How $613 million in tokens were stolen from Poly Network in cryptocurrency's biggest heist

Published August 12, 2021
Representations of virtual currency stand on a motherboard in this picture illustration. — Reuters
Representations of virtual currency stand on a motherboard in this picture illustration. — Reuters

Hackers pulled off the biggest ever cryptocurrency heist on Tuesday, stealing $613 million in digital coins from token-swapping platform Poly Network, only to return $260m worth of tokens less than 24 hours later, the company said.

Here's what is known so far about the heist:

What is a Poly Network?

A lesser-known name in the world of crypto, Poly Network is a decentralised finance (DeFi) platform that facilitates peer-to-peer transactions with a focus on allowing users to transfer or swap tokens across different blockchains.

For example, a customer could use Poly Network to transfer tokens such as Bitcoin from the Ethereum blockchain to the Binance Smart Chain, perhaps looking to access a specific application.

It was not immediately clear from Poly Network's website where the platform is based or who runs it. According to specialist crypto website Coindesk, Poly Network was launched by the founders of the Chinese blockchain project Neo.

How did hackers steal the tokens?

Poly Network operates on the Binance Smart Chain, Ethereum and Polygon blockchains. Tokens are swapped between the blockchains using a smart contract that contains instructions on when to release the assets to the counterparties.

One of the smart contracts that Poly Network uses to transfer tokens between blockchains maintains large amounts of liquidity to allow users to efficiently swap tokens, according to crypto intelligence firm CipherTrace.

Poly Network tweeted on Tuesday that a preliminary investigation found the hackers exploited a vulnerability in this smart contract.

According to an analysis of the transactions tweeted by Kelvin Fichter, an Ethereum programmer, the hackers appeared to override the contract instructions for each of the three blockchains and diverted the funds to three wallet addresses, digital locations for storing tokens. These were later traced and published by Poly Network.

The attackers stole funds in more than 12 different cryptocurrencies, including Ether and a type of Bitcoin, according to blockchain forensics company Chainalysis.

A person claiming to have perpetrated the hack said they had spotted a "bug", without specifying, and that they wanted to "expose the vulnerability" before others could exploit it, according to digital messages posted on the Ethereum network published by Chainalysis. Reuters could not verify the authenticity of the messages.

Where did the money go?

As of late Wednesday, the hackers had returned $260m of the assets, Poly Network said, but $353m was outstanding. It is unclear where the remaining assets have gone.

Coindesk reported on Tuesday that the hackers had tried to transfer assets including tether tokens from one of the three wallets into liquidity pool Curve.fi, but that transfer was rejected. About $100m has been moved out of another of the wallets and deposited into liquidity pool Ellipsis Finance, Coindesk also reported.

Curve.fi and Ellipsis Finance could not immediately be reached for comment.

Who is the hacker?

The hacker or hackers have not yet been identified.

Cryptocurrency security firm SlowMist said on its website that it has identified the attacker's mailbox, internet protocol address, and device fingerprints, but the company has not yet named any individuals. SlowMist said the heist was "likely to be a long-planned, organised and prepared attack".

Despite the purported hacker posing as a so-called "white hat", an ethical hacker who aimed to identify the vulnerability for Poly Network and had "always" planned to give the money back, according to the messages published by Chainalysis, some crypto experts are sceptical.

Gurvais Grigg, chief technology officer at Chainalysis and former FBI veteran, said it was unlikely that white hat hackers would steal such a large sum. He said they had probably returned some of the funds because it had proved too difficult to convert them into cash.

"It's hard to know the motivation [...] Let's see if they return the whole amount," he added.

Opinion

Editorial

Ties with Tehran
Updated 24 Apr, 2024

Ties with Tehran

Tomorrow, if ties between Washington and Beijing nosedive, and the US asks Pakistan to reconsider CPEC, will we comply?
Working together
24 Apr, 2024

Working together

PAKISTAN’S democracy seems adrift, and no one understands this better than our politicians. The system has gone...
Farmers’ anxiety
24 Apr, 2024

Farmers’ anxiety

WHEAT prices in Punjab have plummeted far below the minimum support price owing to a bumper harvest, reckless...
By-election trends
Updated 23 Apr, 2024

By-election trends

Unless the culture of violence and rigging is rooted out, the credibility of the electoral process in Pakistan will continue to remain under a cloud.
Privatising PIA
23 Apr, 2024

Privatising PIA

FINANCE Minister Muhammad Aurangzeb’s reaffirmation that the process of disinvestment of the loss-making national...
Suffering in captivity
23 Apr, 2024

Suffering in captivity

YET another animal — a lioness — is critically ill at the Karachi Zoo. The feline, emaciated and barely able to...