Near Intents recovered approximately $3.8 million Friday, one day after the protocol identified the exploiter and delivered a 48-hour deadline to return the funds. The attacker drained the full amount Thursday. By Friday afternoon, it was back.
The recovery marks another instance where naming an attacker publicly, or at least claiming to have done so, compressed the timeline between exploit and return. Near Intents didn’t detail what information it held or how identification occurred, but the ultimatum came with enough conviction that the exploiter apparently decided cooperation was the better option.
Thursday Exploit, Friday Return
The $3.8 million drain hit Thursday. Near Intents moved quickly, issuing a public statement that it had identified the individual responsible and setting a 48-hour clock. That gave the exploiter until Saturday to return the funds. He didn’t need the full window.
By Friday, the protocol confirmed the return in full. No additional detail on whether any agreement was struck, white hat bounty, no legal pursuit, clean slate, but the outcome is the same. Funds are back, exploiter is gone, and Near Intents avoided the protracted negotiation or law enforcement process that drags out for months in most cases.
Identification as Leverage
Public identification doesn’t always work. Exploiters tied to jurisdictions with weak enforcement or working through sufficient operational security layers often ignore threats. But when a protocol can credibly claim it knows who you are, the calculus shifts. Returning funds and disappearing becomes less risky than waiting to see if the team follows through with formal complaints, subpoenas, or cooperation with law enforcement.
Near Intents didn’t publish a wallet address, real name, or specifics about the identification process. That silence keeps the leverage. Whether the exploiter was tied to an exchange KYC account, a prior transaction pattern, or metadata scraped from the exploit itself, the message was enough.
This wasn’t a white hat finding a bug and requesting a bounty upfront. The funds were gone Thursday. The exploiter didn’t reach out first, didn’t signal good faith. Near Intents applied pressure, and it worked. Fast.
