Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Web3 & Enterprise·

Jan 29, 2024

Label Foundation to launch Web3 music streaming platform on LG Smart TVs

The Label Foundation is working with global electronics conglomerate LG Electronics to rollout its Web3 music streaming service, Tracks, on LG Smart TVs, according to an article by Bitcoinist on Monday (KST). The platform’s TV app will be available for free on the latest LG Smart TV models that support webOS22 and 23.Photo by Blaz Photo on UnsplashReinvented music streamingTracks is a music streaming service that allows users to enjoy free high-quality music and artistic visuals through their TVs. The platform leverages Web3 technology to offer a variety of rewards based on the amount of time spent listening. In particular, the Label Foundation aims to make Tracks easily accessible to Web2 users around the world to serve as a bridge between Web2 and Web3. “With the upcoming launch, numerous TV owners will be able to enjoy music for free, which resonates deeply with Label’s ethos, championing universal music accessibility without financial boundaries. We are happy that our collaboration with LG Electronics made this a reality,” Label Foundation said. Rapid riseSince its launch in July, Tracks has gained substantial popularity among younger generations, with its mobile app amassing over 150,000 users worldwide and more than 10,000 daily active users. The Label Foundation attributes this success in user acquisition to its user-centered approach, as opposed to the content provider-centered approach of traditional music streaming services.  As part of its monetization efforts, Tracks will also integrate a free advertising supported streaming television (FAST) service in the near future, which will allow users to access content like television programming and films without subscription fees.

news
Policy & Regulation·

Dec 21, 2023

Korean regulator monitors non-listed token amidst peer-to-peer trading surge

Korean regulator monitors non-listed token amidst peer-to-peer trading surgeThe South Korean financial regulator is closely monitoring BTCMobick, a non-listed token issued by crypto influencer Oh Tae-min, who is known for authoring books like “The Great Bitcoin” and “Bitcoin and the Geopolitics of the Dollar.” The Financial Services Commission (FSC) is cautioning local crypto exchanges regarding the potential for price manipulation should the token be listed.Photo by Daniel Bernard on UnsplashBTCMobick TokenThe BTCMobick token is reportedly being traded peer-to-peer at around KRW 300,000, which is approximately equivalent to $230, in chat rooms of messaging apps like KakaoTalk outside of cryptocurrency exchanges. The token has gained enough traction to spur the emergence of dedicated apps that facilitate these peer-to-peer trades, charging fees for their services. Based on the size of the chat rooms and apps involved, it is estimated that approximately 3,000 participants are trading the token, according to a report by local news website Etoday.As per another coverage by the same outlet, the Virtual Asset Inspection Division of the Financial Intelligence Unit (FIU), which operates under the FSC, has inquired with local crypto exchanges on two occasions — once in September and again this week — about whether they have listed or are planning to list the BTCMobick token. It’s rare for the financial authority to specifically target a particular token when making inquiries with crypto trading platforms.Potential price manipulationAn FIU official explained the rationale behind the agency’s inquiry into crypto exchanges. The official stated that the probe aimed to caution the exchanges about potential price manipulation of the BTCMobick token. The concern is that many crypto users might suffer losses if such a token, which has been experiencing a continual rise in price outside of trading platforms, were to be listed. Currently, legal penalties for cryptocurrency price manipulation fall under the Virtual Asset User Protection Act, which will not be enforced until July 2024. This indicates a regulatory gap in the immediate term.Hwang Suk-jin, a professor at Dongguk University’s Graduate School of International Affairs and Information Security, pointed out that while giving out privately generated tokens to friends or acquaintances doesn’t raise any legal issues, the situation changes once these tokens are listed for trading on exchanges and distributed more broadly in the market. In such scenarios, these tokens can become a source of legal disputes, he explained.Amidst these developments, there are circulating rumors suggesting that BTCMobick is on the verge of being listed on exchanges. An industry insider has mentioned that there are brokers actively spreading these rumors, indicating that the token might soon become publicly tradable.Oh Tae-min’s denial of rumorsMeanwhile, Oh Tae-min, the creator of BTCMobick who has been distributing his token for free, states that the token is part of an experiment intended to mimic the early stages of Bitcoin. However, critics are concerned that the personally issued token has no practical utility. Addressing the circulating rumors about the token’s potential listing on exchanges, Oh asserts that these rumors are baseless and false. He further warns that any brokers spreading such rumors are likely engaging in fraudulent activities.

news
Policy & Regulation·

Dec 05, 2024

Indian government claims Binance isn’t tax compliant

According to India’s Finance Ministry, Binance and a number of other virtual asset service providers (VASPs) are not tax-compliant in India. Cases of tax evasion detectedNews of this matter emerged via written answers, published on Dec. 2, provided in response to parliamentary questions which had been put to India’s Finance Minister, Pankaj Chaudhary. The minister confirmed that a “few cases of evasion of Goods and Services Tax (GST) by cryptocurrency exchanges and investors” had been detected. The document goes on to list 17 crypto entities who are currently being investigated on that basis, with Binance being the most well-known among them. Notable Indian exchanges listed include WazirX, CoinDCX and CoinSwitch. Chaudhary included details of cases booked against these exchanges. In Binance’s case, it was required to pay 722 crore Indian rupees, which amounts to around $85.2 million. While Binance doesn’t appear to have incurred penalties, in the case of WazirX, the exchange had an assessed tax shortfall of 40.51 crore Indian rupees ($4.78 million), but after fees and interest, it was provided with a demand for 49.19 crore Indian rupees ($5.8 million). CoinDCX and CoinSwitch were also assessed with a demand for 20.86 crore Indian rupees ($2.46 million) and 19.38 crore Indian rupees ($2.28 million), inclusive of penalties and interest. In the case of WazirX, CoinDCX and CoinSwitch, the exchanges have had to pay an additional 21%, 24% and 37% respectively in fees and interest over and above their original tax liabilities.Photo by Naveed Ahmed on UnsplashPrevious tax and regulatory issuesTo date, the Finance Ministry has recovered 122.3 crore rupees ($14.4 million) as part of these investigations. Binance has as yet not paid the funds demanded by the authorities. It emerged in August that India’s Directorate General of Goods and Services Tax Intelligence (DGGI) had imposed an $86 million tax demand on the company, with Binance contesting the assessment. The global crypto exchange platform had previously paid a $2.5 million fine for having engaged with Indian customers despite not having been approved by the authorities to trade within the country. After a number of months during which it didn’t trade within the Indian market, in August Binance regularized its standing and gained approval to trade. In a request for comment on the matter from Cointelegraph, a Binance representative stated: “We continue to work closely with regulatory authorities and attend necessary hearings to address any concerns and questions. Binance remains responsive and cooperative and is committed to addressing all necessary tax inquiries.” The company recently hired UK-based accounting and business advisory firm Grant Thornton to assist with accounting, tax and audit preparedness. In the case of WazirX, a spokesperson said that “GST law on cryptocurrencies was not clear in India,” and that on this basis, the company found itself being assessed for non-payment of the applicable taxes.

news
Loading