Cryptocurrency heist hacker returns $260m in fundson August 11, 2021 at 11:44 pm

- Advertisement -
- Advertisement -
- Advertisement -
- Advertisement -

The hacker behind the $600m Poly Network cryptocurrency heist has posted a Q&A on the blockchain.

A hacker working on a computer, while monitoring data on a tablet

image sourceGetty Images

The hacker behind one of the largest ever cryptocurrency heists ever has returned almost half of the $600m (£433m) stolen assets.

Yesterday, blockchain platform Poly Network wrote a letter on Twitter, asking the individual to get in touch “to work out a solution”.

The website said the amount of money hacked was “biggest” incident so far in the decentralised finance industry.

But at 18:28 BST on Wednesday, Poly Network said it had received $260m.

Poly Network posted on Twitter that it had been sent digital tokens relating to three crypto-currencies, including $3.3m worth of Ethereum, $256m worth of Binance Smart Chain (BSC) and $1m worth of Polygon.

A total of $269m in Ethereum tokens and $84m in Polygon tokens has yet to be recovered.

The hacker also took to one of the blockchains to publish a three-page-long Q&A session, where he essentially “interviewed himself”, according to Tom Robinson, co-founder of Elliptic, a London-based blockchain analytics and compliance firm.

The hacker said that he decided to return the stolen assets because he is “not very interested in money”.

“I know it hurts when people are attacked, but shouldn’t they learn something from those hacks?” he wrote in the notes posted to the blockchain.

A person monitoring the price of various crypto-currencies on a tablet

image sourceGetty Images

The hacker added that it had taken him all night to find a vulnerability to exploit. He said he was worried that Poly Network would patch the security flaw quietly without telling anyone, so he decided to take millions of dollars in crypto-currency tokens to make a point.

But he stressed that he didn’t want to cause a “real panic [in] the crypto-world”, so he only took “important coins”, except Dogecoin, the crypto-currency that started off as a joke.

“Either they just intended to commit theft and steal the assets, or they were acting like a white hat hacker to expose a bug, to help Poly Network make themselves more strong and secure,” Mr Robinson, who routinely advises governments and law enforcement agencies about crypto-related crimes, explained to the BBC.

He added that the nature of blockchain technology makes it hard for cyber-criminals to profit from stealing digital currencies, because everyone can see the money being moved across the network into the hackers’ wallets.

“I wonder whether this hacker stole the funds, realised how much publicity and attention they were getting, realised wherever they moved the funds they would be watched, and decided to give it back,” said Mr Robinson.

“The blockchain itself has operated here flawlessly, but the problem is on blockchains like Ethereum, you can write your own smart contracts. Various services have started offering this, including Poly Network.

“So whenever a human being writes code, there’s a chance they will make a mistake.”

A man buying crypto-currencies on a mobile app

image sourceGetty Images

A blockchain is a ledger, or log, of every single transaction made of a cryptocurrency, such as Bitcoin. The ledger is distributed to all the users in the network to verify all new transactions when they occur, instead of being held by any one single authority.

Poly Network’s platform works by facilitating movement between several blockchains when people trade one crypto-currency for another, such as trading BSC for Ethereum.

“The Polygon network is the thing that facilitates the movement between these chains – ultimately, it’s software, it’s code, and code always has imperfections and defects in it,” James Chappell, co-founder of London-based cyber-security firm Digital Shadows told the BBC.

“And that’s true of banks, or any financial system. Unfortunately, what seems to have happened here is a party has spotted a weakness in the implementation and exploited it to fool the network into transferring these tokens incorrectly.”

Similar attacks to the Poly Network case have occurred in the last 12 months to several other services, including Yearn Finance, which had $11m stolen by hackers in February; Alpha Finance, which had $37m stolen in the same month; and Meerkat Finance, which was drained of $32m by hackers in March.

2px presentational grey line
Analysis box by Joe Tidy, Cyber reporter

What a rollercoaster 24 hours for the crypto community.

As the hacker posted online: “The pains suffered is temporary but memorable.”

The hacker’s, or hackers’, claim that it was all an elaborate way to force Poly Network to fix security failings is being treated with scepticism.

Why the taunting and boasting online, if the motive was honourable?

There’s some suggestion that the net may have been closing in, as one cyber-security company says it was close to working out the identity of the cyber-criminal.

It might have been the case that the hacker bit off way more than they could chew and got scared, so returned the money.

The authorities will still no doubt be working hard to capture them, regardless of the swift refund.

But what this story mostly points to is just how powerful hackers can be and how powerless the unregulated, decentralised crypto-currency network is when someone swipes a large fortune from under its nose.

2px presentational grey line
- Advertisement -

Discover

Sponsor

Latest

Twitter: Elon Musk blames ‘activist groups’ for earnings dropon November 4, 2022 at 8:36 pm

Elon Musk, the new owner of Twitter, makes the accusation as the tech firm makes sweeping job cuts.Image source, Getty ImagesElon Musk, the new...

Super Bowl 2020 Event Information

Super Bowl 2020 Event InformationOne of the coolest and most exciting events this year is Super Bowl 2020. There will be two massive...

Women’s World Cup highlights: Beth Mooney shines as Australia survive Bangladesh scareon March 25, 2022 at 7:18 am

Watch as Beth Mooney makes 66 not out as Australia survive a scare from Bangladesh to end the group stage undefeated at the Women's...

Women’s World Cup 2023 qualifying: Kazakhstan 0-3 Waleson April 12, 2022 at 2:53 pm

Natasha Harding scores to mark her 100th international appearance as dominant Wales claim a 3-0 World Cup qualifying win in Kazakhstan.

Dread Broadcasting Corporation: The pirate that changed British radioon November 27, 2022 at 12:43 am

Europe's first dedicated black music station, Dread Broadcasting CorporationEurope's first dedicated black music station, Dread Broadcasting Corporation