{"id":53590,"date":"2023-07-03T05:12:57","date_gmt":"2023-07-03T09:12:57","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=53590"},"modified":"2023-07-03T05:13:00","modified_gmt":"2023-07-03T09:13:00","slug":"poly-network-issues-withdrawal-notice-to-users-after-exploit","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/poly-network-issues-withdrawal-notice-to-users-after-exploit\/","title":{"rendered":"Poly Network Issues Withdrawal Notice to Users After Exploit"},"content":{"rendered":"\n<p><a href=\"https:\/\/coinscreed.com\/staging\/cross-chain-bridge-qubit-loses-80-million-to-hackers.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cross-chain bridge<\/a> platform Poly Network on July 2, was attacked by a hacker, and the exploit affected 57 crypto assets. This has prompted the network to urge users to withdraw their funds.  <\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"900\" height=\"570\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/Poly-Network-hacker-makes-move-to-return-stolen-funds.png\" alt=\"Poly Network Issues Withdrawal Notice to Users After Exploit\" class=\"wp-image-7687\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/Poly-Network-hacker-makes-move-to-return-stolen-funds.png 900w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/Poly-Network-hacker-makes-move-to-return-stolen-funds-300x190.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/Poly-Network-hacker-makes-move-to-return-stolen-funds-768x486.png 768w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><figcaption class=\"wp-element-caption\">Poly Network Issues Withdrawal Notice to Users After Exploit<\/figcaption><\/figure>\n\n\n\n<p>In a tweet dated July 2, Poly Network confirmed it was the latest victim of decentralized finance (DeFi) exploit after attackers were able to manipulate an intelligent contract function on the cross-chain bridge protocol. The company also announced it would temporarily suspend services.<\/p>\n\n\n\n<p>In its most recent update, the team disclosed that 57 crypto assets on ten blockchains, including Ethereum, <a href=\"https:\/\/coinscreed.com\/staging\/bnb-chain-launches-layer-2-solution-testnet.html\" target=\"_blank\" rel=\"noreferrer noopener\">BNB Chain<\/a>, Polygon, Avalanche, Heco, OKX, and Metis, were affected by the exploit.<\/p>\n\n\n\n<p>PeckShield reported that the exploiter had transferred at least $5 million worth of cryptocurrency.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image.png\" alt=\"\" class=\"wp-image-53595\" width=\"683\" height=\"609\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image.png 943w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-300x268.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-768x685.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2023\/07\/image-750x669.png 750w\" sizes=\"(max-width: 683px) 100vw, 683px\" \/><figcaption class=\"wp-element-caption\">Tokens transferred out of Poly Network. Source:\u00a0Twitter\/PeckShield<\/figcaption><\/figure>\n\n\n\n<p>&#8220;We have initiated communication with centralized exchanges and law enforcement agencies and requested their assistance,&#8221; the team reported in an update dated July 3.<\/p>\n\n\n\n<p>It also recommended that project teams and token holders withdraw liquidity and release their liquidity provider tokens.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-34b-poly-network-exploit\">34B Poly Network Exploit <\/h2>\n\n\n\n<p>According to DeFi security analyst Arhat, the exploit resulted from a smart contract flaw that allowed the perpetrator to &#8220;craft a malicious parameter containing a fake validator signature and block header.&#8221;<\/p>\n\n\n\n<p>This was accepted by the smart contract, bypassing the verification process and allowing the perpetrator to issue tokens from Poly Network's Ethereum pool to their address on other chains, including Metis, BNB Chain, and <a href=\"https:\/\/polygon.technology\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Polygon<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>\n\n\n\n<p>The procedure was repeated for other chains, resulting in the accumulation of tokens.<\/p>\n\n\n\n<p>The analyst stated that the hacker's wallet once contained approximately $42 billion worth of tokens, but they could only convert and steal a fraction of them.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cThis way, the hacker was able to mint billions of tokens on various blockchains that did not exist before and transfer them to their own wallet addresses.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Dedaub, a provider of blockchain security solutions, labeled the latest Poly Network exploit a &#8220;34 billion Poly Network hack.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Getting to the bottom of the &quot;34 billion&quot; Poly network hack with a technical postmortem.<br><br>TL ; DR<br><br>Poly network had a simple 3 of 4 multisig arrangement over 2 years!<br><br>Looking at the final event we found that the private keys to the addresses marked were compromised. <a href=\"https:\/\/t.co\/Y0eMJXcYso\" target=\"_blank\">pic.twitter.com\/Y0eMJXcYso<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Dedaub (@dedaub) <a href=\"https:\/\/twitter.com\/dedaub\/status\/1675516729349292032?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 2, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>Dedaub identified flaws in the protocol's multisig, noting that it had a simplistic &#8220;3 of 4&#8221; multi-signature arrangement for two years and adding:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><em>\u201cLooking at the final event we found that the private keys to the addresses marked were compromised.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p>Dedaub described the attack as uncomplicated, as no logic flaws were exploited. It added that Poly Network's response time of seven hours cost the platform $5.5 million in misappropriated cryptocurrency. Fortunately, the lack of liquidity in several tokens averted additional losses.<\/p>\n\n\n\n<p>The CEO of Binance, <a href=\"https:\/\/coinscreed.com\/staging\/binance-founder-changpeng-zhao-says-us-crypto-exchange-will-go-public-in-three-years.html\" target=\"_blank\" rel=\"noreferrer noopener\">Changpeng Zhao<\/a>, reassured customers following the attack by stating, &#8220;This does not impact Binance users. We are unable to accept deposits from this network.&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"embed-twitter\"><blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Poly Network got rekt again; allegedly because of compromised hot keys.<br><br>It&#39;s going to keep happening untill our industry changes our approach to security.<br><br>Smart contract audits only scratch the surface.<br><br>ps Poly network has NOTHING to do with Polygon. <a href=\"https:\/\/t.co\/n1qI48b4Kb\" target=\"_blank\">https:\/\/t.co\/n1qI48b4Kb<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/p>&mdash; Mudit Gupta (@Mudit__Gupta) <a href=\"https:\/\/twitter.com\/Mudit__Gupta\/status\/1675584195798913024?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener\">July 2, 2023<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><use href=\"#wpil-svg-outbound-7-icon-path\"><\/use><\/svg><\/span><\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/div>\n<\/div><\/figure>\n\n\n\n<p>The Poly Network was attacked in August 2021 in one of the industry's largest-ever exploits. Over $600 million was stolen by hackers, who were revealed to be affiliated with the North Korean hacking group Lazarus Group.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cross-chain bridge platform Poly Network on July 2, was attacked by a hacker, and the exploit affected 57 crypto assets. This has prompted the network to urge users to withdraw their funds. In a tweet dated July 2, Poly Network confirmed it was the latest victim of decentralized finance (DeFi) exploit after attackers were able [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":7687,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11476],"tags":[10417,2118,2117,1929],"class_list":["post-53590","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacks-and-scams","tag-expliot-2","tag-hacker","tag-poly-network","tag-withdrawals"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2021\/08\/Poly-Network-hacker-makes-move-to-return-stolen-funds.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/53590","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=53590"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/53590\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/7687"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=53590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=53590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=53590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}