Top

Poly Network Exploit Results in Billions of Nonexistent Tokens

Web3 & Enterprise·July 04, 2023, 12:01 AM

Poly Network, the China-based interoperability platform, was targeted by hackers over the weekend in a major attack that resulted in the creation of billions of tokens out of thin air. It’s the second time in as many years that the cross-chain bridge has been exploited by hackers.

The attacker exploited a vulnerability in Poly Network’s cross-chain bridge tool, allowing them to generate a substantial number of tokens that previously did not exist, as reported by Arhat, the Founder of 3z3 Labs, on Twitter.

Photo by Shubham Dhage on Unsplash

 

Network suspension

The Shanghai-based project team behind Poly Network promptly informed its users on Sunday that its services were temporarily suspended due to the attack. The platform assured its users that it was diligently assessing the extent of the breach and the impact on assets. They emphasized their commitment to safeguarding users’ assets and urged everyone to remain calm.

The hacker, at one point, held nearly $43 billion worth of cryptocurrency in their digital wallet, according to DeBank, a decentralized finance portfolio tracker. This staggering figure was corroborated by PeckShield, a blockchain data and security firm.

 

Bridge vulnerabilities

Bridges play a crucial role in the Web3 ecosystem, enabling users to transfer assets across different networks. However, they have often been attractive targets for hackers. In this attack on Poly Network, the hackers issued themselves nearly 100 million BNB and $10 billion worth of BUSD, the Binance-branded stablecoin, on the layer-2 network Metis, revealed Colin Wu, a Chinese crypto journalist.

Similarly, on the Heco network, approximately 100 trillion units of the dog-themed meme coin, Shiba Inu, were created. Additionally, a significant number of altcoins were generated on Polygon and Avalanche networks.

 

Illiquid Metis tokens

Metis clarified that the BNB and BUSD tokens issued on its network by the hackers are effectively worthless since there is no available sell liquidity. Poly Network also locked these tokens, ensuring they cannot be utilized. Arhat of 3z3 Labs acknowledged that the impact of the Poly Network attack was somewhat mitigated by the lack of liquidity, which prevented the hackers from realizing substantial gains on Metis.

However, on other networks like Ethereum, the stolen tokens were exchanged on decentralized exchanges. Arhat estimated that the attacker managed to convert only a small portion of the tokens, amounting to approximately $400,000 worth of crypto, while the remaining tokens lacked liquidity and were essentially worthless.

SlowMist, a blockchain security firm, suggested that the hacker’s total gains were higher. They reported that over $4 million worth of digital assets from the attack had been cashed in, including 1,500 Ethereum worth $3 million and 93 billion SHIB worth $700,000.

Poly Network had previously made headlines in 2021 when it experienced a historic attack, considered the largest exploit in decentralized finance at the time. The project suffered a loss of $600 million as funds were siphoned away from Ethereum, Binance Smart Chain, and Polygon. However, the hacker eventually returned $342 million worth of stolen crypto, and Poly Network took steps to repay affected users.

More to Read
View All
Policy & Regulation·

Jul 01, 2025

Kazakhstan establishing national crypto reserve

Kazinform, the state-owned official news agency of Kazakhstan, has reported that the central Asian republic is working towards the establishment of a national crypto reserve. The news agency revealed that in answering an inquiry from a member of the Kazakhstan parliament, Timur Suleimenov, Governor of the National Bank of Kazakhstan, said that the central bank is currently studying information related to the formation and management of a national crypto reserve. Photo by engin akyurt on UnsplashFollowing best international practicePlans are being devised for a crypto reserve on the basis that best international practice as applied to sovereign wealth fund management is adopted. In this respect, guidelines related to transparency of accounting and secure crypto custody will be followed. The reserve will be established through an affiliate entity of Kazakhstan's central bank, specializing in alternative investments. In responding to the parliamentary inquiry, Suleimenov also revealed the likely source of funding for the fund. He stated: “International practice shows that the sources for such a reserve may include confiscated crypto-assets, as well as  cryptocurrencies mined by a crypto miner partially owned by the government.” Suleimenov outlined that while crypto assets have proven to be volatile and riskier than other asset classes, having the reserve controlled and managed by a central bank affiliate would result in the required levels of risk management and overall oversight being applied. According to Kursiv, a news organization focused on the Central Asian region, the authorities in Kazakhstan plan to amend relevant legislation so as to enable the effective management of the crypto reserve. Suleimenov stated that the central bank is open to discussing potential legislative amendments with members of Kazakhstan's parliament. The National Bank of Kazakhstan's governor also warned that misinformation by pseudo-business coaches related to cryptocurrencies needs to be curbed. He feels that in order to protect investors, and particularly young people, legal measures will be necessary in an effort to bring about greater transparency within the country’s crypto market. The authorities in Kazakhstan currently have a crypto regulatory framework in place that requires crypto trading platforms that extend their services to local users to have acquired a trading license from the Astana International Financial Centre (AIFC).  In May, it emerged that the Central Asian republic is planning to establish a pilot project for cryptocurrencies called “CryptoCity.” At the time, Kazakhstan’s president, Kassym-Jomart Tokayev, delivered a speech at the Astana International Forum outlining that the CryptoCity project would facilitate the use of crypto for the payment of goods and services within a specific geographical zone. Crypto hub potentialEarlier that month, the country’s First Vice-Minister of Digital Development, Innovation and Aerospace Industry, Kanysh Tuleushin, said that Kazakhstan had the potential to emerge as a leading cryptocurrency hub within the Central Asian region. Following the implementation of a ban on crypto mining in China in 2021, Kazakhstan experienced an influx of miners, attracted by cheap electricity. However, the arrival of miners was unplanned for, putting extreme pressure on the local electricity grid, resulting ultimately in brownouts and protests. The country once accounted for 27% of global Bitcoin mining. However, regulations introduced in 2023 led to the activity being scaled back considerably.

news
Web3 & Enterprise·

Jan 09, 2024

1st-Generation partners with Tapbit to venture into global blockchain market

1st-Generation, a leading firm in the blockchain sector based in Daegu, South Korea, has signed a memorandum of understanding (MOU) with global cryptocurrency exchange Tapbit, according to an article published by South Korean news outlet Tokenpost on Tuesday (KST). Through this MOU, 1st-Generation expects to further accelerate its growth through active participation and advancement into the global blockchain industry.Photo by Chris Liverani on Unsplash"As the global blockchain industry continues to grow at a rapid pace, we aim to create an ecosystem where we can make a positive impact through cooperation," said Lee Jun-hyuk, CEO of 1st-Generation. Pioneering the future of blockchainWith its advanced technology and outstanding expertise in the blockchain field, 1st-Generation has registered with the Financial Supervisory Service (FSS) under the name "1st Generation Group". The company is focused on providing innovative solutions globally, effectively utilizing blockchain technology based on advanced IT experience. Tapbit’s statisticsFounded in 2021, Tapbit is a global exchange with a user base that exceeds six million users worldwide. In particular, it is currently ranked 38th on CoinMarketCap’s top cryptocurrency derivatives exchange list with a 24-hour derivative trading volume of about $8 billion as of this writing. In addition, it is also working on creating crypto Travel Rule solutions through cooperation with domestic exchanges.

news
Policy & Regulation·

May 17, 2023

Cross Trading of LUNA Tokens Uncovered on Three Korean Crypto Exchanges

Cross Trading of LUNA Tokens Uncovered on Three Korean Crypto ExchangesAccording to a report by the Maeil Business Newspaper on Wednesday, it was discovered that cross trading of LUNA tokens took place on three South Korean cryptocurrency exchanges: Bithumb, Coinone, and GoPax.Three crypto exchangesAn indictment by the Seoul Southern District Prosecutors’ Office against Terraform Labs co-founders Do Kwon and Daniel Shin, along with interviews conducted within the cryptocurrency industry, revealed that Bithumb, Coinone, and GoPax were involved in cross trading LUNA tokens with a combined value of $598 million. Specifically, Bithumb accounted for $224 million, Coinone for $299 billion, and GoPax for $74 billion.The prosecution has confirmed that cross trading continued until the end of February 2022, a period marked by significant demands for virtual asset legislation from both the market and academia. Despite widespread calls for regulations to curb unfair trading practices, these instances of cross trading went undetected.Classification of LUNAMoreover, it is reported that legal punishment for the $598 million worth of cross trading is challenging unless LUNA tokens are officially recognized as securities by the court. Under the Korean Capital Markets Act, only cross trading involving tokens identified as securities can be subject to penalties as a form of market manipulation.During a plenary session of the National Assembly’s Legislation and Judiciary Committee on Tuesday, Justice Minister Han Dong-hoon made a statement suggesting that LUNA tokens could be considered securities due to their backing by real-world assets. However, he said that this distinction might not apply to other tokens.On April 25, the Seoul Southern District Prosecutors’ Office indicted Shin and others as accomplices to Kwon, assuming that LUNA tokens were indeed securities. This case now revolves around whether the prosecution can successfully establish the classification of LUNA tokens as securities during the trial, making it the central issue in the case.Photo by Kanchanara on UnsplashCrypto investor protection legislationLast Thursday, the National Assembly’s National Policy Committee approved a bill known as the “Virtual Assets User Protection Act,” signaling an accelerated legislative process. However, there are arguments suggesting that the definition of cross trading should be further clarified in either the legislation or enforcement decree.A representative of a law firm specializing in virtual assets stated that the implementation of the User Protection Act would take another year even after its promulgation, making it challenging to retrospectively penalize cross trading practices that had already occurred.

news
Loading