The identified hacker has until the expiration of a 48-hour window to return the $3.8 million stolen from NEAR Intents or face imminent legal consequences. Aurora co-founder Alex Shevchenko publicly confirmed that the protocol’s security team has successfully unmasked the perpetrator's identity. This move is a strategic tactic frequently used in the DeFi space to pressure attackers into returning funds in exchange for a bug bounty and immunity from further prosecution.
The breach targeted NEAR Intents, a protocol designed to facilitate seamless cross-chain transactions within the NEAR ecosystem. The exploit resulted in a loss of approximately $3.8 million, highlighting vulnerabilities in emerging intent-based architectures that are becoming popular in 2026. By publicly identifying the attacker, the Aurora and NEAR teams are leveraging off-chain pressure to recover user funds, bypass long-term litigation, and restore confidence in the ecosystem's security protocols.
This incident underscores the increasing effectiveness of on-chain sleuthing and the decreasing anonymity available to malicious actors. For US-based crypto participants, this case demonstrates a shift toward protocol-led enforcement as a primary response to exploits, potentially involving law enforcement agencies if the 48-hour deadline is ignored. The ability to track the exploiter suggests they may have interacted with KYC-compliant centralized exchanges or failed to adequately mask their digital footprint during the transaction flow.
Investors should closely watch the NEAR and Aurora ecosystems over the next two days to see if the funds are moved to a recovery address. A successful return would be a bullish indicator for NEAR’s governance and security response capabilities. However, if the hacker remains defiant, the market may brace for a protracted legal battle and potential volatility for NEAR-related tokens as the community debates further security hardening measures.