Unchained
Unchained

Unconfirmed: Why Did the Poly Network Attacker Return Half the Money They Stole? - Ep.263

Poly Network, a cross-chain DeFi protocol, recently suffered a $600M hack -- the largest DeFi exploit in crypto history. Mudit Gupta, security researcher and SushiSwap dev, breaks down the attack, explaining how it occurred, why the hacker is returning the funds, and what Poly Network should do next

Featured Speakers

Mudit Gupta Guest

Topics Discussed

Episode Summary

Executive Summary: This episode centers on the massive Poly Network DeFi exploit, where a hacker used Poly Network’s cross-chain message verification design to impersonate trusted keepers and drain over $600M in assets. Guest Mudit Gupta explains the exploit, the subsequent on-chain communications and partial fund return, and the broader implications for bridge security, centralized stablecoin controls, and how Poly Network should negotiate recovery.

Main Topics: Poly Network exploit mechanics (Priority: 5/5): Mudit Gupta explains how Poly Network’s bridge architecture works and how the attacker exploited the keeper/signature system to replace trusted parties and authorize unauthorized withdrawals across chains. Why the attack was unusually effective (Priority: 5/5): The conversation highlights that this was not a typical flash-loan or price-manipulation hack; it exploited Poly Network’s cross-chain trust model and permission assumptions in a unique way. Hacker identity, KYC slip-up, and return of funds (Priority: 4/5): SlowMist’s tracing suggested one wallet may have been tied to a KYC exchange account, potentially exposing the attacker. The attacker later began returning funds while claiming white-hat intent, though Mudit suspects fear of identification changed their behavior. On-chain communication and negotiations (Priority: 4/5): The attacker used blockchain transactions to taunt, negotiate, and even create encrypted communication with Poly Network, turning the chain into a public and semi-private messaging channel. Stablecoin issuer and chain response (Priority: 4/5): Tether blacklisted stolen USDT quickly, while USDC reacted too slowly to prevent movement. Binance Smart Chain could not easily censor the attacker despite its relative centralization. Policy and infrastructure news roundup (Priority: 3/5): The recap covers the U.S. infrastructure bill’s crypto tax provision, Coinbase earnings and ETH trading volume surpassing BTC, Brian Brooks’ departure from Binance US, Tether reserves disclosure, Circle’s bank ambitions, BitMEX’s settlement, and SEC-Ripple developments.

Key Arguments: Poly Network’s design let the destination-chain manager execute messages based on keeper signatures, creating a security risk if that manager held admin powers. The attacker exploited the fact that a transaction failing on the source chain could still succeed on the destination chain if executed by the manager contract. Once the keepers were replaced, the attacker could sign arbitrary transactions and drain funds without corresponding source-chain authorization. SlowMist’s discovery of a possible KYC-linked wallet suggests the hacker may have made a traceable operational mistake. The attacker’s fund returns may reflect fear of identification and legal consequences more than purely altruistic white-hat behavior. Tether’s quick blacklist response shows centralized stablecoins can intervene rapidly, whereas USDC and BSC lacked either speed or practical censorship coordination. Poly Network should prioritize recovery first, then decide on legal action; Mudit argues a bounty is appropriate, but the amount should be bounded and reasonable. The infrastructure bill’s broker language could sweep in non-custodial actors, making compliance impossible for many decentralized participants.

Data Points: Total Poly Network funds stolen: more than $600 million - Size of the DeFi exploit discussed in the interview Ethereum assets stolen: $273 million - Part of the stolen funds attributed to Ethereum-based coins BSC assets stolen: $253 million - Part of the stolen funds attributed to Binance Smart Chain coins USDC stolen: $85 million - Stolen stablecoins in the exploit USDT stolen: $33 million - Tether later blacklisted these tokens Total Poly Network return estimate: about 50% returned - Mudit says roughly half the stolen tokens had been returned by the time of the interview Potential bounty benchmark: 10% - Mudit cites the traditional critical-bug bounty norm as a reference point Infrastructure bill passage: 69 to 30 - U.S. Senate vote approving the $1.2 trillion infrastructure bill Crypto tax provision revenue target: $28 billion - Expected tax revenue from the broker reporting language Coinbase Q2 profit: $1.6 billion - Quarterly profit reported by Coinbase Coinbase Q2 revenue: $2.03 billion - Revenue beat analyst expectations Coinbase monthly transacting users growth: 44% - Q1 to Q2 growth Coinbase verified customers: 68 million - Total verified customer count reported ETH share of Coinbase volume: 26% - ETH surpassed BTC in trading volume during Q2 BTC share of Coinbase volume: 24% - Bitcoin’s share of Coinbase trading volume in Q2 Tether reserves disclosed: $62.8 billion - Value in Tether’s new attestation Commercial paper and CDs share: 48% - Portion of Tether reserves held in commercial paper and certificates of deposit BitMEX settlement amount: $100 million - Civil settlement with CFTC and FinCEN USDC issuer bank ambition: U.S. national bank - Circle’s stated goal in its filing Ether Rock NFT sale threshold: over $100,000 each - Two Ether Rock NFTs sold for more than this amount Polymarket referral reimbursement: up to $100 - Sponsor offer mentioned in the episode Crypto.com app interest: up to 8.5% on Bitcoin - Sponsor promotion read during the show

Pivotal Quotes: "The hacker managed to kick out the trusted parties from the system and replace them with their own malicious party." — Mudit Gupta: Explaining the core exploit mechanism behind Poly Network "This means that anyone can make the manager contract on the destination blockchain basically rebroadcast almost any transaction." — Mudit Gupta: Describing the trust assumptions in Poly Network’s cross-chain architecture "The suggested approach in these cases is to pay the ransom, whatever the demand is, get your product back, get as much funds secured as possible." — Mudit Gupta: Advising Poly Network on how to respond to the attacker’s negotiation

Implications: Bridge security and trust assumptions are now a top DeFi risk, while centralized issuers can sometimes respond faster than chains themselves. The case also underscores how on-chain transparency can aid both extortion and negotiation, and may push future protocols toward stronger permission isolation and monitoring.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained