Hackers stole over $600 million in the biggest DeFi hack…Start to return some of the stolen funds

Hackers stole over 0 million in the biggest DeFi hack…Start to return some of the stolen funds

CNBC

By Arjun Kharpal & Ryan Browne

More than $600 million was stolen in what is likely to be one of the biggest cryptocurrency thefts ever.

— Hackers exploited a vulnerability in Poly Network, a platform that looks to connect different blockchains so that they can work together.

— In a strange turn of events Wednesday, the hackers began returning some of the funds they stole.

Hackers have started returning some of the $600 million they stole in what’s likely to be one of the biggest cryptocurrency thefts ever.

The cybercriminals exploited a vulnerability in Poly Network, a platform that looks to connect different blockchains so that they can work together.

Poly Network disclosed the attack Tuesday and asked to establish communication with the hackers, urging them to “return the hacked assets.”

A blockchain is a ledger of activities upon which various cryptocurrencies are based. Each digital coin has its own blockchain and they’re different from each other. Poly Network claims to be able to make these various blockchains work with each other.

Poly Network is a decentralized finance platform. DeFi is a broad term encompassing financial applications based on blockchain technology that looks to cut out intermediaries — such as brokerages and exchanges. Hence, it’s dubbed decentralized.

Proponents say this can make financial applications such as lending or borrowing more efficient and cheaper.

“The amount of money you hacked is the biggest in defi history,” Poly Network said in a tweet.

Hackers start to return the funds

In a strange turn of events Wednesday, the hackers began returning some of the funds they stole.

They sent a message to Poly Network embedded in a cryptocurrency transaction saying they were “ready to return” the funds. The DeFi platform responded requesting the money be sent to three crypto addresses.

Poly Network on X (formerly Twitter): “pic.twitter.com/AP4tCC565d / X”

pic.twitter.com/AP4tCC565d

As of midday London time, more than $4.8 million had been returned to the addresses.

“I think this demonstrates that even if you can steal cryptoassets, laundering them and cashing out is extremely difficult, due to the transparency of the blockchain and the use of blockchain analytics,” Tom Robinson, chief scientist of blockchain analytics firm Elliptic, said via email.

“In this case the hacker concluded that the safest option was just to return the stolen assets.”

Once the hackers stole the money, they began to send it to various other cryptocurrency addresses. Researchers at security company SlowMist said a total of more than $610 million worth of cryptocurrency was transferred to three addresses.

SlowMist said in a tweet that its researchers had “grasped the attacker’s mailbox, IP, and device fingerprints” and are “tracking possible identity clues related to the Poly Network attacker.”

The researchers concluded that the theft was “likely to be a long-planned, organized and prepared attack.”

Poly Network urged cryptocurrency exchanges to “blacklist tokens” coming from the addresses that were linked to the hackers.

About $33 million of Tether that was part of the theft has been frozen, according to the stablecoin’s issuer.

Changpeng Zhao, CEO of major cryptocurrency exchange Binance, said he was aware of the attack.

He said Binance is “coordinating with all our security partners to proactively help,” but that “there are no guarantees.”

CZ 🔶 BNB on X (formerly Twitter): “We are aware of the https://t.co/IgGJ0598Q0 exploit that occurred today. While no one controls BSC (or ETH), we are coordinating with all our security partners to proactively help. There are no guarantees. We will do as much as we can. Stay #SAFU. 🙏 https://t.co/TG0dKPapQT / X”

We are aware of the https://t.co/IgGJ0598Q0 exploit that occurred today. While no one controls BSC (or ETH), we are coordinating with all our security partners to proactively help. There are no guarantees. We will do as much as we can. Stay #SAFU. 🙏 https://t.co/TG0dKPapQT

“We will take legal actions and we urge the hackers to return the assets,” Poly Network said on Twitter.

DeFi hacks on the rise

DeFi has become a key target for attacks.

Since the start of the year until July, DeFi-related hacks totaled $361 million — an increase of nearly three times from all of 2020, according to cryptocurrency compliance company CipherTrace.

DeFi-related fraud is also on the rise. In the first seven months of the year, it accounted for 54% of total crypto fraud volume versus 3% for all of last year.

This article originally appeared in CNBC

More

Leave a Reply

Your email address will not be published. Required fields are marked *

Hackers stole over $600 million in the biggest DeFi hack...Start to return some of the stolen funds

 

Log In

Or with username:

Forgot password?

Forgot password?

Enter your account data and we will send you a link to reset your password.

Your password reset link appears to be invalid or expired.

Log in

Privacy Policy

Add to Collection

No Collections

Here you'll find all collections you've created before.