Cryptocurrency Heist: How Hackers Stole $613 Million in Digital Tokens From Poly Network

Poly Network is a decentralised finance (DeFi) platform that facilitates peer-to-peer transactions.

Advertisement
Updated: 12 August 2021 18:06 IST
Highlights
  • The hacker or hackers has not yet been identified
  • SlowMist said the heist was likely to be long-planned
  • The attackers stole funds in more than 12 different cryptocurrencies

A lesser-known name in the world of cryptocurrency, Poly Network is a decentralised finance

Hackers pulled off the biggest ever cryptocurrency heist on Tuesday, stealing $613 million (roughly Rs. 4,550 crores) in digital coins from token-swapping platform Poly Network, only to return  $342 million (roughly Rs. 2,540 crores) worth of tokens less than 24 hours later, the company said. Here's what we know so far about the heist.

What is Poly Network?

A lesser-known name in the world of cryptocurrency, Poly Network is a decentralised finance (DeFi) platform that facilitates peer-to-peer transactions with a focus on allowing users to transfer or swap tokens across different blockchains.

Advertisement

It was not immediately clear from Poly Network's website where the platform is based or who runs it. According to specialist crypto website Coindesk, Poly Network was launched by the founders of Chinese blockchain project Neo.

Advertisement

How did hackers steal the tokens?

Poly Network operates on the Binance Smart Chain, Ethereum and Polygon blockchains. Tokens are swapped between the blockchains using a smart contract which contains instructions on when to release the assets to the counterparties. Ethereum price in India stood at Rs. 2.4 lakhs as of 6pm IST on August 12. 

Advertisement

One of the smart contracts that Poly Network uses to transfer tokens between blockchains maintains large amounts of liquidity to allow users to efficiently swap tokens, according to crypto intelligence firm CipherTrace.

Poly Network tweeted on Tuesday that a preliminary investigation found the hackers exploited a vulnerability in this smart contract.

Advertisement

According to an analysis of the transactions tweeted by Kelvin Fichter, an Ethereum programmer, the hackers appeared to override the contract instructions for each of the three blockchains and diverted the funds to three wallet addresses, digital locations for storing tokens. These were later traced and published by Poly Network.

The attackers stole funds in more than 12 different cryptocurrencies, including ether and a type of bitcoin, according to blockchain forensics company Chainalysis.

A person claiming to have perpetrated the hack said they had spotted a "bug," without specifying, and that they wanted to "expose the vulnerability" before others could exploit it, according to digital messages posted on the Ethereum network published by Chainalysis. Reuters could not verify the authenticity of the messages.

Where did the money go?

As of late Wednesday, the hackers had returned  $342 million (roughly Rs. 2,540 crores) of the assets, Poly Network said, but $353 million (roughly Rs. 2,620 crores) was outstanding. It is unclear where the remaining assets have gone.

Coindesk reported on Tuesday that the hackers had tried to transfer assets including tether tokens from one of the three wallets into liquidity pool Curve.fi, but that transfer was rejected. About $100 million (roughly Rs. 740 crores) has been moved out of another of the wallets and deposited into liquidity pool Ellipsis Finance, Coindesk also reported.

Curve.fi. and Ellipsis Finance could not immediately be reached for comment.

Who is the hacker?

The hacker or hackers has not yet been identified.

Cryptocurrency security firm SlowMist said on its website that it has identified the attacker's mailbox, internet protocol address, and device fingerprints, but the company has not yet named any individuals. SlowMist said the heist was "likely to be a long-planned, organised and prepared attack."

Despite the purported hacker posing as a so-called "white hat", an ethical hacker who aimed to identify the vulnerability for Poly Network and had "always" planned to give the money back, according to the messages published by Chainalysis, some crypto experts are skeptical.

Gurvais Grigg, chief technology officer at Chainalysis and former FBI veteran, said it was unlikely that white hat hackers would steal such a large sum. He said they had probably returned some of the funds because it had proved too difficult to convert them into cash.

"It's hard to know the motivation ... Let's see the if they return the whole amount," he added.

© Thomson Reuters 2021


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Poly Network, Cryptocurrency

Popular Stores

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus 15s Visits BIS Certification Website; Could Launch in India Soon
  2. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  3. OnePlus Watch Lite With Up to 10 Days Battery Life Launched: See Price
  4. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  5. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  6. Apple's Foldable iPhone Could Resemble This iPad Model When Unfolded
  7. Vivo V70 Stops By US FCC Database Along With RAM and Storage Details
  8. Nvidia's GeForce RTX 50 Series GPUs Are About to Be Scarce
  9. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan
  10. Infinix Xpad Edge With 13.2-Inch Display, 8,000mAh Battery Launched
  1. Samsung Exynos 2600 Details Leak Ahead of Galaxy S26 Launch; Could Be Equipped With 10-Core CPU, AMD GPU
  2. Vivo Y50e 5G, Vivo Y50s 5G Appear on Google Play Console; Mysterious Vivo Phone Listed on Certification Site
  3. Nvidia to Reportedly Cut GeForce RTX 50 Series GPU Production Amid Global RAM Shortage
  4. Apple Allows Third-Party App Stores, Relaxes Payment Restrictions in Japan to Comply With MSCA Act
  5. Hogwarts Legacy Has Sold 40 Million Copies, Warner Bros. Games Announces
  6. OnePlus 15s Listing on BIS Certification Website Hints at Imminent Launch in India
  7. Infinix Xpad Edge Launched With 13.2-Inch Display, 8,000mAh Battery: Price, Specifications
  8. Ethirneechal Thodargiradhu Now Streaming on SunNXT: What You Need to Know
  9. The Villainess Is Adored by the Prince of the Neighbor Kingdom OTT Release Date: Know When and Where to Watch This Japanese Anime Series Online
  10. Easygoing Defense by the Optimistic Lord Anime to Stream on Crunchyroll in January 2026
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.