Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Web3 & Enterprise·

Oct 31, 2023

Saudi Arabia’s NEOM Forms $50M Animoca Brands Partnership

Saudi Arabia’s NEOM Forms $50M Animoca Brands PartnershipHong Kong’s Animoca brands, a gaming and metaverse venture capital firm, is embarking on a partnership with Saudi Arabia’s NEOM Investment Fund, focusing on pioneering Web3 initiatives.Animoca announced the initiative via a statement published to its website on Monday. NEOM is an ambitious project aiming to create a futuristic urban oasis in northwest Saudi Arabia, serving as a nexus for technology, commerce, entertainment, and tourism. It is planning to invest $50 million in Animoca.Photo by Hala AlGhanim on UnsplashDeveloping Web3 service capabilitiesThis collaboration will see Animoca harness its expertise to develop Web3 service capabilities with broad global applications in tandem with NEOM, aligning with NEOM’s vision of becoming a cutting-edge tech hub of the future.Animoca Brands has been a prominent player in the Web3 investment arena for several years. In July 2022, the company’s valuation soared to $6 billion, with backing from notable entities such as Singapore’s state investment fund, Temasek. Despite its ambitious goal to secure $2 billion for its metaverse fund in November of the same year, those expectations were significantly tempered following the FTX collapse. Consequently, in March, Animoca revised its target to a more modest $800 million.In-house market makingA report by The Block on Friday revealed that Animoca has been making efforts to pitch an in-house market making service to fledgling Web3 businesses within its portfolio. That service has been presented by the company to more than 400 startup projects in which it has been an investor over recent months.The key market makers in the crypto space include Wintermute, Keyrock, and GSR. This move by Animoca potentially puts Animoca in direct competition with these primary crypto-sector market makers. An in-house digital asset team has been tasked with offering the service. An Animoca spokesperson stated:“Its primary role, much like the treasury teams in many large corporations, is to optimize the utilization of the company’s balance sheet. The team does conduct market-making to ensure there is enough buy/sell liquidity for certain tokens, which is similar to the function that third-party market makers conduct, except that we choose to perform this in-house for scale and efficiency.”Saudi diversificationAs part of its Vision 2030 initiative, Saudi Arabia has been looking to diversify away from its predominantly oil-based economy. In an interview last month, Animoca Brands Founder Yat Siu outlined that the Middle Eastern country is embracing new technologies such as artificial intelligence (AI) and blockchain, encompassing blockchain-based gaming and Web3.In July it emerged that the Saudi Central Bank (SAMA) and the Hong Kong Monetary Authority (HKMA) were looking to extend the level of collaboration between the two territories relative to international payments and tokenization.This renewed interest from state-backed funds in Animoca suggests a potential shift in the Web3 venture capital landscape, coinciding with broader indications of a thaw in the crypto winter. The collaboration with NEOM and the injection of $50 million underscore the growing recognition of Web3’s potential, cementing Animoca Brands’ position as a key player in the ever-developing Web3 space.

news
Policy & Regulation·

Jan 02, 2024

Chinese authorities provide insight into conviction of RenrenBit founder

China has provided insights into the conviction of Zhao Dong, the influential crypto over-the-counter (OTC) trader and widely known founder of the RenrenBit crypto trading desk. The ‘OTC King’Last Wednesday, China’s Supreme Procuratorate disclosed that Zhao, known as the "OTC King," was handed down a substantial prison sentence for engaging in illegal foreign exchange and crypto business operations. The case is emblematic of China's persistent efforts to clamp down on cryptocurrency trading, even when conducted through less transparent channels like OTC desks, private chat groups and stablecoins.Photo by Hanson Lu on UnsplashTracing fundsIn their comprehensive disclosure, the Chinese authorities outlined the meticulous investigation that led to Zhao Dong's conviction. The focus was on tracing fund movements across Chinese bank accounts, overseas cash pools and the circulation of Tether and Bitcoin. Investigators honed in on accounts associated with Zhao Dong and the chat groups used for trading activities. Their arsenal included detailed bank records, WeChat conversations, testimonies from Zhao's OTC agents and other documentary evidence. The report highlighted that all defendants, including Zhao Dong, confessed to the process of collecting dirhams in cash in Dubai, paying RMB to the other party's designated account, buying Tether with dirhams, and allowing the domestic gang to illegally sell it back for RMB. Seven year sentenceIn one of the alleged schemes, Zhao Dong purportedly orchestrated crypto-fiat trades between Dubai-based entities holding cash piles in United Arab Emirates (UAE) dirhams and Chinese contacts within the country. With numerous related recipients confirming that the funds Zhao received were payments from foreigners, the prosecution's case was made so much stronger. Zhao unsuccessfully argued during three public court hearings that his actions constituted digital currency transactions and not a breach of foreign exchange laws. The prosecution countered with evidence from the group's chat records, emphasizing the nature of foreign exchange in their dealings. The court ultimately rendered a verdict, sentencing Zhao Dong to seven years in prison and imposing a 2.3 million Chinese yuan ($325,000) fine. This conviction serves as a stark reminder of the stringent regulatory stance that China has adopted towards cryptocurrency trading. Zhao Dong was considered one of China's most influential OTC crypto traders. He was a Bitfinex shareholder and founder of the D Fund venture capital fund. He established RenrenBit in August 2018, incorporating the company in Singapore. The influential crypto trader is also believed to have been involved in assisting stablecoin-issuer Tether to launch its Tether Yuan product. However, once the authorities moved against him, RenrenBit was taken offline while Tether scrapped its pursuit of Tether Yuan. Despite his influence, Zhao has ultimately become a symbol of the government's commitment to curbing such crypto trading activities within mainland China. The outcome underscores the severity of China's regulatory crackdown on cryptocurrency trading and sends a strong message to other players in the crypto space within the country.

news
Policy & Regulation·

Jun 21, 2023

Singapore Regulator Awards CMS License to AsiaNext

Singapore Regulator Awards CMS License to AsiaNextAsiaNext, a joint venture between Tokyo-based financial services company SBI Digital Asset Holdings and Switzerland’s SIX Group AG, has received regulatory approval for its institutional-grade digital asset exchange in Singapore. The Monetary Authority of Singapore (MAS) granted AsiaNext an in-principle approval for a Capital Markets Services (CMS) license, marking a significant milestone for the company.Photo by Davis Sánchez on PexelsTaking to LinkedIn last week, the firm said that the achievement is a testament to the efforts it has made in terms of rigorous regulatory compliance. With this CMS license, AsiaNext is poised to become a trusted digital asset exchange catering specifically to institutional investors in Asia and globally. The joint venture, which was finalized in September 2021, brings together the expertise and networks of SBI Digital Asset Holdings and SIX Group AG to meet the growing demand for trading public and private digital assets.Singapore-based joint ventureChong Kok Kee, appointed as the CEO of AsiaNext in March 2022, and Neil Thomas, serving as the Chief Commercial Officer, lead the team. Their combined experience in the financial industry positions AsiaNext to deliver a comprehensive suite of services that meet the rigorous standards of institutional investors.The primary goal of AsiaNext is to bridge the gap between traditional finance and the digital asset space. Chong emphasized the importance of a secure, transparent, and compliant platform that instills confidence in market participants during an interview with Hubbis in 2022. The exchange aims to provide integrated listing, trading, and post-trade services for various digital assets, including digital payment tokens.AsiaNext recognizes the increasing demand for trading digital assets among institutional investors. To address this demand, the joint venture will leverage the extensive networks and expertise of SBI Digital Asset Holdings in Asia and SIX Digital Exchange in Switzerland and Europe. Both partners have already demonstrated their leadership in global digital asset markets through investments, issuances, and initiatives.By securing the CMS license, AsiaNext, which is based in Singapore, has taken a crucial step towards becoming a trusted platform for institutional investors in Singapore and beyond.SBI partnershipsFor its part, SBI has favored joint ventures and partnerships when it comes to its increasing involvement in the digital assets space. It has entered into a joint venture with Zodia Custody, a digital assets custodian which has been spun up by UK-based financial services giant Standard Chartered, to take on the Japanese market. Additionally, it has increased its shareholding in the custodian in recent months.Its crypto exchange subsidiary, SBI VC Trade, recently formed a partnership with the project team behind the XDC Network blockchain with a view towards making inroads into the Japanese market.AsiaNext is now focused on preparing for the launch of its digital asset exchange, which is scheduled to commence later in 2023. Having now established itself on a firm regulatory footing, and the support of its strategic partners, AsiaNext appears to be well-positioned in meeting the evolving needs of institutional investors in the Asian region.

news
Loading