Aurora co-founder Alex Shevchenko says his team has identified the NEAR Intents hacker. He gave the attacker 48 hours to return funds from the $3.8 million exploit.

The public ultimatum lists Bitcoin, BNB Chain, Ethereum, and Solana addresses for repayment. However, Shevchenko made a similar claim after another NEAR exploit earlier this year.

Will the NEAR Intents Hacker Take the Exit Offer?

We have identified you, sir. Please return the funds to the following addresses: Bitcoin: bc1qjhv3hu8rfteh5e8exfmalvx2z3pzlmjlgnzxey BNB / Ethereum: 0xB18a1aEDfde8B70FD67012C9E9c7a088B4d0C0e7 Solana: AHTfKaeRcaK1sbSG8MFJS2uPxLBChfenigNtvbWEkhKD You know better than most how… — Alex Shevchenko 🇺🇦 (@AlexAuroraDev) October 2, 2026

Shevchenko posted the warning a day after the NEAR Intents hack, which hit the cross-chain swap service on October 1. Aurora runs an Ethereum-compatible network on top of NEAR Protocol.

NEAR Price Performance (1M). Source: BeInCrypto

In his post, Shevchenko addressed the attacker directly and listed three wallets. One of them covers both BNB Chain and Ethereum, since the two networks share the same address format.

Shevchenko’s post also points the attacker toward responsible disclosure. That practice lets hackers report flaws privately, often in exchange for a bounty.

He added that the attacker knows how that process works “better than most.” According to Shevchenko, the 48-hour deadline is the final chance to take that route.

Notably, Shevchenko did not name the NEAR Intents hacker or explain how his team traced them. He also did not say what happens once the deadline passes.

Why the Rhea Finance Case Matters Here

In April, Rhea Finance, a decentralized finance (DeFi) hub on NEAR, lost $18.4 million in an exploit, according to QuillAudits. Initial estimates of the Rhea Finance exploit put the damage at $7.6 million.

Shevchenko then publicly confirmed that the attacker had been identified, the security firm says.

Later, the attacker returned about 3.36 million USDC, 1.56 million NEAR, and roughly $4.4 million in Zcash (ZEC), among other assets. In addition, Tether froze about $3.29 million in USDT tied to the attack.

Those returns and freezes left a shortfall of about $400,000, which the Rhea team has committed to cover.

Two exploits on NEAR-linked services within six months raise questions about the ecosystem’s security. However, the Rhea case shows that a public warning can precede large returns. If the NEAR Intents hacker also returns the funds, public identification threats could become a standard recovery tool across DeFi.

The post NEAR Intents Hacker Identified: Will $3.8M Return in 48 Hours? appeared first on BeInCrypto.