Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Policy & Regulation·

Jul 27, 2023

Korean Banks Impose Crypto Exchanges to Maintain a Reserve of at Least 3B KRW

Korean Banks Impose Crypto Exchanges to Maintain a Reserve of at Least 3B KRWIn a significant step towards regulating the cryptocurrency market and ensuring the safety of virtual asset users, South Korea’s Federation of Banks (KFB) has collaborated with financial authorities and virtual asset exchanges to establish the “Guidelines for the Operation of Real Name Accounts for Virtual Assets.” The KFB, as a group of banks and financial institutions, facilitates cooperation between its members and promotes the development of the financial industry.Photo by rc.xyz NFT gallery on UnsplashThe guidelines come as a response to the increasing need for stronger money laundering prevention measures and standardization in the crypto industry. The first step towards this was taken in 2018 when crypto exchanges became obliged to establish a real name account at a bank in order to provide Korean Won (KRW) deposit and withdrawal services to their customers. Currently, the exchanges that won such bank accounts are Upbit, Bithumb, Coinone, Korbit, and Gopax.However, this policy brought with it a set of challenges, including differing practices among various cryptocurrency exchanges, leading to inconveniences for users. Additionally, varying user protection measures, such as reserve requirements, caused confusion in the market.3 billion KRW in reservesTo address these issues, the new guidelines aim to clarify how banks operate cryptocurrency real-name accounts and bolster overall security. One of the key changes is the requirement for crypto exchanges to maintain a reserve of at least 3 billion KRW ($2.36 million). This reserve fund serves as a precautionary measure to address potential financial losses resulting from hacking incidents or system failures at crypto exchanges.Furthermore, the guidelines mandate banks to manage deposit and withdrawal limits by categorizing user accounts into limited and normal accounts. A limited account will not be converted to a normal account, which grants higher deposit and withdrawal limits, until the user’s transaction purpose and the source of funds are verified.Enhanced due diligenceIn addition, banks will perform annual enhanced due diligence (EDD) for individual account holders. This thorough review will encompass users’ identification, transaction purposes, and the origin of funds.User asset segregationTo safeguard users’ funds, crypto exchanges will be required to ensure that customer deposits are held separately or placed in trust. Regular due diligence at crypto exchanges will also be conducted by banks, with mandatory visits occurring at least once a month. Moreover, third-party services will be engaged to perform independent due diligence every quarter on crypto exchanges, providing an additional assessment of their operations.The official launch of these new guidelines is scheduled for January of next year. However, the requirement of depositing at least 3 billion KRW will come into effect earlier, starting in September of this year. Additionally, the implementation of guidelines for expanding deposit and withdrawal limits is anticipated in March of next year.

news
Policy & Regulation·

Apr 10, 2023

Binance Headlines List of Japan FSA Warning Letter Recipients

Binance Headlines List of Japan FSA Warning Letter RecipientsJapan’s Financial Services Agency (FSA) issued a warning letter on Friday stating that several foreign cryptocurrency exchanges have been operating in the country without proper registration, thereby infringing Japan’s fund settlement laws. The regulatory authority specifically named Binance, Bybit, MEXC Global, and Bitget as the entities in question.The FSA indicated that these exchanges need to register with the agency to continue operating in Japan. Failure to comply with the registration requirements would result in enforcement actions by the FSA, which could include the suspension of their operations in the country.©Pexels/David DibertUnregistered digital asset exchangesThe FSA’s warning letter detailed that the cryptocurrency exchanges mentioned had contravened Japan’s fund settlement regulations by engaging in crypto asset exchange operations without proper registration. The regulatory body emphasized that the current list of unregistered traders may not accurately reflect the current state of unregistered businesses in the country.The FSA intends to continue monitoring the market and taking appropriate regulatory measures to protect consumers and the integrity of the financial system. The agency also encouraged all unregistered operators to register with the FSA to avoid any possible enforcement actions.Clamping down on unregistered exchangesThe FSA’s recent action against unregistered cryptocurrency exchanges is in line with the regulatory body’s ongoing efforts to clamp down on non-compliant operators in Japan. In 2020, the FSA introduced new regulations mandating that all crypto exchanges must register with the agency and obtain a license to operate in the country. These regulations were put in place to strengthen consumer protection and enhance the transparency of the cryptocurrency market. By taking these measures, the FSA aims to foster a more stable and secure environment for the burgeoning crypto industry in Japan.The FSA’s warning to Binance is indicative of the growing regulatory scrutiny that the cryptocurrency industry in Japan and other nations is currently facing. Regulators are increasingly concerned about the potential risks associated with unregulated cryptocurrency exchanges, such as fraud, money laundering, and market manipulation. As a result, many regulatory bodies are implementing stricter rules and guidelines to promote transparency, accountability, and consumer protection in the cryptocurrency market.These regulations aim to create a more secure and reliable environment for investors and industry participants. The FSA’s actions against Binance serve as a reminder to all market players that compliance with regulatory requirements is critical for the long-term success of the cryptocurrency industry.Global regulatory variationWhile Japan is taking steps to implement new regulations for the cryptocurrency and Web3 sectors, the country has not been as stringent in its approach as some other major economies, such as the United States. However, this does not mean that regulators in Japan are not actively monitoring the industry and taking appropriate action where necessary.One example of such action is the recent lawsuit filed by the US Commodity Futures Trading Commission against the popular crypto exchange firm, Binance, and its founder, Changpeng Zhao, over regulatory violations. This highlights the fact that regulatory bodies in different parts of the world are taking a more proactive approach to monitoring the cryptocurrency industry.Moreover, the FSA in Japan issued a formal warning letter to Binance in 2021 for operating without the necessary permissions. This is an indication that the regulatory landscape in Japan is evolving, and that crypto exchanges must comply with the relevant regulations to avoid potential legal repercussions. While the severity of regulatory measures may differ across different jurisdictions, the message is clear: compliance is crucial for the long-term viability of the cryptocurrency industry.

news
Web3 & Enterprise·

Jan 17, 2024

Wemade to onboard action RPG Crystals of Naramunz to WEMIX PLAY

Wemade has signed an agreement with Swedish gaming company Crypto Rogue Games to onboard the developer’s blockchain game Crystals of Naramunz to WEMIX PLAY, according to an official press release on Tuesday (KST).Photo by Anas Alshanti on Unsplash“Our collaboration represents a convergence of expertise and creativity,” said Åke Andre, CEO of the development studio. “Crypto Rogue Games is thrilled to announce our partnership with WEMIX PLAY. This marks a significant milestone in our vision to reach the pinnacle of excellence in the Action RPG genre by providing everlasting experiences and value to our players.” Post-apocalyptic funCrystals of Naramunz is an upcoming free-to-play action role-playing game (RPG) set in a post-apocalyptic steampunk world called Naramunz. Players can explore Naramunz, which is characterized by ruins and dungeons, maximize the benefits of their in-game items and skills, and collect and trade in-game assets. The game also features fast and explosive action sequences, character upgrades and a barter economy. Unveiling potentialCrypto Rogue Games recently held an Alpha playtest for Crystals of Naramunz to gather feedback and assess improvements that can be made. A report published on the game’s official Medium page disclosed that reactions were positive, noting strengths and weaknesses of the game in its current stage of development. Crypto Rogue Games is led by a team of industry veterans from various RPG projects like the Path of Exile series and Pillars of Eternity, as well as the strategic simulation game Stellaris.

news
Loading