Explainer-How hackers stole $600 million in crypto tokens from Poly Network

Explainer-How hackers stole $600 million in crypto tokens from Poly Network

By Gertrude Chavez-Dreyfuss and Michelle Price

WASHINGTON (Reuters) -Hackers pulled off the biggest ever cryptocurrency heist on Tuesday, stealing more than $600 million in digital coins from token-swapping platform Poly Network, only to return $342 million worth of tokens less than 48 hours later, the company said.

Our top trading bots

Here is what we know so far about the heist.

WHAT IS POLY NETWORK?

A lesser-known name in the world of crypto, Poly Network is a decentralized finance (DeFi) platform that facilitates peer-to-peer transactions with a focus on allowing users to transfer or swap tokens across different blockchains.

For example, a customer could use Poly Network to transfer tokens such as bitcoin from the Ethereum blockchain to the Binance Smart Chain.

Poly Network was founded by Chinese entrepreneur Da Hongfei, who is currently chief executive of Neo, a blockchain platform.

According to Neo's website, Poly Network was launched in August last year as a collaboration between Neo, crypto trading platform Switcheo and blockchain company Ontology.

HOW DID HACKERS STEAL THE TOKENS?

Poly Network operates on the Binance Smart Chain, Ethereum and Polygon blockchains. Tokens are swapped between the blockchains using a smart contract which contains instructions on when to release the assets to the counterparties.

One of the smart contracts that Poly Network uses to transfer tokens between blockchains maintains large amounts of liquidity to allow users to efficiently swap tokens, according to crypto intelligence firm CipherTrace.

Poly Network tweeted on Tuesday that a preliminary investigation found the hackers exploited a vulnerability in this smart contract.

According to an analysis of the transactions tweeted by Kelvin Fichter, an Ethereum programmer, the hackers appeared to override the contract instructions for each of the three blockchains and diverted the funds to three wallet addresses, digital locations for storing tokens. These were later traced and published by Poly Network.

The attackers stole funds in more than 12 different cryptocurrencies, including ether and a type of bitcoin, according to blockchain forensics company Chainalysis.

A person claiming to have perpetrated the hack said they had spotted a "bug," without specifying, and that they wanted to "expose the vulnerability" before others could exploit it, according to digital messages posted on the Ethereum network published by Chainalysis. Reuters could not verify the authenticity of the messages.

WHERE DID THE MONEY GO?

Coindesk reported on Tuesday that the hackers had initially tried to transfer some of the assets from one of the three wallets into liquidity pool Curve.fi, but that transfer was rejected. About $100 million was moved out of another of the wallets and deposited into liquidity pool Ellipsis Finance, Coindesk also reported.

Curve.fi. and Ellipsis Finance could not immediately be reached for comment.

But early Wednesday the hackers started transferring assets back to Poly Network and by Thursday morning had returned $342 million worth of tokens, with $268 million stolen from the Ethereum chain outstanding, Poly Network said. Around 10 a.m. ET (1400 GMT) on Thursday, Poly Network said it was still communicating with the hackers, who were gradually transferring back the remaining assets.

WHO IS THE HACKER?

The hacker or hackers have not yet been identified.

Cryptocurrency security firm SlowMist said on its website that it has identified the attacker's mailbox, internet protocol address, and device fingerprints, but the company has not yet named any individuals. SlowMist said the heist was "likely to be a long-planned, organized and prepared attack."

Despite the purported hacker posing as a so-called "white hat", an ethical hacker who had "always" planned to give the money back, according to the messages published by Chainalysis, some crypto experts are skeptical.

Gurvais Grigg, chief technology officer at Chainalysis and former FBI veteran, said it was unlikely that white hat hackers would steal such a large sum. He said on Wednesday that they had probably returned some of the funds because it had proved too difficult to convert them into cash.

"It's hard to know the motivation ... Let's see the if they return the whole amount," he added.

Read on relating to Reuters
Green ‘light:’ The EU’s approach to crypto balances eco-values with regulatory relevance
Last week, Bitcoin (BTC) dodged a regulatory bullet in the European Union when proposed cryptocurrency legislation was altered to not include a ban on proof-of-work-...
REN price gains 65% after Catalog launch brings a cross-chain DEX to its blockchain
Decentralized finance projects like Ren pumped in 2021, only to finish the year right back where they started as high fees on Ethereum (ETH) led to decreased...
API3 price gains 55% after new partnerships and exchange listings attract investors
In the emerging Web3 world, data is the most valuable commodity, and oracle solutions provide a valuable role in facilitating the accurate and secure transmission...
Decentralized and traditional finance tried to destroy each other but failed
The year 2022 is here, and banks and the traditional banking system remain alive despite decades of threatening predictions made by crypto enthusiasts....
Nifty News: AMC investors get tokens, Naomi Osaka NFTs, Guy Oseary to represent World of Women
AMC shareholders gifted free NFTThe AMC movie theater chain dropped NFTs to all AMC shareholders on Tuesday.As part of the reward, AMC CEO Adam Aron tweeted...
OpenSea acquires Dharma Labs and a new CTO
OpenSea announced Tuesday the acquisition of Dharma Labs, a cryptocurrency lending platform and digital wallet, for an undisclosed amount. According to...
Solana price eyes $300 as Grayscale launches SOL-backed trust
Solana (SOL) held onto its intraday gains on Nov. 30 as Grayscale Investments, the largest cryptocurrency fund in the world, announced that it would add...
Bitcoin does not make a great deal of sense, according to billionaire Lee Cooperman
By his own admission, Lee Cooperman still does not understand Bitcoin (BTC), despite its being up more than 300% since early December 2017.Speaking to CNBC...
BlockFi board of directors replaces 'Crypto Dad' after four months
Former Commodity Futures Trading Commission chair Christopher Giancarlo, also known as “Crypto Dad,” will be leaving crypto lending firm BlockFi’s board...
The future of art? World-famous artists delve into NFTs
For millennia, the world of art has remained unchanged for the most part. The tradition has always revolved around artists selling their work to museums,...
South Korean Shinhan Bank joins Klaytn’s blockchain governance council
Shinhan Bank, one of the largest banking institutions in South Korea, has entered into a partnership with Klaytn, a global blockchain platform developed...
Grayscale adds Cardano to Digital Large Cap Fund after rebalancing
In a recent development, Grayscale Investments announced an adjustment to its Grayscale Digital Large Cap Fund (OTCQX: GDLC) to include Cardano (ADA) as...
Ethereum Soars 30% As Investors Gain Confidence
Investing.com - Ethereum was trading at $2,906.69 by 20:43 (00:43 GMT) on the Investing.com Index on Friday, up 30.32% on the day. It was the largest one-day...
Facebook-backed Diem Association reportedly to launch stablecoin pilot in 2021
Facebook-backed digital currency project Diem could yet launch its first stablecoin in 2021 as a small-scale pilot, according to an anonymous source. Cited...
1 in 7 Chinese Piled in Cryptos, Only 2% Not Familiar With BTC
Chinese are not only aware what cryptos are but they also gladly pile funds into them. The survey results are showing that 1 in 7 Chinese citizens have...