Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Web3 & Enterprise·

May 06, 2024

Animoca Brands partners with Saakuru Labs to bolster Web3 gaming

Metaverse gaming company Animoca Brands has recently announced a strategic partnership with Saakuru Labs, aiming to drive the adoption and integration of blockchain technology within Saakuru Labs' ecosystem. The collaboration is expected to bolster the expansion of the Web3 gaming industry, particularly in Southeast Asia, where the partnership officially kicks off. The initiative involves the incorporation of Web3 games developed with the Saakuru Protocol into the Animoca Brands ecosystem. Gasless transactionsAnimoca Brands will play a crucial role by providing gaming titles to its partners, while Saakuru Labs will facilitate Animoca Brands' expansion efforts in Southeast Asia. Developers stand to benefit from access to accelerated development processes and gasless transactions. Gasless transactions are particularly significant in regions like Southeast Asia, known for lower-income demographics. The market has shown a keen interest in blockchain technology and Web3 games, indicating promising growth potential. With gasless transactions, developers can seamlessly integrate critical functionalities into their gaming titles, including infrastructure components.Photo by Bastian Riccardi on UnsplashTransition to Web3 gamingThe Saakuru Protocol, known for its consumer-centric L2 infrastructure, enables major integrations of Web3 components into traditional gaming segments. This ensures a smooth transition from traditional gaming to Web3 gaming, enhancing the overall gaming experience. Yat Siu, Executive Chairman of Animoca Brands, emphasized the pivotal role of gaming in the evolution of the Internet and open metaverse, highlighting Southeast Asia's potential to lead in Web3 technology adoption. Jack Vinijtrongjit, CEO of Saakuru Labs, underscored the platform's capability to offer seamless engagement with multiplayer gaming titles without latency or transaction fees. The partnership between Saakuru Labs and Animoca Brands aligns with Saakuru Labs' recent collaboration with cloud computing infrastructure platform Aethir, aimed at enhancing blockchain gaming through GPU infrastructure. Notable partners of Animoca Brands, including GameGPT, W3GG and GameFi.org, have already expressed their commitment to adopting the gasless protocol. Experts believe that gaming presents an ideal avenue to accelerate blockchain technology adoption and advance Web3 gaming principles. With gaming becoming a mainstream form of entertainment, seamless integration of technology is crucial for user acceptance. The outcome of the Animoca Brands and Saakuru Labs partnership is anticipated to manifest results in the coming quarter or by the end of the year. 

news
Policy & Regulation·

Sep 26, 2023

Japan’s Cryptoasset Group Proposes Self-Regulatory Reforms for IEO System

Japan’s Cryptoasset Group Proposes Self-Regulatory Reforms for IEO SystemThe Japan Cryptoasset Business Association (JCBA) has revealed a preliminary draft advocating for reforms in self-regulation to bolster the soundness of the initial exchange offering (IEO) system. This draft has been submitted to the Japan Virtual and Crypto Assets Exchange Association (JVCEA).IEOs serve as a mechanism enabling various enterprises to accrue funds and broaden their user base by orchestrating token sales on cryptocurrency exchanges for Web3 projects. This fundraising method holds the potential to enhance trust as crypto exchanges, supervised by the Japanese Financial Services Agency, undertake evaluations of project feasibility and maintain ongoing oversight.Photo by Takashi Miyazaki on UnsplashPositive regulatory developmentsThe ameliorating regulatory landscape is also a positive development, highlighted by this year’s tax law amendment, which grants exemptions to enterprises’ self-issued tokens from year-end corporate taxation. In Japan, four IEOs have been conducted so far, with the inaugural IEO amassing over 900 million yen (approximately $6 million). The cumulative amount from the four IEOs has surpassed 4.4 billion yen. However, given that the IEO is a relatively nascent fundraising method, improvements in token price stability and operational modalities are required to ensure that businesses and users can engage with it confidently.Enhanced user protectionAgainst this backdrop, JCBA, an organization comprised of various enterprises involving virtual assets and Web3, has been discussing the direction of the IEO system from a corporate viewpoint since May of this year. Establishing price stabilization measures and selling restrictions within the Japanese IEO system will contribute to user protection by allowing investors to manage their assets under domestic regulations. JCBA stated that users will find domestic exchanges more secure in comparison to foreign ones.As this proposal represents an initial draft, deliberated and formulated only within the JCBA, the group intends to consult and assess the feasibility of the self-regulatory rules with each pertinent organization as necessary.Four key pointsThe document submitted by JCBA to JVCEA presented four key points concerning the IEO. Pertaining to pricing, it suggested the diversification of calculation methods customized to each project and the specification of price-related disclaimers. On liquidity, it posited that liquidity objectives should be established at the time of listing, and an environment conducive to securing liquidity should be developed. JCBA also pointed out the necessity of establishing rules for price stabilization measures at the time of listing. Finally, regarding selling restrictions, it was noted that both token issuers and exchanges should adhere to a minimum three-month lock-up period for tokens.

news
Policy & Regulation·

Jun 13, 2023

Thai Central Bank Collaborates With Singapore’s 2C2P on CBDC Pilot

Thai Central Bank Collaborates With Singapore’s 2C2P on CBDC PilotThe Bank of Thailand is set to commence a pilot project for a retail central bank digital currency (CBDC) within a regulatory sandbox later this month.Three participating fintech firmsThat’s according to local media, with reports suggesting that three payment providers will participate in the project, which is expected to involve up to 10,000 users and run until August.The scheme will involve two Thai banks, Bank of Ayudhya (Krungsri), Thailand’s fifth largest bank, and Siam Commercial Bank. Singapore-based payments service provider 2C2P will also collaborate with the Thai central bank on the CBDC initiative. 2C2P is a global payments platform which helps businesses to accept payments securely online, on mobile, and in-store. Each organization has developed an app exclusively available to selected users, encompassing a digital wallet and a QR code scanner.Krungsri plans to engage up to 2,000 staff members and approximately 100 merchants in the project, focusing on locations around the bank’s headquarters. Furthermore, the project will expand to include the Ploenchit branch.Photo by Florian Wehde on UnsplashMaintaining relevanceBanks are having to embrace the need to adapt to the eventuality of developments like CBDCs as, depending upon how they’re implemented, they could render some banking products obsolete. Sam Tanskul, the Managing Director of Krungsri Finnovate, a division of the Thai banking business that focuses on strategic investments, expressed the need for the bank to establish a distinct strategy for differentiating the retail CBDC from its existing PromptPay mobile payments service.Siam Commercial Bank’s pilot project will operate in a similar manner to Krungsri’s, involving staff members and nearby merchants as participants. The Bank of Thailand has emphasized that the project aims to facilitate learning rather than serve as an official pilot launch. At present, the central bank has not disclosed any official plans to implement a CBDC.Wholesale and retail CBDCsThe Bank of Thailand commenced the development of a wholesale CBDC back in 2018. It has actively participated in various projects such as the Bank for International Settlements’ (BIS) mBridge cross-border payment initiative and the Project Inthanon-Lion Rock collaboration with the Hong Kong Monetary Authority (HKMA).In a move to foster the growth of the digital token market, Thailand waived corporate income tax and value-added tax for companies issuing investment tokens in March. While this decision is expected to result in an approximate loss of $1 billion in revenue for the country, it is projected that investment tokens will generate $3.7 billion over the next two years, as stated by a government spokesperson.The Bank of Thailand’s forthcoming retail CBDC pilot project is one of a plethora of such projects being pursued throughout the Asia-Pacific region. In Japan, the Bank of Japan recently completed the second phase of a proof of concept project relative to its CBDC, with the project now progressing to phase three. Last month, it emerged that the Bank of Korea is collaborating with Samsung Electronics relative to its CBDC project. Meanwhile, India is progressing further in trialing its CBDC, while China is further along the development curve than all others in that respect.

news
Loading