NEAR Intents Recovers $3.8M After Ultimatum to Exploiter
In a rare win for decentralized finance, NEAR Intents has confirmed the full recovery of approximately $3.8 million in assets stolen during a recent exploit. The recovery followed an unusual public ultimatum issued directly to the attacker, who ultimately returned the funds rather than face the consequences of a coordinated response. The episode stands out not only for the successful clawback but for the strategy that made it possible.
The exploit itself was a reminder of the persistent risks in cross-chain intent-based protocols, where user orders are matched and executed by solvers. Attackers had found a vulnerability in the settlement layer, siphoning a substantial pool of user funds before the team could intervene. Rather than quietly pursuing legal channels or accepting the loss, the NEAR Intents team went public with a stark choice: return the assets within a set window or face an escalated response, including potential law enforcement involvement and permanent blacklisting of the attacker's addresses.
Why the ultimatum worked
The success of this approach hinges on the economics of on-chain crime. In many exploits, stolen funds are difficult to launder without leaving a trace, and the reputational and legal costs of holding tainted assets can outweigh their value. By signaling a willingness to pursue every avenue, NEAR Intents effectively raised the cost of keeping the funds higher than the cost of returning them. The attacker's compliance suggests that rational calculation, not remorse, drove the decision.
Still, the recovery should not be mistaken for a systemic fix. Ultimatums are a reactive tool, and their effectiveness depends on the attacker's anonymity being imperfect and the assets being traceable. The broader lesson for the ecosystem is that robust auditing, faster detection, and built-in pause mechanisms remain the first line of defense. A successful clawback is better than a loss, but it is no substitute for prevention.
For users, the episode offers cautious optimism. It demonstrates that teams can act decisively and that stolen funds are not always gone forever. But it also underscores how fragile trust remains in a sector where a single vulnerability can threaten user capital. As intent-based architectures grow, the industry must treat recovery as a contingency, not a strategy.