NEAR Intents has shifted its $3.8 million security breach into a new phase, moving from technical containment to direct attribution and recovery pressure. The protocol now says it has identified the person behind the exploit, publicly addressing the attacker and giving them 48 hours to return the stolen assets. This ultimatum is backed by the publication of return addresses on Bitcoin, BNB Chain, and Solana, a practical move since earlier forensics traced the funds through KuCoin and across multiple networks.
The context goes back to a bug in NEAR Intents’ Omni deposit-and-withdrawal link with its smart contract, which allowed the exploit to play out last week. That led to losses totaling $3.8 million, forced a halt to deposits and withdrawals across 11 networks, and triggered a first phase of response focused on operational patching.
The question now shifts from what broke to whether identification and a public deadline can create real leverage to recover the money. NEAR Intents also says all affected users will be compensated fully, whether or not the funds are returned.