Why Was $610 Million Returned?
The story of cryptocurrency attacks usually unfolds similarly: a vulnerability is found, assets are transferred to other addresses, and the attacker tries to cover their tracks.
In the Poly Network attack, however, the event ended unexpectedly.
On August 10, 2021, an attacker exploited a vulnerability in the Poly Network, which allows asset transfers between different blockchain networks, transferring approximately $610 million worth of crypto assets to addresses under their control.
At the time, this event was recorded as one of the largest attacks in the history of decentralized finance. However, just one day after the attack, a portion of the assets began to be returned.
By August 23, all affected assets had been recovered.
So why would an attacker return hundreds of millions of dollars worth of assets they had gained control of?
What Was Poly Network?
Poly Network was a cross-chain protocol that allowed users to move crypto assets between different blockchain networks.
When a user wanted to transfer assets from Ethereum to another blockchain network, Poly Network's smart contracts checked the instructions transmitted between the chains and ensured the transaction was completed on the other network.
The attacker exploited an authority management issue between the two key smart contracts managing these transactions.
Simply put, the attacker managed to change the control mechanism the system used to recognize authorized transactions. The transfer instructions they created were thus accepted by the system as valid transactions.
Assets on Ethereum, Binance Smart Chain, and Polygon were transferred to different addresses belonging to the attacker.
More detailed information about the technical structure of the attack can be found in Reuters' attack analysis and CertiK's technical review.
Were the Assets Actually Returned?
Yes, but this process didn't happen all at once.
The attacker began returning the assets on August 11, 2021. According to Chainalysis data, as of August 12, approximately $578.6 million worth of crypto assets had been returned to Poly Network.
Approximately $33.4 million worth of USDT remained. These assets were unusable by the attacker because Tether had frozen the USDT associated with the attack shortly afterward.
On August 23, the attacker shared the private key necessary to access the co-controlled wallet containing the remaining assets. Poly Network thus regained control of the remaining assets, including ETH and WBTC.
Following Tether's release of the frozen USDT, Poly Network announced on August 23, 2021, that all assets affected by the attack had been recovered.
Details of the process are included in Poly Network's incident report, Chainalysis's analysis, and a Reuters news report.
Why Did the Attacker Return the Money?
In messages added to the blockchain transactions, the attacker stated that their intention was not to profit from the attack.
He claimed he wanted to expose the vulnerability before someone else could exploit it, that he saw the attack as a challenge, and that he had planned to return the assets from the beginning.
However, the veracity of this statement was never definitively proven.
According to security experts, there may have been a more practical reason for the return: moving or cashing out such a large amount of cryptocurrency without being detected was extremely difficult.
The addresses used by the attacker were quickly identified. All transfers on the blockchain are openly tracked, and cryptocurrency companies and exchanges are warned about the relevant addresses.
Tether's freezing of $33.4 million worth of USDT also showed the attacker that assets controlled by centralized institutions could not be easily used.
According to Chainalysis, the transparency of blockchain transactions meant that the attacker's movement of funds was immediately noticeable. Trying to cash out hundreds of millions of dollars worth of assets by sending them to exchanges could significantly increase the risk of his identity being revealed.
In short, it was possible to obtain the money, but using it securely and without detection was much more difficult.
Was “Mr. White Hat” Truly an Ethical Hacker?
Poly Network communicated with the attacker via messages embedded in blockchain transactions, referring to him as “Mr. White Hat.”
The company subsequently offered the attacker a $500,000 security reward and a security consulting role. However, the attacker began returning the assets before this offer was made.
Therefore, it cannot be said that the money was returned solely in exchange for the reward.
Nevertheless, responsibly reporting a security vulnerability is not the same as transferring users' assets to other addresses without authorization. Although the assets were later recovered, the attack put thousands of users at serious risk.
The Poly Network attack is therefore still a controversial event.
Was the attacker truly a security researcher trying to protect the system, or did he realize he couldn't use the compromised assets and create a safer escape route for himself?
The definitive answer to this question was never known.
However, the event demonstrated an important truth to the blockchain world: Seizing an asset and being able to use it undetected are not the same thing.
The Poly Network attacker managed to gain control of approximately $610 million worth of assets. However, storing, transporting, and converting these assets to cash became a much more difficult problem with the entire industry under scrutiny.
The blockchain's transparency didn't prevent the attack, but it severely restricted the attacker's freedom of movement and played a significant role in recovering the stolen assets.
Disclaimer
This content is for general informational purposes only and does not constitute technical, investment or cybersecurity advice.