Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Web3 & Enterprise·

Aug 21, 2023

KT and Iron Mountain Forge Alliance to Propel Blockchain-Powered E-Document Ecosystem

KT and Iron Mountain Forge Alliance to Propel Blockchain-Powered E-Document EcosystemSouth Korean telecommunications giant KT has entered into a strategic partnership with global information management company Iron Mountain to leverage blockchain technology in expanding the certified electronic document ecosystem.Photo by ron dyar on UnsplashFrom paper to digitalUnder this collaboration, KT and Iron Mountain will utilize the Korean telecom firm’s blockchain-based electronic document platform to digitize Iron Mountain’s physical documents. The partnership extends beyond digitization, with plans to explore diverse business prospects across various markets. It’s worth noting that Iron Mountain has an extensive global presence, operating across 54 countries.KT has been operating the Paperless platform since 2020, providing services such as contract writing, registered document delivery, and document storage. This initiative has been particularly beneficial for small and medium-sized enterprises, as well as sole proprietorship businesses, eliminating the need to establish individual systems.Asia-Pacific market as a priorityBoth companies are united in their objective to capture the Asia-Pacific market, a region where conventional paper documentation remains deeply ingrained. Given the extensive usage of paper documents in this market, the anticipated demand for digital transformation is substantial.Song Jae-ho, Vice President of KT’s AI/DX Convergence Business Division, emphasized the promising prospects of combining KT’s technological expertise with Iron Mountain’s global business capabilities. He highlighted the potential for a significant positive impact that their collaboration could bring to the global document market. Song expects the partnership will help KT position as a leader in driving digital transformation within the document management sector.Joyce Housien, Vice President of Commercial at Iron Mountain, echoed these sentiments, underlining the broader scope of their collaboration. She noted that their joint efforts are not only focused on achieving digital transformation within South Korea but also on generating new value within the wider Asian digital industry landscape.

news
Policy & Regulation·

Feb 27, 2025

Local crypto firms in talks with Hong Kong’s SFC on crypto staking

Local crypto firms in Hong Kong are understood to be in “active” talks with the Securities and Futures Commission (SFC), with a view towards bringing about the integration of staking within crypto exchange-traded fund (ETF) products. Haiyang Ru, chief risk officer of HashKey Group, a leading Hong Kong-headquartered digital asset financial services firm, told The Block that the Chinese autonomous territory may shortly see the introduction of staking services relative to crypto derivatives trading products and crypto ETFs. He stated: "We are actively discussing with the SFC the introduction of ETF staking and tokenized money market funds, as well as launching an 'Earn' feature alongside spot trading."Photo by tommao wang on UnsplashFocus on staking in 2025HashKey is one of a number of well-known digital asset firms that is in regular contact with the regulator. Other firms are also paying attention to developments. Alessio Quaglini, co-founder and CEO of Hex Trust, a Hong Kong-based firm that offers regulated institutional digital asset custody and staking services, believes that staking will garner greater attention in 2025. He stated: “Institutions that move into crypto custody will naturally seek yield-generating opportunities for their clients."  OSL, one of the first entities alongside HashKey to be awarded digital assets-related licensing in Hong Kong, has also identified rising customer demand for yield-generating products in the crypto space within the Chinese autonomous territory.  Global competitionThe authorities in Hong Kong are likely to be watching developments overseas also. ETH ETFs in the United States have reeled in $3 billion in capital inflows without staking. Since the launch of these products, many industry commentators have suggested that in the event that staking is approved, big institutions, particularly pension funds and wealth managers, are going to be attracted to the passive yields on these ETFs.  Traditional finance (TradFi) loves yield, and in the case of Ether ETFs that include staking, an annual percentage yield (APY) of up to 5% should be possible. Last month, an S&P Global report suggested that there was growing interest from institutional investors with regard to crypto staking opportunities.  Cryptocurrency ETF issuer 21Shares has applied to the Securities and Exchange Commission (SEC) in the U.S. to include staking within its ETH ETF product. A similar application has been made by crypto asset manager Grayscale relative to its ETH ETF offering. With that activity ongoing in the U.S. and inter-jurisdictional competition in terms of digital asset growth opportunities, it’s likely that Hong Kong will be keen to enable this market offering. Staking ‘unparalleled’ in TradFi markets Earlier this week, the SFC introduced a new roadmap geared towards strengthening the digital assets sector in Hong Kong. One of the initiatives itemized is the enabling of crypto staking.  The explanatory document published by the regulator states that it is examining the introduction of staking with safeguards in respect to digital asset custody, liquidity risks and “ensuring that the operational processes for staking are transparent.” The SFC described crypto staking as a yield generation opportunity that is unparalleled in TradFi markets.

news
Policy & Regulation·

Feb 15, 2024

Singapore’s Web3 sector hopes for budget measures to grow talent pool

Deputy Prime Minister and Minister for Finance Lawrence Wong is slated to unveil the Singapore 2024 Budget Statement on Feb. 16. As Singapore prepares for the unveiling of its 2024 Budget, the city-state’s Web3 community is amplifying its call for crucial government backing. That’s according to a recent report by The Straits Times. The plea from Singaporean firms revolves around two pivotal areas: one, nurturing a proficient talent pool well-versed in blockchain technology; and, in addition to that, having a strength and depth in cybersecurity, so as to fortify defenses against cyber threats.Photo by David Pardo Bernal on UnsplashUrgent need for Web3 talentSome time ago, stakeholders in Singapore set out their stall in terms of the ambition of firmly establishing the city-state as a global hub for Web3 development. It’s off to a good start with many notable crypto and Web3 companies having established themselves in Singapore. However, broadening that industry hub to the fullest extent will involve overcoming the significant hurdles hindering the growth trajectory of Singapore’s Web3 sector. Top of the list is the scarcity of skilled professionals in the blockchain domain. Danny Lim, a core contributor at MarginX, a decentralized exchange, stressed the pressing demand for seasoned developers. Lim underscored the necessity of supporting Web2 developers transitioning into Web3 realms, especially those grappling with job displacement, to solidify Singapore’s status as a nucleus for groundbreaking blockchain ventures. Elaine Zhu, the general manager of the Asian division of blockchain infrastructure firm Parity Technologies, emphasized the critical need for blockchain education, expressing apprehension over the dwindling influx of new developers. In citing a recent report by crypto-focused venture capital firm Electric Capital which quantified developer activity across Web3, Zhu noted that the number of experienced developers in Singapore remains healthy. However, the report found that the number of newly qualified developers dropped by 52 percent last year. Bolstering cyber defensesAdditionally, the industry is clamoring for fortified cyber defenses to shield against the escalating threat landscape targeting digital assets. This focus on security underscores the broader challenge of ensuring the secure proliferation of Web3 technologies and digital currencies within Singapore’s technological ecosystem. A report by Singapore-based blockchain security firm Beosin last year found that exit scams are a growing concern in the crypto-sphere. At the end of last month, the Singapore Police Force, alongside the Cyber Security Agency of Singapore (CSA), issued an advisory in order to raise awareness regarding crypto-centric cyber attacks. Ong Chengyi, representing Chainalysis, hailed Web3 as pivotal for long-term growth and advocated for sustained governmental support to enhance the sector’s capability in mitigating risks using advanced technological solutions. Ong remarked:“We hope to see more public-private collaboration to bolster Singapore’s defences against crypto crime and cyber threats more generally, through the utilization of data and technology.” Angela Ang of TRM Labs echoed that sentiment, emphasizing the imperative for heightened regulatory support to nurture the expansion of digital assets. Ang stated:“To deliver clarity to businesses at scale, whether it’s through licensing decisions or implementation guidance, the Government must invest in both human capital and technology throughout the regulatory process.” 

news
Loading