Skip to content
Incident record

Poly Network Cross-Chain Exploit, August 2021: What Happened & What to Check

An attacker exploited Poly Network's cross-chain contract to reassign the keeper role, taking roughly $611m — then returned substantially all of it.

Resolved Discovered Disclosed
Share X in @
Schematic of the Poly Network incident showing the access control stage as the failure point.
Schematic of the Poly Network incident showing the access control stage as the failure point.

At a glance

AFFECTED ENTITY
Poly Network
REPORTED LOSS
approx. US$611 million (substantially all returned)(Poly Network, 10 Aug 2021)
OFFICIAL RESPONSE
x.com

Authorisation, not cryptography

Poly Network is the incident to cite when someone describes bridge security as a cryptography problem. Nothing cryptographic failed here. A function in the cross-chain management contract permitted the keeper role — the privileged account that authorises withdrawals — to be reassigned by a caller who should never have been able to do so. Having reassigned it, the attacker simply asked the bridge to release funds, and the bridge complied, because from its point of view the request was properly authorised.

The return

Substantially all of the assets were returned over the following days, with the attacker communicating through transaction input data. That outcome is unusual and should not be read as typical: the overwhelming majority of exploits of this size do not end in restitution. It also does not reduce the severity of the underlying defect, which would have been equally exploitable by someone with no interest in returning anything.

What this means for a reader

Bridges concentrate risk by design: they hold pooled collateral and they run privileged logic to decide when to release it. When assessing one, the question worth asking is not how strong the signatures are but who — and what code path — can change who is allowed to authorise a withdrawal.

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Poly Network publicly discloses the exploit and publishes the attacker addresses across three chains. Poly Network
  2. The attacker begins returning assets, communicating via transaction input data. Poly Network

What to check

Poly Network published the affected addresses and its recovery updates on its official channels at the time; those statements are the authoritative record of what was taken and what was returned.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Poly Network, Official incident statement and attacker addresses (10 Aug 2021)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.