Cross-Chain Poly Network Exploited for the Second Time, Millions of Dollars Stolen

Published on

numen cyber focuses on Web3 Security and Threat Detection and Response. They provide industry-leading Web3 Security Solutions, which
can completely cover cybersecurity requirements of all kinds.

Cross-chain bridge protocol Poly Network is still reeling this week after suffering an exploit last Sunday, which saw at least $5m worth of cryptocurrency from 10 different blockchains (including Ethereum, Avalanche and others) siphoned to the attacker’s wallet.

It was reported that at one point the attacker’s wallet actually contained an eye-watering $42bn worth of tokens, however due to the nature of the exploit, a tiny portion of this sum could actually be extracted.

The attacker used a fake validator signature to trick the platform’s smart contract into signing the transaction and, worryingly, blockchain security firms have described the exploit technique as “simple”.

While nowhere near the value of the previous hack – this is the second time that Poly Network has been exploited in the past two years.

In 2021, the network was exploited by the infamous Lazarus Group for around $610m worth of tokens – and this second exploit may be further harming the chain’s reputation.

The operators of Poly Network have advised users to withdraw their tokens for the time being – which has caused the platform’s total value locked to drop by more than 36% since the attack.

(About Poly Network)

Poly Network is a decentralized finance (DeFi) platform that facilitates interoperability between various blockchain networks. It aims to overcome the limitations of siloed blockchains by creating a seamless environment for the transfer of digital assets across different networks. One of the key features of Poly Network is its ability to enable cross-chain asset transfers without the need for a central authority. This decentralized approach ensures that users have complete control over their assets and eliminates the need for intermediaries. In 2021 however, Poly Network fell victim to a huge exploit, which saw more than $600m drained from the platform. That hasn’t stopped the platform’s development, and Poly Network remains a popular protocol.

Image

Latest articles

SEC Takes First Enforcement Measure Against NFTs Regulatory Body Concludes Impact Theory’s NFTs Were Marketed as Unregistered Securities

U.S. regulatory authorities have mandated a Los Angeles company, which had previously issued non-fungible tokens (NFTs), to provide compensation to investors who had procured the aforementioned NFTs.

Binance Cuts Ties with Sanctioned Russian Banks Amid Regulatory Compliance Efforts

Binance has severed its affiliations with five Russian banks that were under sanctions, having been previously featured on the exchange's peer-to-peer platform for ruble fund transfers, the native currency of Russia.

Former OpenSea Employee Receives Three-Month Sentence in First NFT Insider Trading Lawsuit

A former employee of the NFT marketplace OpenSea has been sentenced to three months in prison on Tuesday in what federal prosecutors have characterized as the first case of insider trading involving digital tokens.

Crypto Market Takes a Dive, Bitcoin Slumps to Two-Month Low Amid Rate-Hike Concerns

In a dramatic turn of events on Thursday's early afternoon trading session, the cryptocurrency market witnessed a substantial downturn, plunging to its lowest point in two months.

More like this

SEC Takes First Enforcement Measure Against NFTs Regulatory Body Concludes Impact Theory’s NFTs Were Marketed as Unregistered Securities

U.S. regulatory authorities have mandated a Los Angeles company, which had previously issued non-fungible tokens (NFTs), to provide compensation to investors who had procured the aforementioned NFTs.

Binance Cuts Ties with Sanctioned Russian Banks Amid Regulatory Compliance Efforts

Binance has severed its affiliations with five Russian banks that were under sanctions, having been previously featured on the exchange's peer-to-peer platform for ruble fund transfers, the native currency of Russia.

Former OpenSea Employee Receives Three-Month Sentence in First NFT Insider Trading Lawsuit

A former employee of the NFT marketplace OpenSea has been sentenced to three months in prison on Tuesday in what federal prosecutors have characterized as the first case of insider trading involving digital tokens.