have a habit of having follow-on attacks when the vulnerability isn't patched and disclosed quickly.

NEAR's broader ecosystem has been pushing hard on interoperability and intent-based architecture, positioning itself as a serious Layer 1 contender. A $3.8 million exploit does not kill that narrative, but a botched response will. The next 48 hours are as much a test of the team's crisis management as they are a countdown for the hacker.

What to Watch

If the funds are returned, this becomes a story about DeFi growing up and using identity pressure as a legitimate recovery tool. If they aren't, NEAR Intents faces a harder conversation about security architecture and user trust.

Watch for the post-mortem. Watch for any on-chain movement of the stolen funds. And if you are currently deployed in NEAR Intents, the smart move right now is to understand your exposure before the 48-hour window closes, one way or another.