Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Policy & Regulation·

Aug 21, 2023

Senior Gyeonggi Officials Required to Declare Virtual Asset Holdings by Sept 1

Senior Gyeonggi Officials Required to Declare Virtual Asset Holdings by Sept 1The Gyeonggi province of South Korea is requiring officials of rank 4 or higher to report their cryptocurrency holdings from today until September 1. This move is in line with the amended Public Service Ethics Act, set to take effect on December 14, which will require senior government officials to declare their virtual asset holdings.Photo by Mathew Schwartz on UnsplashRevised code of conductThe nation’s most populated provincial government announced today the finalization and implementation of revisions to the employee code of conduct. These changes intend to prevent government employees from exploiting their official positions for personal financial gains. Before finalizing these changes, the province had sought public feedback on the amendment until July 25.In May, Gyeonggi Governor Kim Dong-yeon convened a meeting to call for devising a plan that encourages public officials under financial disclosure requirements to declare their virtual assets. He emphasized the importance of proactive measures in this regard.On August 14, the provincial government presented guidelines on virtual asset reporting, detailing the reporting process, content requirements, and penalties for false submissions.A move towards transparencyLee Seon-beom, the Head of Gyeonggi’s Investigation Office, explained that this initiative is designed to alleviate the public’s concerns over virtual assets. It also aims to promote transparency among officials, ensuring they avoid unlawful accumulation of wealth.

news
Policy & Regulation·

Dec 15, 2023

Banking giants in Turkey embrace crypto ahead of legislative change

Banking giants in Turkey embrace crypto ahead of legislative changeIt remains unclear what the underlying environment for the further development of the crypto sector in Turkey will be until such time as the country introduces a legislative framework to shape the industry’s development. However, that fact is not deterring a couple of Turkey’s leading banks, who have decided to embrace the digital asset realm.Photo by Michael Jerrard on UnsplashStablex acquisitionOn Monday CoinDesk Turkiye reported that the investment arm of Turkish bank Akbank had acquired local crypto company Stablex. Stablex was founded in May 2020 by Jihad Shannak with the objective of providing professional services, including trading relative to cryptocurrencies in Turkey. Majority shareholding passed to Ak Investment in May of this year, with initial negotiations on the sale having commenced in August 2022.A high-ranking official at Ak Investment expressed the group’s ambition to become a pivotal figure in the digital asset realm, signaling a proactive approach to the evolving financial landscape. Akbank also banks the majority of crypto start-ups based in Turkey.Speaking about the acquisition recently, Akbank executive Mert Erdoğmuş stated:“We have invested in Stablex to respond to the need for reliable and innovative service in the cryptocurrency market. Stablex reflects our values with its experience in the sector, pioneering achievements and professional service approach.”BBVA crypto walletAlongside Akbank’s move into the digital assets arena, Garanti BBVA, Turkey’s second largest private bank, recently unveiled its crypto wallet app. The feature-rich application includes a cold wallet, empowering users to seamlessly send and receive assets such as bitcoin (BTC), USD Coin (USDC) and ether (ETH).The pilot project for the app commenced in August, with the application currently available on iOS. In bringing the app to market, the bank created Garanti BBVA Digital Assets, a dedicated subsidiary firm. Commenting on that development back in August, the subsidiary’s Chairman of the Board, M. Çağrı Süzer, stated:”Our research shows that customers significantly value trust in their crypto transactions and especially on its storage. Hence, we are happy to launch our Crypto Custody Wallet addressing these real needs.”Despite uncertainties, Turkey has firmly established itself in the global crypto landscape, ranking among the top 20 countries in Chainalysis’ Global Crypto Adoption Index 2023. The instability of the Turkish lira in recent years has been a driver for crypto adoption in the country. In recent days, the bitcoin unit price has reached its highest exchange rate level against the local sovereign currency.Earlier this week, it emerged that crypto platform Blockchain.com is adding headcount and has its sights set on expansion into Turkey as one of its growth opportunities.FATF-compliant regulatory approachTurkey’s regulatory stance has been to take a cautious approach. In 2021, the central bank restricted the use of crypto for payments, although a complete ban on digital assets was ruled out by officials.Looking ahead, a government official revealed plans for crypto legislation to be presented to Parliament in November. While details remain scarce, this legislative move aligns with Turkey’s broader strategy to exit the Financial Action Task Force’s (FATF) “gray list.”

news
Web3 & Enterprise·

Dec 10, 2024

GRVT snags license to become world’s first regulated DEX

GRVT, a hybrid cryptocurrency exchange platform that bases its operations in Singapore, has secured a trading license in Bermuda which the project claims, makes it the first regulated decentralized exchange (DEX).  In a press release published on the project’s behalf by PR Newswire on Dec. 6, the project, which aspires to be “Goldman Sachs on blockchain,” announced the acquisition of a Class M Digital Asset Business License from the Bermuda Monetary Authority (BMA). Photo by GuerrillaBuzz on UnsplashAiming for further licensingThe license puts the firm on a path to operate as a fully regulated DEX. Securing this Class M license isn’t the end of the project’s regulatory compliant endeavors, however. Class M confers a “modified” exchange license under the Bermuda Digital Asset Business Act (DABA). Class M covers pre-operational activities while the service remains within a sandbox environment. The company hopes to have acquired Class F or “Full” licensing designation by mid-2025. At that point, GRVT will be in a position to take its service from a sandbox environment to full launch of its institutional-grade perps DEX in a regulatory compliant manner. On X GRVT suggested that this licensing is pivotal in the movement of decentralized finance (DeFi) towards mainstream adoption. “With this milestone, DeFi evolves - safer for users and institutions alike,” the project wrote. Hybrid approachAs a hybrid DEX, GRVT combines the decentralization of DeFi with the structure and compliance required for the participation of institutional investors. Commenting on this latest development, GRVT CEO Hong Yea stated:”We've always believed compliance should be the foundation for crypto and DeFi, not an afterthought. Without it, earning institutional trust—and bringing revolutionary technologies to the mainstream—becomes nearly impossible." Yea told Cointelegraph that in two weeks time, the project will officially launch its mainnet to all users. “Our trading volume will then be available through major external data providers,” he added. In preparation for that mainnet launch, the project announced in September that it had partnered with 16 market makers including Galaxy Trading, Amber Group, QCP and others, in order to ensure that the platform has sufficient liquidity in place to enable a smooth launch. Users have been testing the platform following its Open Beta Testnet launch in August. The GRVT CEO believes that the project can “unify cryptocurrency and mainstream finance, creating a system where assets move freely and all forms of value coexist in one integrated ecosystem.”   A regulated yet decentralized offeringReferring to the two main components baked into the GRVT offering, he said that “decentralization distributes control away from central authorities, promoting transparency, security, and user empowerment.” Meanwhile, “regulation establishes standards to protect users, ensure market integrity and promote fair practices.” In successfully pursuing licensing in Bermuda, GRVT joins a list of more than 30 firms in the digital assets sector who have obtained licensing in the British overseas territory. In October global cryptocurrency exchange platform Kraken launched a Bermuda-based derivatives trading business having obtained licensing from the BMA. USDM stablecoin issuer Mountain Protocol received a Class F license from the BMA in July. Other entities successfully licensed by the BMA include Coinbase, HashKey, Circle, Bittrex and Zero Hash.

news
Loading