🚨 Time is Running Out: Reserve Your Spot in the Lucky Draw & Claim Rewards! START NOW

Poly Network Loses at Least $5M in Crypto Due to Compromised Private Keys

Poly Network Loses at Least $5M in Crypto Due to Compromised Private Keys

After almost two years, Poly Network experiences déjà vu as hackers strike again.

Poly Network, a cross-chain bridge platform, became the latest victim of the Decentralized Finance (DeFi) exploit. During the attack, malicious actors fabricated billions of tokens for profit.

The incident, which transpired on July 2nd, saw the hackers manipulate a fundamental function of the smart contract, allowing them to issue non-existent tokens on the network.

What is Ripple? Beginner-Friendly XRP Explainer (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe - We publish new crypto explainer videos every week!

By utilizing the smart contract loophole, hackers transferred tokens from Poly Network's Ethereum pool to their addresses on several other chains

The technique applied was as straightforward as it was devious. It involved creating a false parameter loaded with a counterfeit validator signature and block header.

As a result, the hackers bypassed the usual verification protocols, thereby initiating the minting process for these illicit tokens. Moreover, they replicated this process across several chains, amassing a substantial token collection.

Among the affected networks were prominent blockchains such as Ethereum, BNB Chain, Polygon, Avalanche, Heco, OKx, and Metis, among others.

Analytics from Peckshield suggests the attacker siphoned off at least $5 million in crypto assets. Despite the ambiguity surrounding the precise stolen amount, the attackers' wallets held an estimated $42 billion in tokens at one point, as noted by DeFi security analyst @0xArhat.

However, the successful conversion and theft of these tokens were inhibited by one primary obstacle - liquidity. A liquidity shortage made it challenging for the attacker to monetize the large stash of fabricated tokens. This shortage was particularly apparent for tokens like Binance Coin (BNB) and Binance USD (BUSD) on the Metis blockchain.

In contrast, liquidity was found for a few other illicitly minted tokens, enabling the attacker to exchange a significant token volume. It is believed that the attacker traded 94 billion Shiba Inu (SHIB) tokens for 360 Ether (ETH), 495 million Cook (COOK) for 16 Ether, and 15 million RioDeFi (RFuel) for 27 Ether.

After the incident, the Poly Network took immediate action to stop the move of stolen funds. They've initiated communications with centralized exchanges and law enforcement agencies. In addition, they've advised the stakeholders of affected projects and token holders to unlock their LP tokens and withdraw liquidity

Security provider Dedaub has subsequently named this exploit the "34 billion Poly Network hack." The company was critical of the protocol's simplistic "3 of 4" multi-signature arrangement and delayed response, which likely contributed to the breach. Dedaub emphasized that this was not a sophisticated attack as no logic bugs were exploited.

This isn't the first instance Poly Network fell prey to such an attack. The platform was compromised for $600 million in August 2021, marking a record in the crypto industry.

The attack is a stark reminder of the vulnerabilities within the blockchain ecosystem, particularly concerning cross-chain bridges.

Gile K. , Market Sentiment Analyst
Gile is a Market Sentiment Analyst who understands what public events may form what emotions. Her experience researching Web3 news and public market messages – including cryptocurrency news reports, PRs, and social network streams – is critical to her role in helping lead the Crypto News Editorial Team.
As an intelligent professional in public relations, together with the team, she aims to determine real VS fake news patterns, and bring her findings to anyone searching for unbiased news and events happening in the FinTech markets. Her expertise is uncovering the latest trustworthy & informative Web3 announcements to the masses.
When she's not researching the trustworthiness of mainstream stories, she spends time enjoying her terrace view and taking meticulous care of her outdoor environment.

Loading...
binance
×
Verified

$600 WELCOME BONUS

Earn Huge Exclusive Binance Learners Rewards
5.0 Rating