BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Analyzing the biggest theft in the DeFi field: How hackers stole $600 million from Poly Network

区块链骑士
特邀专栏作者
This article is about 1105 words, reading the full article takes about 2 minutes
The DeFi field jointly resists hacker attacks, and any illegal behavior will be punished.
AI Summary
Expand
The DeFi field jointly resists hacker attacks, and any illegal behavior will be punished.

Around 1:00 p.m. UTC, Poly Network's official Twitter account stated that the Poly Network platform had been attacked, which was one of the worst attacks it has suffered since its inception.

Hackers managed to move more than $600 million in assets to addresses on Polygon, Ethereum, and Binance Smart Chain (BSC).

According to their mainnet description, Poly Network is a protocol for cross-chain operations with decentralized exchanges (DEXs), which can be used for lending and providing stablecoin-based services.The platform has integrated Bitcoin, Ethereum BSC, Ontology, Elrond, Ziliqa and more

Poly Network calls on miners, crypto exchanges and other entities to blacklist these stolen funds, including WBTC, WETH, RenBTC, DAI, UNI, SHIB, FEI, USDC, USDT, etc.

The hack took place on an interoperable blockchain-agnostic transaction pool established with O3 Labs, also known as O3.

"After an initial investigation, we have identified the cause of the vulnerability," Poly Network said.Hackers exploited gaps between smart contract calls, not by a single administrator。”

While the hackers were successful in moving the funds, some entities, such as Tether, responded to Poly Network’s call and blacklisted some of the assets.

Attackers Tried to "Launder" Swag Using Curve and Other Defi Protocols, ButPart of this “wash” failed due to transactions using blacklisted USDT

A community member named "Hanashiro.eth" told the hackers not to use USDT through a transaction message, and received a reward of 13.37 ETH worth $42,000 from the address linked to "PolyNetwork Exploiter", as shown below.

Many others tried to help the hacker get rewarded and started referring to the hacker as "Etherhood".

The attackers managed to cash out most of the funds other than those concentrated in stablecoins, and Poly Network posted the following message in an attempt to establish a communication channel with the hackers and retrieve some of the DeFi tokens.

"The funds you have obtained through hacking are the largest in history. Law enforcement in any country would consider this a major economic crime and you will be hunted down. It would be highly unwise for you to do any further transactions. The money you stole was stolen from tens of thousands of community members."

Shortly after, security firm SlowMist released a report saying they had identified the attacker's mailbox, IP, and device fingerprints.The company, apparently with the help of partners and exchange platforms, used on-chain and off-chain data to track hackers

Other reports have pointed out that DeFi funds are tied to central entities, so it is possible to track down the attackers.

The original text comes from bitcoinist, compiled and organized by Blockchain Knight, the English copyright belongs to the original author, please contact the compiler for Chinese reprint.

The original text comes from bitcoinist, compiled and organized by Blockchain Knight, the English copyright belongs to the original author, please contact the compiler for Chinese reprint.

DeFi
Welcome to Join Odaily Official Community