{"investigation":{"slug":"poly-network","entity_name":"Poly Network","trust_score":10,"severity_base":null,"score_modifier":0,"confidence":0.92,"status":"published","content_type":"investigation","summary":"Poly Network was a cross-chain interoperability protocol launched in August 2020 by Neo, Ontology, and Switcheo. It suffered the largest DeFi hack in history in August 2021 (~$611M stolen, nearly all returned), followed by a second exploit in July 2023 (~$10M realized losses) attributed to compromised multisig private keys. The protocol permanently shut down all services on September 30, 2024.","sections":[{"content":"Poly Network is a cross-chain interoperability protocol that was launched on August 18, 2020. Its founding members included the Neo, Ontology, and Switcheo blockchain ecosystems. The protocol was designed to enable asset transfers across heterogeneous blockchains including Ethereum, BNB Chain, Polygon, Avalanche, and others, without issuing its own native token. By the time of its first major exploit in 2021, the protocol had facilitated over $3.3 billion in cross-chain asset transfers across 18,000+ addresses. The project maintained close ties to the O3 Labs team — the development group behind the O3 Wallet, which originated in the Neo community in 2017. Poly Network did not publish the identities of its core development team publicly; its founders operated largely through the parent organization structure shared with Neo.","heading":"Overview and Background","sources":[{"url":"https://neo.org/blog/details/4207","name":"neo.org","type":"other","credibility":3},{"url":"https://phemex.com/academy/what-is-poly-network","name":"phemex.com","type":"other","credibility":3},{"url":"https://cointelegraph.com/magazine/shanghai-man-poly-network-hacking-shows-how-divided-the-eastern-and-western-crypto-communities-still-are/","name":"cointelegraph.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On August 10, 2021, an unknown attacker exploited a critical access control vulnerability in Poly Network's smart contracts, stealing approximately $611 million in cryptocurrency — the largest DeFi hack recorded at that time. Assets were drained across three chains: approximately $273 million in ETH-based tokens on Ethereum, $253 million on Binance Smart Chain, and $85 million in USDC on Polygon. The attacker transferred funds to three controlled wallet addresses.\n\nThe root technical cause was an improper access control relationship between two core smart contracts: EthCrossChainManager and EthCrossChainData. The EthCrossChainManager contract contained a function called verifyHeaderAndExecuteTx which could execute arbitrary user-supplied calldata. The attacker exploited this to invoke the PutCurEpochConPubKeyBytes function on EthCrossChainData, effectively replacing the legitimate 'keeper' public keys with their own address. This gave the attacker full authority to authorize and execute outbound token transfers, draining Poly Network's liquidity pools.\n\nSecurity firm SlowMist claimed shortly after the attack to have identified the attacker's IP address, email, and device fingerprints, though these claims were not independently verified and no criminal charges followed.\n\nThe three attacker-controlled addresses on Ethereum, BSC, and Polygon were publicly identified by on-chain analysts within hours of the exploit.","heading":"August 2021 Hack — Largest DeFi Exploit in History","sources":[{"url":"https://www.coindesk.com/markets/2021/08/10/cross-chain-defi-site-poly-network-hacked-hundreds-of-millions-potentially-lost","name":"coindesk.com","type":"other","credibility":3},{"url":"https://www.chainalysis.com/blog/poly-network-hack-august-2021/","name":"chainalysis.com","type":"other","credibility":3},{"url":"https://www.halborn.com/blog/post/explained-the-poly-network-hack-august-2021","name":"halborn.com","type":"other","credibility":3},{"url":"https://research.kudelskisecurity.com/2021/08/12/the-poly-network-hack-explained/","name":"research.kudelskisecurity.com","type":"other","credibility":3},{"url":"https://slowmist.medium.com/the-root-cause-of-poly-network-being-hacked-ec2ee1b0c68f","name":"slowmist.medium.com","type":"other","credibility":3},{"url":"https://www.certik.com/resources/blog/HPJ3e0qAWPErSPdGeMXg1-poly-network-exploit","name":"certik.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Beginning on August 11, 2021 — just one day after the theft — the attacker began voluntarily returning stolen funds, communicating via embedded notes in on-chain transactions. The attacker claimed the theft was conducted 'for fun' and that it was 'always the plan' to return the funds, asserting they wished to expose vulnerabilities rather than profit from them.\n\nPoly Network responded by publicly addressing the attacker as 'Mr. White Hat' and, as assets were restored, offered the attacker a $500,000 bug bounty reward and the position of 'chief security advisor' of the protocol. By August 13, approximately $340 million had been returned. The final tranche of funds was returned by August 25, 2021, with the exception of $33.4 million in USDT which had been frozen by Tether Ltd. immediately following the hack.\n\nThe decision by Poly Network to retroactively brand the attacker as a 'white hat' drew significant criticism from the cybersecurity community. Security professional Katie Paxton-Fear stated that 'labelling this hack as a white hat is really disappointing.' Former DOJ and FBI official Charlie Steele noted that 'private companies have no authority to promise immunity from criminal prosecution.' Critics argued this framing could set a dangerous precedent normalizing criminal theft of digital assets, provided funds were eventually returned. The hacker declined the $500,000 bounty. No law enforcement agency publicly identified the attacker or filed criminal charges related to the 2021 incident.","heading":"Fund Return and Controversial 'Mr. White Hat' Framing","sources":[{"url":"https://cointelegraph.com/news/poly-network-hacker-returns-nearly-all-funds-refuses-500k-white-hat-bounty","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://www.cnbc.com/2021/08/23/poly-network-hacker-returns-remaining-cryptocurrency.html","name":"cnbc.com","type":"other","credibility":3},{"url":"https://en.wikipedia.org/wiki/Poly_Network_exploit","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://protos.com/poly-network-white-hat-offers-500k-once-crypto-returned/","name":"protos.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On July 2, 2023, Poly Network suffered a second major exploit. The attacker leveraged a vulnerability to mint tokens across 57 different crypto assets on 10 blockchains — including Ethereum, BNB Chain, Polygon, Avalanche, Metis, and Optimism — notionally creating tens of billions of dollars in unauthorized token issuance. The on-paper value of tokens minted was reported at approximately $34–$43 billion, though realized losses were constrained by pool liquidity. Security firm Beosin estimated actual losses at approximately $10 million in ETH and other liquid assets successfully swapped or extracted by the attacker; PeckShield estimated over $5 million was moved from Ethereum, Polygon, and BNB Chain.\n\nPost-incident analysis by blockchain security firm Dedaub concluded that the most likely root cause was the compromise of private keys belonging to three of four keeper addresses in Poly Network's multisig governance arrangement. Poly Network's cross-chain bridge was secured by a 3-of-4 multisig, meaning that if three keeper keys were compromised, an attacker could authorize arbitrary state changes. Dedaub noted: 'Poly Network had a simple 3 of 4 multisig arrangement over 2 years — which is incredibly risky.' The firm found that the maliciously crafted state root submitted in the exploit was correctly signed by 3 of 4 keeper addresses, indicating the key material itself was compromised rather than a logical contract flaw.\n\nPoly Network's own post-incident report attributed the exploit to a Trojan virus implanted in the program compilation environment, alleging attackers acquired consensus keys by compromising the relay chain build pipeline — a supply chain attack vector. The possibility of an insider threat or rug pull could not be fully excluded by independent analysts, though no direct evidence of insider involvement was published. Poly Network suspended all services immediately following the incident and urged users to withdraw assets.","heading":"July 2023 Hack — Second Exploit and Compromised Multisig","sources":[{"url":"https://www.halborn.com/blog/post/explained-the-poly-network-hack-july-2023","name":"halborn.com","type":"other","credibility":3},{"url":"https://dedaub.com/blog/poly-network-hack/","name":"dedaub.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/237452/attacker-pockets-10-million-from-poly-network-security-attack-beosin","name":"theblock.co","type":"other","credibility":3},{"url":"https://decrypt.co/147059/poly-network-attack-conjures-billions-of-dollars-in-tokens-that-did-not-exist","name":"decrypt.co","type":"other","credibility":3},{"url":"https://www.coindesk.com/tech/2023/07/02/polynetwork-attacker-issues-worthless-billions-in-shib-bnb-busd-in-latest-crypto-hack","name":"coindesk.com","type":"other","credibility":3},{"url":"https://therecord.media/crypto-platform-poly-network-suspends-service-after-hack","name":"therecord.media","type":"other","credibility":3},{"url":"https://polynetwork.medium.com/the-poly-network-exploit-analysis-b0a77aff6078","name":"polynetwork.medium.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Poly Network's core smart contracts — including EthCrossChainData, EthCrossChainManager, UpgradableECCM, EthCrossChainManagerProxy, ECCUtils, LockProxy, Swapper, and SwapProxy — had undergone security audits prior to the August 2021 hack, including a review by BlockSec. Despite these audits, the critical access control flaw that enabled the 2021 exploit went undetected. Following the 2021 hack, Poly Network announced a $500,000 bug bounty program hosted on the Immunefi platform, offering up to $100,000 for critical vulnerability disclosures.\n\nThe July 2023 hack occurred approximately two years after the first exploit, suggesting that while the smart contract layer was hardened, the off-chain governance infrastructure — specifically the keeper key management and multisig arrangement — was not adequately secured. Operating a 3-of-4 multisig for a protocol handling hundreds of millions of dollars in cross-chain liquidity over a two-year period, without apparent rotation or hardware security module protection for keys, represents a significant governance and operational security failure.","heading":"Security Posture and Audit History","sources":[{"url":"https://blocksec.com/audit-report/security-audit-report-for-poly-contracts","name":"blocksec.com","type":"other","credibility":3},{"url":"https://www.vidma.io/blog/poly-network-hack-a-611-million-lesson-in-smart-contract-vulnerabilities","name":"vidma.io","type":"other","credibility":3},{"url":"https://dedaub.com/blog/poly-network-hack/","name":"dedaub.com","type":"other","credibility":3}],"severity":"medium"},{"content":"On September 11, 2024, Poly Network announced the complete termination of all its services, effective September 30, 2024. The announcement cited 'the changing market landscape' as the stated reason, without providing additional detail. The notice did not include specific guidance on how users could withdraw remaining assets or a detailed transition process. This marked the permanent shutdown of the Poly Bridge cross-chain service and all associated infrastructure. As of the shutdown date, Poly Network is no longer operational.","heading":"Service Termination","sources":[{"url":"https://polynetwork.medium.com/notice-of-complete-termination-of-poly-network-services-3470ef78d9d9","name":"polynetwork.medium.com","type":"other","credibility":3},{"url":"https://neonewstoday.com/development/poly-network-announces-complete-termination-of-all-services/","name":"neonewstoday.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Poly Network carries several compounding risk flags across its operational history. First, it suffered two separate major security incidents within two years: the August 2021 $611M exploit and the July 2023 exploit resulting in ~$10M realized losses. Second, the 2023 hack revealed that the protocol's off-chain keeper infrastructure had operated on a static 3-of-4 multisig for two years without documented key rotation — an operational security practice inconsistent with the level of funds under management. Third, Poly Network's public framing of the 2021 attacker as 'Mr. White Hat' and its offer of a $500,000 bounty and advisory role was widely criticized by security professionals as potentially normalizing criminal behavior. Fourth, the protocol's core development team operated with limited public accountability, with founders not publicly identified and organizational structure dispersed across affiliated entities including Neo and O3 Labs. Fifth, the protocol shut down with limited transparency and minimal user guidance, citing only vague market conditions.","heading":"Risk Flags and Community Concerns","sources":[{"url":"https://en.wikipedia.org/wiki/Poly_Network_exploit","name":"en.wikipedia.org","type":"other","credibility":3},{"url":"https://dedaub.com/blog/poly-network-hack/","name":"dedaub.com","type":"other","credibility":3},{"url":"https://therecord.media/crypto-platform-poly-network-suspends-service-after-hack","name":"therecord.media","type":"other","credibility":3},{"url":"https://cointelegraph.com/news/poly-network-hacker-returns-nearly-all-funds-refuses-500k-white-hat-bounty","name":"cointelegraph.com","type":"other","credibility":3},{"url":"https://polynetwork.medium.com/notice-of-complete-termination-of-poly-network-services-3470ef78d9d9","name":"polynetwork.medium.com","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2020-08-18","event":"Poly Network launches as a cross-chain interoperability protocol, founded by Neo, Ontology, and Switcheo.","source":""},{"date":"2021-08-10","event":"Poly Network suffers the largest DeFi hack in history: approximately $611M stolen across Ethereum (~$273M), BNB Chain (~$253M), and Polygon (~$85M) via an access control exploit in EthCrossChainManager.","source":""},{"date":"2021-08-11","event":"The attacker begins returning stolen funds and claims via on-chain messages that the theft was conducted 'for fun' to expose vulnerabilities. Poly Network begins addressing the attacker as 'Mr. White Hat.'","source":""},{"date":"2021-08-13","event":"Approximately $340M returned. Poly Network offers attacker a $500,000 bug bounty and the role of 'chief security advisor.' Security community criticizes the white hat framing.","source":""},{"date":"2021-08-15","event":"Tether Ltd. confirms it froze $33.4M in USDT linked to the attacker's wallet immediately after the hack.","source":""},{"date":"2021-08-25","event":"All remaining unfrozen funds returned to Poly Network. The attacker declines the $500,000 bounty.","source":""},{"date":"2023-07-02","event":"Poly Network suffers a second exploit: attacker mints tens of billions in notional token value across 57 assets on 10 blockchains. Realized losses estimated at ~$10M. Root cause: alleged compromise of 3 of 4 multisig keeper private keys.","source":""},{"date":"2023-07-03","event":"Poly Network suspends all services and advises users to withdraw assets. Dedaub publishes postmortem attributing the attack to compromised private keys, not a smart contract bug.","source":""},{"date":"2024-09-11","event":"Poly Network announces complete termination of all services, effective September 30, 2024, citing 'changing market conditions.'","source":""},{"date":"2024-09-30","event":"Poly Network permanently shuts down all services, including Poly Bridge.","source":""}],"sources_used":[{"url":"https://neo.org/blog/details/4207","name":"neo.org","type":"other","archive_url":"http://web.archive.org/web/20260418011431/https://neo.org/blog/details/4207","credibility":3,"archive_timestamp":"2026-04-18T01:14:31+00:00"},{"url":"https://phemex.com/academy/what-is-poly-network","name":"phemex.com","type":"other","archive_url":"https://web.archive.org/web/20260830080513/https://phemex.com/academy/what-is-poly-network","credibility":3,"archive_timestamp":"2026-08-30T08:05:13+00:00"},{"url":"https://cointelegraph.com/magazine/shanghai-man-poly-network-hacking-shows-how-divided-the-eastern-and-western-crypto-communities-still-are/","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260218061957/https://cointelegraph.com/magazine/shanghai-man-poly-network-hacking-shows-how-divided-the-eastern-and-western-crypto-communities-still-are/","credibility":3,"archive_timestamp":"2026-02-18T06:19:57+00:00"},{"url":"https://www.coindesk.com/markets/2021/08/10/cross-chain-defi-site-poly-network-hacked-hundreds-of-millions-potentially-lost","name":"coindesk.com","type":"other","archive_url":"http://web.archive.org/web/20260413160447/https://www.coindesk.com/markets/2021/08/10/cross-chain-defi-site-poly-network-hacked-hundreds-of-millions-potentially-lost","credibility":3,"archive_timestamp":"2026-04-13T16:04:47+00:00"},{"url":"https://www.chainalysis.com/blog/poly-network-hack-august-2021/","name":"chainalysis.com","type":"other","archive_url":"http://web.archive.org/web/20260315140752/https://www.chainalysis.com/blog/poly-network-hack-august-2021/","credibility":3,"archive_timestamp":"2026-03-15T14:07:52+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-poly-network-hack-august-2021","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260829134428/https://www.halborn.com/blog/post/explained-the-poly-network-hack-august-2021","credibility":3,"archive_timestamp":"2026-08-29T13:44:28+00:00"},{"url":"https://research.kudelskisecurity.com/2021/08/12/the-poly-network-hack-explained/","name":"research.kudelskisecurity.com","type":"other","archive_url":"http://web.archive.org/web/20250729214805/https://research.kudelskisecurity.com/2021/08/12/the-poly-network-hack-explained/","credibility":3,"archive_timestamp":"2025-07-29T21:48:05+00:00"},{"url":"https://slowmist.medium.com/the-root-cause-of-poly-network-being-hacked-ec2ee1b0c68f","name":"slowmist.medium.com","type":"other","archive_url":"http://web.archive.org/web/20260422164553/https://slowmist.medium.com/the-root-cause-of-poly-network-being-hacked-ec2ee1b0c68f","credibility":3,"archive_timestamp":"2026-04-22T16:45:53+00:00"},{"url":"https://www.certik.com/resources/blog/HPJ3e0qAWPErSPdGeMXg1-poly-network-exploit","name":"certik.com","type":"other","archive_url":"https://web.archive.org/web/20260830092305/https://www.certik.com/blog/HPJ3e0qAWPErSPdGeMXg1-poly-network-exploit","credibility":3,"archive_timestamp":"2026-08-30T09:23:05+00:00"},{"url":"https://cointelegraph.com/news/poly-network-hacker-returns-nearly-all-funds-refuses-500k-white-hat-bounty","name":"cointelegraph.com","type":"other","archive_url":"http://web.archive.org/web/20260331055353/https://cointelegraph.com/news/poly-network-hacker-returns-nearly-all-funds-refuses-500k-white-hat-bounty","credibility":3,"archive_timestamp":"2026-03-31T05:53:53+00:00"},{"url":"https://www.cnbc.com/2021/08/23/poly-network-hacker-returns-remaining-cryptocurrency.html","name":"cnbc.com","type":"other","archive_url":"http://web.archive.org/web/20260826080701/https://www.cnbc.com/2021/08/23/poly-network-hacker-returns-remaining-cryptocurrency.html","credibility":3,"archive_timestamp":"2026-08-26T08:07:01+00:00"},{"url":"https://en.wikipedia.org/wiki/Poly_Network_exploit","name":"en.wikipedia.org","type":"other","archive_url":"http://web.archive.org/web/20260819195251/https://en.wikipedia.org/wiki/Poly_Network_Exploit","credibility":3,"archive_timestamp":"2026-08-19T19:52:51+00:00"},{"url":"https://protos.com/poly-network-white-hat-offers-500k-once-crypto-returned/","name":"protos.com","type":"other","archive_url":"http://web.archive.org/web/20260609062939/https://protos.com/poly-network-white-hat-offers-500k-once-crypto-returned/","credibility":3,"archive_timestamp":"2026-06-09T06:29:39+00:00"},{"url":"https://www.halborn.com/blog/post/explained-the-poly-network-hack-july-2023","name":"halborn.com","type":"other","archive_url":"http://web.archive.org/web/20260516233004/https://www.halborn.com/blog/post/explained-the-poly-network-hack-july-2023","credibility":3,"archive_timestamp":"2026-05-16T23:30:04+00:00"},{"url":"https://dedaub.com/blog/poly-network-hack/","name":"dedaub.com","type":"other","archive_url":"http://web.archive.org/web/20260414022223/https://dedaub.com/blog/poly-network-hack/","credibility":3,"archive_timestamp":"2026-04-14T02:22:23+00:00"},{"url":"https://www.theblock.co/post/237452/attacker-pockets-10-million-from-poly-network-security-attack-beosin","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"forbiddenaccess","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://decrypt.co/147059/poly-network-attack-conjures-billions-of-dollars-in-tokens-that-did-not-exist","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260308132556/https://decrypt.co/147059/poly-network-attack-conjures-billions-of-dollars-in-tokens-that-did-not-exist","credibility":3,"archive_timestamp":"2026-03-08T13:25:56+00:00"},{"url":"https://www.coindesk.com/tech/2023/07/02/polynetwork-attacker-issues-worthless-billions-in-shib-bnb-busd-in-latest-crypto-hack","name":"coindesk.com","type":"other","archive_url":"https://web.archive.org/web/20260915161956/https://www.coindesk.com/tech/2023/07/02/polynetwork-attacker-issues-worthless-billions-in-shib-bnb-busd-in-latest-crypto-hack","credibility":3,"archive_timestamp":"2026-09-15T16:19:56+00:00"},{"url":"https://therecord.media/crypto-platform-poly-network-suspends-service-after-hack","name":"therecord.media","type":"other","archive_url":"http://web.archive.org/web/20260208230659/https://therecord.media/crypto-platform-poly-network-suspends-service-after-hack","credibility":3,"archive_timestamp":"2026-02-08T23:06:59+00:00"},{"url":"https://polynetwork.medium.com/the-poly-network-exploit-analysis-b0a77aff6078","name":"polynetwork.medium.com","type":"other","archive_url":"http://web.archive.org/web/20251113122916/https://polynetwork.medium.com/the-poly-network-exploit-analysis-b0a77aff6078","credibility":3,"archive_timestamp":"2025-11-13T12:29:16+00:00"},{"url":"https://blocksec.com/audit-report/security-audit-report-for-poly-contracts","name":"blocksec.com","type":"other","archive_url":"http://web.archive.org/web/20260416020757/https://blocksec.com/audit-report/security-audit-report-for-poly-contracts","credibility":3,"archive_timestamp":"2026-04-16T02:07:57+00:00"},{"url":"https://www.vidma.io/blog/poly-network-hack-a-611-million-lesson-in-smart-contract-vulnerabilities","name":"vidma.io","type":"other","archive_url":"http://web.archive.org/web/20260315225710/https://www.vidma.io/blog/poly-network-hack-a-611-million-lesson-in-smart-contract-vulnerabilities","credibility":3,"archive_timestamp":"2026-03-15T22:57:10+00:00"},{"url":"https://polynetwork.medium.com/notice-of-complete-termination-of-poly-network-services-3470ef78d9d9","name":"polynetwork.medium.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://neonewstoday.com/development/poly-network-announces-complete-termination-of-all-services/","name":"neonewstoday.com","type":"other","archive_url":"http://web.archive.org/web/20260311215740/https://neonewstoday.com/development/poly-network-announces-complete-termination-of-all-services/","credibility":3,"archive_timestamp":"2026-03-11T21:57:40+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:55.341081+00:00","updated_at":"2026-09-15T16:20:14.139561+00:00"}}