NEAR Intents recovered all $3.8 million stolen in an exploit after identifying the attacker and issuing a 48-hour ultimatum to return the funds.

The exploiter complied with the deadline and returned the full amount. NEAR Intents, a protocol operating on the NEAR blockchain, disclosed the breach and recovery without providing additional technical details about how the funds were taken or the specific mechanics of the exploit.

The rapid recovery represents an unusual outcome in cryptocurrency theft cases. Most major hacks result in partial or no recovery of stolen assets. The identification of the exploiter and the issuance of the ultimatum proved effective in this instance, with the attacker choosing to return the money rather than face ongoing pursuit or additional consequences.

NEAR Intents did not publicly name the exploiter or reveal whether law enforcement was involved in the identification process. The protocol also did not disclose whether the return of funds included any negotiated terms or agreements between NEAR Intents and the attacker.

The incident highlights both the vulnerabilities present in decentralized protocols and the potential for recovery when attackers can be identified. NEAR Intents' swift action and the exploiter's decision to comply with the ultimatum prevented what could have resulted in a significant permanent loss of user funds.