#zcash现货etf首现周度净流出9360万美元
On the surface, this is just a piece of news about “a hacker stole money, and the team got it back.” But what’s really worth watching may not be the $3.8 million itself.

📢 消息第一时间

On Thursday, the cross-chain swap service Near Intents was exploited via a contract vulnerability, and about $3.8 million was transferred out. Team lead Alex Shevchenko didn’t stay silent; he publicly called out: “We have identified you, sir,” essentially naming the person already identified and issuing a 48-hour final warning. The next day, the money was fully returned. The team then announced that it would stop investigating. On-chain, a message was also left that appears to be from the hacker: “We’re sorry, everything will be returned. And we advise others to take the bug bounty path instead.”

What most people see is “another security incident.” But the unusual part is that the stolen funds were actually able to come back in full—and it only took 48 hours.

In recent years, the recovery rate for stolen funds has generally been painfully low. Most often, it requires law enforcement involvement, an exchange freezing assets, or post-incident tracking via on-chain analysis. This time, it relied on something else: not the police, but the reputation deterrence created by “I already know who you are.” In a decentralized world, recovering stolen assets is increasingly like a negotiation—whoever holds identity clues has the bargaining power.

Zoom out a bit further, and this event is tied to another thread. Just two days earlier, Near Intents blocked a $50 million swap. The one who made the move was the same hacker behind Bitget’s roughly $387.5 million theft case—industry consensus has widely pointed to North Korea. The same service, on one side, was being robbed, and on the other, it intercepted the robbery. And next to it, Bitwise’s NEAR spot ETF had only just launched a few days earlier.

So what’s worth looking at is the next link in the chain: when a cross-chain service plays both roles—“victim” and “interceptor”—what it accumulates isn’t just a security reputation, but also the trust of institutional capital that’s willing to entrust it.

If this trend continues, whether stolen money can be recovered in the future may depend more and more on whether the project team can “turn the hacker into a negotiation partner.” What’s truly worth keeping an eye on is the on-chain bargaining-and-haggling mechanism—whether more people will replicate it..

Once the next case of full recovery appears, the market’s pricing of the two words “stolen” may have to be recalculated.