• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

Poly Network Exploiter Starts Returning the Funds, Asks For Donations

August 11, 2021
in Crypto News
Reading Time: 7min read
0 0
A A
0
Poly Network Exploiter Starts Returning the Funds, Asks For Donations
0
SHARES
2
VIEWS
ShareShareShareShareShare

Source: iStock/paisan191

The hacker of the decentralized finance (DeFi) interoperability protocol Poly Network, that just lost over USD 600m, first asked the protocol for a multi-signature (multisig) wallet to return the funds – and has started returning it.

According to Tom Robinson, the chief scientist and co-founder of the blockchain data tracker Elliptic, USD 258m has been returned so far, while the hacker “is also asking for donations, as a reward for doing the right thing.”

After seemingly having some fun with messages asking if a community vote should decide on where the stolen funds should go, the attacker wrote “READY TO RETURN THE FUND!” – as it stands in the comment attached to a transaction executed by the address marked as ‘PolyNetwork Exploiter’. It’s not clear, however, if the hacker was planning on returning all the stolen funds.

But then this confusing soup of a situation thickened.

Poly Network had already posted a letter to the hacker threatening them with law enforcement and stating that the money they took in “the biggest [hack] in the [Defi] history” belongs to the people.

And despite apparently wanting to return the funds hours later, in another transaction, the hacker said: “FAILED TO CONTACT THE POLY. I NEED A SECURED MULTISIG WALLET FROM YOU.”

Hacker: “IT’S ALREADY A LEGEND TO WIN SO MUCH FORTUNE. IT WILL BE AN ETERNAL LEGEND TO SAVE THE WORLD. I MADE THE DECISION, NO MORE DAO”

0xd239b01026c49b234d075e3d23a07efd1c3234239cfb440c0f90d5e84836fbe2 pic.twitter.com/yDc2BwBiO2

— harry.eth (@sniko_) August 11, 2021

Later today, the protocol shared the addresses to which the funds can be returned.

As reported, Poly Network suffered a massive exploit yesterday, seeing the attacker taking off with more than USD 600m. The attack happened on Binance Smart Chain (BSC), Ethereum (ETH), and Polygon (MATIC).

The address on Etherscan, marked as “reported to be involved in a PolyNetwork exploit,” contains USD 183m worth of ERC-20 tokens at the time of writing. Polygonscan shows more than USD 85m, and the BscScan address has around USD 133m.

It is still not clear what exactly happened behind this hack. There are even opinions that it was inside job, though many disagree.

The blockchain security specialist Xiamen SlowMist Technology wrote that “the core of this attack is that the verifyHeaderAndExecuteTx function of the EthCrossChainManager contract can execute specific cross-chain transactions through the _executeCrossChainTx function.” The attacker replaced the address of the keeper role, constructed a transaction at will, and was able to withdraw any amount of funds from the contract.

Similarly, researcher Kelvin Fichter opined that there is a “critical flow” in Poly Network contract called the ‘EthCrossChainManager’.

just setting up my twttr

— jack⚡️ (@jack)

An engineer who goes by the name ‘El Doggo Diablo’ stressed that the crypto space suffers from “an extreme lack of software security processes.”

Meanwhile, there are reports that quite a few individuals and funds in China, where this and related projects are said to be popular, have been affected by the hack. Investor Michael Gu (a.k.a. ‘Boxmining’) claimed to have been a victim himself, stating that there is nothing he can do about it now.

“The Poly Network hack shows that while cross-chain tech is certainly progressing, it appears to be two steps forward and one step back. Most beta launches are disclaimed such that sending large amounts to un-audited smart contracts is ill-advised by the protocol teams. Still, many investors can’t wait to barge through the gates in order to do a quick 10x flip,” Kay Khemani, Managing Director at Spectre.ai, a broker-less trading platform, said.

“The crypto world has two philosophical camps. The Bitcoin world moves slowly and cautiously with an emphasis on security. The other camp has embraced a “move fast and break things” approach. The most obvious examples of this are in the frequent hacks we hear about – Bitcoin DeFi has yet to experience any such hacks,” Edan Yago, Contributor to the Bitcoin-based Defi protocol Sovryn, said in an emailed comment.

According to him, the difference goes even deeper, with many projects outside of Bitcoin sacrificing decentralization and opening the door to capture by elites.

‘Send me money’

Nearly immediately post-attack, there appeared quite a few of those who were sending messages and/or congratulating the hacker, in hopes that they’d get a tip.

Such comments on Etherscan seem to have been marked as spam. Some still remain though. For instance, Omaz Z Khan said: “Dude, just get all the cryptopunks that you can. SPARE me some eth or just one punk 🙂 Il be indebted.”

“Pls airdrop some fund to us, we are suffering year long due to COVID, thanks in advance,” said ‘meow chia’. User ‘chanlaka’ wrote a longer post, stating that they lost their parents and are only left with their ill younger sister for whom they need to pay the hospital bills.

‘SumYungGuy’ shared a larger post on, basically, how to get away with the money.

“bro just airdrop to all help all people!,” simply wrote ‘justin wong’ who took a more egalitarian approach to the situation.

It even seems that many people have decided to send the attacker bits of their ETH or other currency with messages, apparently hoping to get a lot more in return. “i sent you a tiny bit of matic maybe itll get your attention :/ please change my life,” commented ‘TheBluntsLit,’ who has written quite a few praises.

And the person who was reported to have received an ETH 13.37 (USD 42,930) tip, seems to have had some fun as well.

All txs are some permutation of 1337. Used 133.713371337 Gwei for Gas.

Uses MrGorbachevTearDownThatWall.txt as the message.

Yeah, hanashiro definitely some 4chan turbo degen just entertaining us. pic.twitter.com/fSBkuu1uMb

— Hsaka (@HsakaTrades) August 10, 2021

____

Other reactions:

For anyone still confused, here’s the hack depicted as a beautiful gif pic.twitter.com/Shg5Tdf21Z

— God-like Natural Number Creator Person (TM, R) (@kelvinfichter) August 10, 2021

__

Chinese Blogger Chaojijun: I consulted USDT, USDC and BSC for the first time. USDT was frozen. The CEO of USDC said… https://t.co/YTzuoOzaTn

— Wu Blockchain (@WuBlockchain)

__

scary to see another half a billion of $US is put in unaudited contracts https://t.co/Ri7hsZaFGP

— Loi ThΞ Luu (@loi_luu)

__

just setting up my twttr

— jack⚡️ (@jack)

__

How many more hacks does it take for you to move it all to $BTC? 2, 3, 5, 20, 100, yours? https://t.co/jCAjEBypph

— Bitcoin Fool PhD (@bitcoinfool)

__

savage thread from jedi master dev @fubuloubu on what works and what doesn’t for improving tech security/reliabilit… https://t.co/WJx1dlkees

— _gabrielShapir0 (@lex_node)

__

The hacker wants to return the funds. #

— Ran Neuner (@cryptomanran)

____

Learn more:
–
RUNE Recovers 11% After Crash and Thorchain USD 8M Hack
– Holding The World To Ransom: Top 5 Online Gangs

– South Korean Politician: North Has Stolen USD 310M in Crypto Since 2019
– Another Two Binance Smart Chain Projects Suffer Flash Loan Attacks
___
(Updated at 15:15 UTC with the latest data about the returned funds. Updated at 15:21 UTC with additional comments.)


Credit: Source link

ShareTweetSendPinShare
Previous Post

South Korea’s Top Remittance Payment Company Global Money Express Joins RippleNet to Expand Payments into Thailand

Next Post

Bank of Jamaica Mints First Tranche of CBDC

Next Post
Bank of Jamaica Mints First Tranche of CBDC

Bank of Jamaica Mints First Tranche of CBDC

You might also like

Bonk Unleashes First On-Chain Arcade Shooter, Letting Players Win Tokens

Bonk Unleashes First On-Chain Arcade Shooter, Letting Players Win Tokens

June 3, 2025
Alchemy Pay Comes to Australia with PayID Integration and AUSTRAC Approval

Alchemy Pay Comes to Australia with PayID Integration and AUSTRAC Approval

May 28, 2025
Solana (SOL) Hints at Bearish Shift: Is Drop on The Horizon?

Solana (SOL) Continues to Fall — Is a Reversal in Sight?

June 2, 2025
Bitcoin Rise To $111,000 ATH Doesn’t Mean The Market Is Bullish, Certified Expert Says

Bitcoin Rise To $111,000 ATH Doesn’t Mean The Market Is Bullish, Certified Expert Says

June 2, 2025
Bitcoin Addresses Holding Between 100 and 10,000 BTC Hit a 7-Week High

AI-Powered Interactivity Transforms Australia’s National Communication Museum

June 3, 2025

Can Dogecoin Price Still Rally 1,000%? Analyst Reveals End-of-Year Prediction

May 31, 2025
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

HKMA Adjusts Countercyclical Measures for Property Mortgage Loans

Hong Kong Monetary Authority Sets 3.50% Interest Rate for 2027 Retail Infrastructure Bonds

June 4, 2025
Bitcoin Price Takes a Breather: Gains Reduced Amid Volatility

Bitcoin Price Encounters Resistance — Traders Eye Breakout or Rejection

June 4, 2025

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Heart NumberHeart Number(HTN)$0.000000-30.47%
  • TadpoleTadpole(TAD)$0.000000-1.76%
  • SEENSEEN(SEEN)$0.000000-2.27%
  • EvedoEvedo(EVED)$0.000000-0.80%
  • MarginswapMarginswap(MFI)$0.000000-2.17%
  • SakeTokenSakeToken(SAKE)$0.0000004.37%
  • WTF TokenWTF Token(WTF)$0.0000000.16%
  • BNSD FinanceBNSD Finance(BNSD)$0.000000-5.83%
  • RobotinaRobotina(ROX)$0.00000038.50%
  • CageCage(C4G3)$0.000000-3.67%