Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Web3 & Enterprise·

Nov 13, 2023

Klaytn Foundation partners with CoinMarketCap to support Web3 startups and developers

Klaytn Foundation partners with CoinMarketCap to support Web3 startups and developersThe Klaytn Foundation, South Korean conglomerate Kakao’s Layer 1 public blockchain, announced on Monday (local time) that it has been selected to be one of the official partners of CoinMarketCap Labs (CMC Labs), a Web3 startup accelerator program operated by the crypto information platform CoinMarketCap.Photo by Shubham Dhage on UnsplashEmpowering buildersThe CMC Labs program offers builders an array of benefits that serve to promote their projects, boost discoverability, communicate with users, and more. This includes the “Learn and Earn” campaign, where startup owners can attract users through a system that distributes token rewards after engaging in educational content. The Airdrop Campaign, on the other hand, helps participants keep up to date on a startup project’s important developments, such as price movements. Startups can also promote their projects through a long-form article or YouTube video published on the CMC Deep Dive platform.Fostering the growth of dAppsCoinMarketCap, in turn, has agreed to be a partner in the Ignite On Klaytn (IOK) Program — a program run by the Klaytn Foundation to support promising developers both in Korea and abroad in their endeavors to bring their decentralized apps (dApps) to the Web3 market, thus cultivating the Klaytn ecosystem. Developers stand to benefit because they can concentrate their efforts on product development, while the program provides support for other crucial aspects like wallets, API nodes and development outsourcing.Through this latest collaboration with CoinMarketCap, the Klaytn Foundation plans to assist various projects in their entry into the global market. It also aims to play a bridging role, enabling more projects within the Klaytn ecosystem to participate in the CMC Labs program.“We are looking forward to the mutual participation of Klaytn Foundation and CoinMarketCap in our respective programs, which is expected to provide momentum to Klaytn’s ongoing efforts to expand its reach into Asia and global markets,” explained Seo Sang-min, Representative Director at the Klaytn Foundation.

news
Policy & Regulation·

Feb 17, 2024

Ethiopia may be embracing Bitcoin mining with new data mining partnership

Ethiopian Investment Holdings, the largest sovereign wealth fund in Africa, has announced the signing of a memorandum of understanding (MoU), which is suspected to involve a deal on Bitcoin mining. Deal uncertaintyTaking to LinkedIn on Feb. 15, the sovereign wealth fund outlined details of a partnership with Data Center Service, a subsidiary of Hong Kong’s West Data Group. Separately, Kal Kassa, CEO of Ethiopian operations at Hashlabs Mining, posted on the X social media platform, outlining that it was a stakeholder in the project and that it involved Bitcoin mining. The matter lacks full confirmation however, given that Kassa subsequently deleted his post while the sovereign fund’s statement falls short of mentioning Bitcoin mining. Once verified, the project would signify a substantial investment of $250 million. It’s understood that the investment would be directed towards the establishment of state-of-the-art infrastructure tailored for data mining and artificial intelligence (AI) training operations within Ethiopia.Photo by Kelly on PexelsExploiting abundant energy resourcesA key component of this venture may involve the setup of Bitcoin mining operations utilizing Canaan Avalon miners. This initiative would align with Ethiopia's broader strategy to capitalize on its abundant energy resources to attract international investment and stimulate economic growth.Ethiopia has about 5,200 MW of installed generation capacity, 90% of it coming from hydropower and the remainder from wind and thermal sources. While the official confirmation from the government is pending, the ambitious project has sparked both excitement and skepticism within the industry. Concerns linger regarding the energy-intensive nature of Bitcoin mining and its potential strain on the local electricity supply, an issue of particular relevance in a nation where energy accessibility remains a pressing challenge for many. Bloomberg reportEarlier this month, a report from Bloomberg highlighted Ethiopia as being a new haven for Chinese crypto miners. Following the imposition of a mining ban in China in 2021, many operations were redeployed overseas. Kazakhstan in particular was a popular choice. The Eurasian country wasn’t prepared for the influx, leading to power blackouts.Hashlabs Mining co-founders Jaran Mellerud and Alen Makhmetov both featured in the article. Mellerud outlined the difficulty, stating:“Firstly, countries can run out of available electricity, leaving no room for miners to expand. Secondly, miners can suddenly be deemed unwelcome by the government and be forced to pack up and leave.”Makhmetov outlined that he had a 10 MW facility in Kazakhstan which still sits idle today as curbs and taxes enforced in Kazakhstan on miners “basically killed the industry.” Despite these difficulties in Kazakhstan and China's official ban on cryptocurrency trading, the legalization of Bitcoin mining in Ethiopia in 2022 has spurred a notable influx of Chinese miners seeking new investment avenues. Ethiopia will need to be mindful of the difficulties experienced in Kazakhstan. With that, the Ethiopian government's move towards regulating cryptographic products, including mining activities, reflects a measured yet optimistic approach towards harnessing the economic potential of Bitcoin mining. This regulatory framework aims to strike a balance between fostering sector growth and safeguarding the country's energy security and environmental commitments.  

news
Policy & Regulation·

Apr 21, 2023

Crypto Features in India-UK Markets Dialogue

Crypto Features in India-UK Markets DialogueAccording to a press release published by HM Treasury, the 2nd India-UK Financial Markets Dialogue meeting held on Wednesday featured six key themes with crypto featuring among them.©Pexels/SkitterphotoThe event brought officials from both nations together in the first in-person financial dialogue since 2017. While the meeting considered banking, insurance and reinsurance, capital markets, asset management and sustainable finance, it also allotted time to discuss payments and crypto-assets.CBDC knowledge sharingBoth sets of officials discussed the scope for augmenting knowledge on Central Bank Digital Currencies (CBDC) by way of mutual learning. The officials agreed on the importance of robust global approaches relative to the emergence and development of crypto-assets internationally. The joint statement issued following the meeting revealed that progress relative to the G20 roadmap for enhancing cross-border payments was a matter which was discussed. It’s an item that could have major implications for the use of cryptocurrency in cross border transactions.Global collaborationThe meeting marks another move towards greater global collaboration on policy and regulation relative to digital payment systems and crypto assets. Earlier this month, India’s Finance Minister Nirmala Sitharaman said that the introduction of any new regulations on digital assets needs to be coordinated on a global basis. “The G20 and its members agree that it’s not going to be possible to have an independent, standalone country dealing with crypto assets”, Sitharaman stated at a news conference following a meeting of central bank governors and G20 finance ministers.There’s a growing recognition among politicians, government and central bank officials that decentralized money doesn’t end at a territory’s borders due to its inherently decentralized properties.Taking steps to regulate cryptoWhile on the one hand strategizing as to how digital assets can be best controlled on a global level, India is also taking its own individual steps towards national regulatory action. Recently, it expanded its Prevention of Money Laundering Act (PMLA) to include consideration of digital assets. The newly amended PMLA will now deal with the exchange of digital assets for fiat money and vice versa. It also considers safekeeping, transfer and administration relative to cryptocurrency. Furthermore, its broadened scope deals with financial services offered related to virtual or digital assets.Rajagopal Menon, the VP of India’s leading cryptocurrency exchange WazirX, has said that “regulations levied by India have been baby steps toward institutional participation in the crypto exchange.” While market participants in the digital assets space are apprehensive about the regulatory measures that governments and state regulators choose to adopt, so long as the objective isn’t to regulate the innovation out of existence, such developments can have a profoundly positive effect on the digital assets market.There’s no doubt that in line with Menon’s point relative to the Indian context, the same scenario can play out in all digital markets given the application of the right regulatory approach. Institutional investment for the most part has eluded crypto despite many already heralding its arrival in recent years. Institutions move slowly and the only way in which they will be comfortable in working with digital assets is with complete regulatory clarity having been set out.So while some in crypto may be concerned at the mention of global regulatory coordination in respect of digital assets, so long as it doesn’t go too far, greater work towards improved regulatory clarity in the digital assets market can be a catalyst for further adoption and growth in India, the UK and further afield.

news
Loading