Authorisation, not cryptography
Poly Network is the incident to cite when someone describes bridge security as a cryptography problem. Nothing cryptographic failed here. A function in the cross-chain management contract permitted the keeper role — the privileged account that authorises withdrawals — to be reassigned by a caller who should never have been able to do so. Having reassigned it, the attacker simply asked the bridge to release funds, and the bridge complied, because from its point of view the request was properly authorised.
The return
Substantially all of the assets were returned over the following days, with the attacker communicating through transaction input data. That outcome is unusual and should not be read as typical: the overwhelming majority of exploits of this size do not end in restitution. It also does not reduce the severity of the underlying defect, which would have been equally exploitable by someone with no interest in returning anything.
What this means for a reader
Bridges concentrate risk by design: they hold pooled collateral and they run privileged logic to decide when to release it. When assessing one, the question worth asking is not how strong the signatures are but who — and what code path — can change who is allowed to authorise a withdrawal.
Timeline
Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.
- Poly Network publicly discloses the exploit and publishes the attacker addresses across three chains. Poly Network
- The attacker begins returning assets, communicating via transaction input data. Poly Network
What to check
Poly Network published the affected addresses and its recovery updates on its official channels at the time; those statements are the authoritative record of what was taken and what was returned.
Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.
Sources
- Poly Network, Official incident statement and attacker addresses (10 Aug 2021)
Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.
Last verified by Conisec Staff.