Near Intents has secured the full return of approximately $3.8 million following an exploit that drained funds from the protocol. According to Decrypt, the team confirmed the recovery after it identified the attacker and issued a 48-hour ultimatum for the return of the stolen assets.

The incident occurred on Thursday, when roughly $3.8 million was removed from the protocol without authorization. The following day, the Near Intents team announced that it had identified the individual behind the exploit and simultaneously delivered a 48-hour deadline for the funds to be returned.

The attacker complied with the ultimatum, and the protocol subsequently confirmed that the entire amount had been recovered. The resolution came just one day after the team publicly stated it knew the identity of the perpetrator, creating a notably brief turnaround between the exploit and full restitution.

This outcome highlights a growing trend in the cryptocurrency sector where project teams leverage on-chain analysis and direct communication to pressure exploiters into voluntary returns. Rather than pursuing prolonged investigations or legal proceedings, some protocols have found success by establishing clear deadlines backed by credible claims of identification.

While the specific vulnerability that enabled the Thursday exploit and the precise forensic methods used to identify the attacker were not detailed in the initial report from Decrypt, the confirmed result is the complete recovery of the drained funds within the imposed 48-hour window.

For users and stakeholders, the rapid resolution mitigates the kind of prolonged uncertainty that often follows major security breaches in decentralized finance. Near Intents avoided the cascading effects commonly associated with multimillion-dollar exploits, including extended fund freezes, emergency protocol pauses, or lasting damage to user confidence.

The case adds to a limited but notable record of blockchain projects that have managed to reclaim stolen assets through direct engagement with threat actors after identifying them. As security incidents continue to challenge the crypto ecosystem, the Near Intents recovery demonstrates that swift identification and firm deadlines can occasionally convert a theft into a full return of capital without further escalation.