0% found this document useful (0 votes)
53 views7 pages

Poly Network Crypto Theft

Poly Network is a decentralized finance platform that facilitates cryptocurrency lending, borrowing, exchanges, and trades. A hacker exploited a vulnerability in Poly Network's system to steal approximately $600 million worth of cryptocurrency. Over the following days, the hacker, dubbed "Mr. White Hat", returned over $260 million of assets as it was deemed a "white hat" hack to expose vulnerabilities. Poly Network thanked the hacker and offered a position as Chief Security Advisor. The hack highlighted the need for companies to implement strong security practices such as bug bounty programs and continuous patching to prevent exploitation of software vulnerabilities.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
53 views7 pages

Poly Network Crypto Theft

Poly Network is a decentralized finance platform that facilitates cryptocurrency lending, borrowing, exchanges, and trades. A hacker exploited a vulnerability in Poly Network's system to steal approximately $600 million worth of cryptocurrency. Over the following days, the hacker, dubbed "Mr. White Hat", returned over $260 million of assets as it was deemed a "white hat" hack to expose vulnerabilities. Poly Network thanked the hacker and offered a position as Chief Security Advisor. The hack highlighted the need for companies to implement strong security practices such as bug bounty programs and continuous patching to prevent exploitation of software vulnerabilities.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 7

Poly Network Crypto Theft

A Case Study - Avinash K


● The hacker exploited a
vulnerability, which is the
_executeCrossChainTx function
Attack Vector ●
between contract calls,
This Attack effectively allowed
The Attack Vector which was the intruder to declare
themselves as the owner of any
exploited in this “Poly Hack” was
funds processed through the
Software vulnerabilities
platform.
Poly Network ● Poly Network was founded by
Chinese entrepreneur Da
Poly Network is built to implement
Hongfei, Poly Network has already
interoperability between multiple
integrated Bitcoin, Ethereum, Neo
chains in order to build the next
& various others.
generation internet infrastructure
● A decentralised finance (DeFi)
platform that facilitates users that
lend, borrow, exchange or trade
cryptocurrencies – and earn or pay
interest while doing so.
● Poly seems to have had a bug that was not identified until now, an
instruction that was used only internally and should not have been
possible to access by those outside the company.
● Poly has this contract called the "EthCrossChainManager". It's
basically a privileged contract that has the right to trigger
messages from another chain.
● But Poly forgot to prevent users from calling a very important
Vulnerabilities ●
target, the EthCrossChainData contract.
It keeps track of the list of public keys that authenticate data
coming from the other chain. If you can modify that list, you don't
even need to hack private keys. You just set the public keys to
match your own private keys.
● The EthCrossChainManager owned the EthCrossChainData
contract. The EthCrossChainManager shouldn't have owned the
EthCrossChainData contract. Exploiting the Vulnerability through
EthCrossChainManager and few function calls transferred
ownership of all transactions on that platform to the hacker.
10/08/2021 (14:30 +UTC):- Poly Network was attacked on Tuesday (10/08/2021), with
the alleged hacker draining roughly $600 million in crypto.

11/08/2021 :- Poly Network poste addresses for Etherium, BSC and Polygon to
return the assets. Tether Freezed assets of worth $33M.
11/08/2021 (04:18:39 PM +UTC) :- $260 million of assets had been returned -
Ethereum: $3.3M, BSC: $256M, Polygon: $1M. Hence declared as a White Hack.

12/08/2021 :- Poly tweeted “As our communication with Mr. White Hat is going on, the
remaining user assets on Ethereum are gradually transferred to the multisig wallet requested
by Mr. White Hat.”
TIMELINE
13/08/2021 :- Approximately $238 million is currently being transferred to the 3/4
multi-signature wallet, while we still wait for Mr. White Hat to provide his final key
authorization. Approximately $33 million USDT is frozen, and #PolyNetwork is actively
communicating with Tether to determine the next course of action.

14/08/2021 :- New Patch was released after the Vulnerability was fixed and users
who lost the assets had getting their assets through a asset recovery team

15/08/2021 :- The Poly Network thanked and offered position of Chief Security
Advisor with $500,000 and left the decision to the Mr White Hat (the attacker). The
identity has been not found till date. Few Q&A were released later.
COST PREVENTION
● Approx $600 M was stolen from ● Employing Strong Security
the platform. measures to find Vulnerabilities.
● Outsourcing to Bug Bounty
● It was sufficient to cause a programs to increase the chance
economic crisis for of discovering Software
cryptocurrency. vulnerabilities.
● Reputation damage and possible ● Continuously patching to
eradicate known vulnerabilities if
insider threat.
existing.
● This hack was a warning and a ● Periodically conducting
show of how devastating it could vulnerability assessments and
have been. pentesting.
Thank you ^,^

You might also like