Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Web3 & Enterprise·

Jun 02, 2023

Wemade Introduces New DeFi Services on WEMIX3.0 Mainnet

Wemade Introduces New DeFi Services on WEMIX3.0 MainnetKorean blockchain game maker Wemade announced today that it will deploy decentralized finance (DeFi) services Kurrency and Konverter on the WEMIX3.0 Mainnet.Photo by Shubham Dhage on UnsplashTwo DeFi servicesKurrency utilizes a collateralized debt position (CDP) model, providing users with the capability to lock up a certain amount of virtual assets in order to mint, deposit, and swap the WEMIX Crypto Dollar (WCD). WCD, a cryptocurrency designed to minimize price fluctuations, complements the WEMIX Dollar, which is fully backed by the stablecoin USDC.Konverter is a new decentralized exchange (DEX) that combines the strengths of established DEXs. On June 9, Konverter will demonstrate functions that contribute to the efficiency of Kurrency. These functions involve seamless swaps between WCD and a variety of stablecoins. The full-fledged version of Konverter, set to launch in the second half of this year, will offer a broader array of swap services along with a “governance function” that doesn’t require forced lock-ups.Mainnet firstThe initial launch of Kurrency and Konverter will take place on the WEMIX3.0 Mainnet. Their goal is to magnify the ecosystem’s scope by boosting the utility of assets within the network and harnessing the synergies derived from decentralized apps (dApps).Multichain expansionLater, the two services on the WEMIX3.0 Mainnet will become more refined and reliable, paving the way for a multichain expansion. A successful implementation will improve interconnectivity between various blockchains, ultimately bolstering the value of the WEMIX ecosystem.Engaging usersStarting today, Kurrency is initiating various quests to encourage user participation. Users gaining experience from these quests will become eligible to join community events, promoting a more vibrant and engaged user base.

news
Web3 & Enterprise·

Sep 25, 2023

Crypto Titans Clash on Elon Musk’s X

Crypto Titans Clash on Elon Musk’s XA subtle panel discussion photo posted by Andrei Grachev of Singapore’s DWF Labs turned into a war of words among crypto trading titans on Elon Musk’s X (formerly Twitter).Photo by Marek Piwnicki on UnsplashDWF vs GSRGrachev, who is a Managing Partner at the market maker and Web3 investment firm, thanked his fellow panelists in the post. However, the tone quickly soured as Cristian Gil, Co-Founder of rival market-making giant GSR, took offense to Grachev’s presence on the panel and voiced his disapproval on the platform.Gil didn’t mince his words, stating: “[Andrei Grachev] had absolutely no business to be on that panel. It’s insulting to [GSR] , [OKX] and [Wintermute] to be in the same room as [DWF Labs].”DWF vs WintermuteHis remarks received a “Like” from Evgeny Gaevoy, the CEO of market maker Wintermute. In response, Grachev defended his presence, asserting that DWF was superior in technology, trading, and business development compared to its rivals, going so far as to suggest to Gil: “Yeah, if I were you — I would be also crying all the time.”The exchange continued with Grachev claiming that DWF was capturing market share from Wintermute, and Gaevoy responded with a nonchalant “lol,” challenging Grachev to invest more if he believed DWF posed a threat.DWF Labs’ rapid growthWhile the exchange consisted of mere words, it shed light on DWF Labs’ sudden rise to prominence earlier over recent months. The company has featured prominently in an array of investments in Web3 startups and blockchain networks over the course of 2023. Prominent among them have been investments in EOS, the Algorand ecosystem, and the TRON ecosystem.Recently appearing on the BlockBeats podcast, Grachev defended the company, outlining that it was not involved in market manipulation in response to recent assertions to the contrary.“We do not engage in any manipulative behavior,” Grachev stated. “Of course, we have the futures market, which is a tool for hedging positions and trading clubs. We are completely different from directional traders,” he added.Gaevoy added some humor to the mix by sharing a meme, raising questions about the maturity level of these prominent figures in the crypto industry. The spat provoked a broad array of commentary from the crypto community.Crypto immaturityThe very public clash raises concerns about how traditional Wall Street firms, currently making bold moves into the crypto space, might perceive such behavior. Notably, firms like BlackRock have been involved in Bitcoin ETF applications, signaling a growing interest in cryptocurrency among mainstream financial institutions. In response to Gaevoy and Grachev, one commentator wrote: “The institutions are never coming back.”While it would appear that there’s no love lost between DWF, GSR, and Wintermute, it also seems evident that both market makers can agree on Singapore as being an appropriate location from where to operate a crypto business. While Wintermute is London-based, it revealed recently that it was expanding its operations in Singapore. Like Wintermute, GSR is primarily based in London although it too maintains a presence in Singapore to service Asia-centric business.

news
Policy & Regulation·

Dec 11, 2023

South Korean FSC updates definition of virtual assets and VASP regulations for Virtual Asset User…

South Korean FSC updates definition of virtual assets and VASP regulations for Virtual Asset User Protection ActThe South Korean Financial Services Commission (FSC) on Monday (local time) published a new enforcement decree and supervisory regulations for the Virtual Asset User Protection Act, under which non-fungible tokens (NFTs) and deposit tokens are excluded from the definition of virtual assets. The act serves to protect customer assets, prevent unfair trading practices, and enforce penalties.“The enforcement decree and supervisory regulations provide detailed standards and methods to safeguard users’ assets and establish stability in the market,” the FSC said.Photo by Tingey Injury Law Firm on UnsplashDefining virtual assetsThe agency explained that it decided to exclude NFTs because they are mainly bought and sold for collection purposes, posing low risks to holders and the financial system. However, NFTs that can be used as a means of payment for purchasing certain goods and services are considered virtual assets. On the other hand, deposit tokens — which will be managed by the Bank of Korea’s central bank digital currency network — are regarded as a legitimate form of monetary deposit and are subject to relevant regulations instead of the User Protection Act. Other “electronic certificates of economic value,” such as mobile vouchers and electronic bonds, are also excluded from the definition of virtual assets.Enhancing security and transparencyFollowing the clarified definition of virtual assets, the updated regulations underline conduct measures that virtual asset service providers (VASPs) must comply with. For example, VASPs must calculate the total value of their customers’ crypto assets every month and store at least 80% in a cold wallet to prevent infringements like hacks — a boost from the current 70 percent. Cold wallets are deemed more secure than hot wallets because they keep crypto keys offline instead of staying connected to the internet.VASPs are also not allowed to arbitrarily block deposits and withdrawals of user assets without prior notice and a justifiable reason like internal system failure or hacks as well as requests from courts, investigative bodies, the National Tax Service and financial authorities. User deposits must be stored in banks, which can invest them only in safe assets such as government bonds.The act is set to take effect on July 19 next year after a legislative review scheduled for next month.

news
Loading