Poly Network Hacker Gradually Returning Stolen Funds

  • It appears as the individual that stole around $600 million in tokens from Poly Network is in fact a white hat hacker.
  • While the hacker is yet to return all the stolen funds, he has started gradually transferring tokens to the three wallet addresses Poly Network provided.
black, grey ,and white hat programmer hackers

Shutterstock

The hacker responsible for Poly Network’s $600 million exploit has expressed his willingness to return the stolen cryptocurrency assets in an embedded Ethereum transaction message on 11 August.

In a follow up message, the hacker stated he had failed to contact Poly Network’s team, and was requesting a multi signature wallet to return the stolen funds to. Poly Network wasted no time in posting three separate wallet address — for Binance Smart Chain, Ethereum, and Polygon — on its Twitter account.

Several hours after the addresses were posted, Poly Network confirmed it had already received more than 1 million ISDC on Polygon, and encouraged the hacker by saying he was “moving things to the right direction”. An hour after that, the hacker also returned around $1.1 million in BTCB on Binance Smart Chain, and later an additional $2.6 million worth of tokens to the Ethereum address.

When Poly Network revealed it had suffered an attack yesterday, it became known the hacker was able to steal around $600 million in tokens from the three blockchains the protocol was operating on. According to blog post from security company SlowMist, the individual took advantage of a bug in Poly Network’s cross-chain smart contracts.

Discussion
Related Coverage
Unibot to Compensate Users Affected by Exploit
  • Popular Telegram bot Unibot, which is used to snipe trades on Uniswap, became a victim of a token approval exploit earlier today, when it was switching to a new router.
  • After confirming the exploit, Unibot assured users that their keys and wallets were safe, and that the project will compensate all affected users.
October 31, 2023, 3:01 PM
unlock

Shutterstock

Balancer Exploited After Giving Warning
  • DeFi protocol Balancer confirmed it was exploited almost a week after disclosing a critical vulnerability affecting several of its boosted pools.
  • The platform did its best to mitigate some of the risks but was unable to pause the affected pools, and an estimated $980,000 in DAI were stolen in an attack.
Zunami Protocol’s Stablecoin Pools Exploited, Suffers $2.1M Loss
  • DeFi yield aggregator Zunami Protocol confirmed that a hacker had attacked its “zStables” pools on Curve Finance using a price manipulation exploit.
  • Security firm PeckShield has estimated that over $2.1 million was lost during the attack, while SlowMist said it had informed Zunami of the vulnerability two months ago.