Aurora co-founder Alex Shevchenko has publicly declared that his team identified the hacker behind the $3.8 million exploit of cross-chain swap service NEAR Intents, issuing a 48-hour ultimatum for the return of the stolen funds.
Ultimatum Issued With Repayment Wallet Addresses
Following the October 1, 2026 attack on NEAR Intents, Shevchenko published a public warning directing the attacker to engage in responsible disclosure. The ultimatum supplied three specific cryptocurrency addresses across multiple chains for repayment:
- Bitcoin: bc1qjhv3hu8rfteh5e8exfmalvx2z3pzlmjlgnzxey
- BNB Chain / Ethereum: 0xB18a1aEDfde8B70FD67012C9E9c7a088B4d0C0e7
- Solana: AHTfKaeRcaK1sbSG8MFJS2uPxLBChfenigNtvbWEkhKD
Shevchenko noted that the attacker understands responsible disclosure procedures "better than most," emphasizing that the 48-hour deadline is the final opportunity to negotiate a resolution. However, Shevchenko did not publicly disclose the hacker's identity or explain the methodology used to trace the funds. The security incident came directly after NEAR Intents was exploited for $3.8 million, testing investor confidence following the launch of Bitwise's spot NEAR ETF.
Key Takeaways of the Recovery Push
- Alex Shevchenko set a 48-hour deadline for the NEAR Intents hacker to return $3.8 million.
- Designated repayment wallets were published for Bitcoin, BNB Chain, Ethereum, and Solana.
- Shevchenko previously used public identification threats to recover funds after the $18.4 million Rhea Finance exploit.
Precedent Set by the Rhea Finance Exploit
A similar situation unfolded in April 2026, when NEAR-based DeFi platform Rhea Finance suffered an exploit resulting in $18.4 million in losses, according to security firm QuillAudits (which initially estimated damage at $7.6 million). Shevchenko publicly announced at the time that the attacker had been tracked down.
That public negotiation yielded substantial asset recovery. The hacker returned 3.36 million USDC, 1.56 million NEAR, and roughly $4.4 million in Zcash (ZEC). Additionally, Tether froze approximately $3.29 million in USDT tied to the hack, leaving a $400,000 shortfall that the Rhea team committed to cover.
Why It Matters
Two significant exploits on NEAR-linked infrastructure within six months highlight persistent smart contract vulnerabilities across cross-chain protocols. However, the successful restitution in the Rhea Finance case indicates that public attribution threats can serve as a potent tool for capital recovery when technical defenses fail. If the NEAR Intents attacker complies with the ultimatum, public identification strategies could increasingly become standard practice for protocol teams seeking to recover stolen funds across decentralized finance.



