Summary
On 10 August 2021, an attacker drained about $611 million from Poly Network, a protocol that moves assets between blockchains, in what was then the largest DeFi theft ever. No private keys were stolen and no cryptography was broken. The attacker found a flaw in how Poly's cross-chain contracts handled permissions and simply instructed the system to make them the owner, then signed their own withdrawals across three chains. The strangest part came next: over the following two weeks the attacker gave almost all of it back, claiming they had done it "for fun" and to expose the bug, and Poly Network ended up thanking them and offering them a job. It is a vivid lesson in smart-contract access control, and in the difference between stealing money on-chain and keeping it.
How it happened
This was not a key theft but a smart-contract access-control failure. Poly's cross-chain manager contract (EthCrossChainManager) had a function (verifyHeaderAndExecuteTx) that dispatched incoming cross-chain calls onward to other contracts, and it placed no allowlist on which target or method those calls could hit. Separately, the contract that stored the bridge's trusted "keeper" public keys (EthCrossChainData) was owned by that manager, and the function to replace those keys was protected only by an owner check.
The attacker connected the two. Solidity identifies a function by a four-byte selector derived from a hash of its name, and four bytes is small enough to brute-force a collision. The attacker found an innocuous-looking method string, f1121318093, whose selector collides with the protected key-replacement function putCurEpochConPubKeyBytes (both hash to 0x41973cd9), then used the dispatcher to make the manager contract, the legitimate owner, call that function. Poly's own contract dutifully replaced the entire keeper key set with the attacker's key. From that moment the attacker could sign any withdrawal they liked, and they emptied reserves across Ethereum (about $273 million), BSC (about $253 million), and Polygon (about $85 million), about $611 million in all.
The white-hat ending
What followed was unprecedented. Tether froze about $33 million of the stolen USDT, but the rest sat in the attacker's hands, fully traceable on-chain. Calling themselves "Mr White Hat," the attacker began returning the funds, and over roughly fifteen days gave back nearly all of it. In a Q&A embedded in their own transactions they said it had been done "for fun" and to expose the bug "before any insiders" could exploit it, and they even sent 13.37 ETH (about $42,000) to a stranger who had warned them on-chain not to move funds that had been blacklisted. Poly Network publicly thanked them, offered a $500,000 bug bounty, and even floated a security-advisor role. Part of the motivation was surely the simple reality that $600 million in watched, traceable crypto is extraordinarily hard to launder.
Why Poly Network still matters
Poly is an access-control lesson first. The most dangerous bugs are not fancy cryptography; they are a privileged function that can be reached from untrusted input, here a manager contract that could be tricked into calling its own owner-only setter. The selector collision is a neat reminder that four-byte function selectors are not unique and should never be trusted from attacker-controlled input. The defences are structural: allowlist which targets and methods a dispatcher may call, never make the executing contract the owner of the privileged config it can call into, put sensitive setters behind multisig or timelock governance, and validate full function selectors. And it stands as the clearest demonstration that on a public blockchain, taking the money and getting away with it are two very different problems.
How to fix it
- Pause the bridge and replace the compromised keeper key set, then re-secure the privileged setters behind multisig or timelock before resuming.
- Separate the executing contract from ownership of the keeper or config contract so no dispatched call can reach an owner-only function.
- Trace and recover funds; Poly recovered nearly everything, helped by how hard $600 million on-chain is to launder under watch.
How to avoid it
- Allowlist permitted call targets in the dispatcher; forbid calls into keeper and privileged config contracts.
- Never make the executing manager contract the owner of the keeper/consensus data contract; separate execution from ownership.
- Place privileged setters like the keeper-key setter behind multisig or timelock governance, not a single contract's owner check.
- Validate full function selectors against an allowlist instead of trusting four-byte selectors from attacker-controlled method strings.
- Audit every cross-contract ownership edge; assert no untrusted-input path reaches an owner-only mutating function.
References
- https://www.chainalysis.com/blog/poly-network-hack-august-2021/
- https://blog.kraken.com/product/security/abusing-smart-contracts-to-steal-600-million-how-the-poly-network-hack-actually-happened
- https://slowmist.medium.com/the-root-cause-of-poly-network-being-hacked-ec2ee1b0c68f
- https://dedaub.com/blog/poly-network-hack/
Related vulnerabilities
All Web3 →- CRITICALWEB3-KILOEX-2025
On April 14, 2025 the perpetuals DEX KiloEx lost about $7.5 million across BNB Chain, Base, opBNB, and Taiko to what was reported as oracle price manipulation but was really an access-control failure. KiloEx's price feed (KiloPriceFeed.setPrices) was meant to be reachable only through a keeper-gated call chain, but the top-level MinimalForwarder.execute function was publicly callable and validated an attacker-supplied signature against attacker-supplied data, letting anyone forge a trusted call that reached setPrices and write an arbitrary price. The attacker set a market price far below true value, opened a leveraged position, then set the price far above value and closed it in the same flow, extracting fabricated profit from the vault; the sequence was repeated across all four chains, with a single transaction netting $3.12M. Reporting that framed it as flash-loan oracle manipulation was imprecise: no market liquidity was moved, the price was simply written directly through the unprotected forwarder. After KiloEx offered a 10% (~$750K) whitehat bounty and no legal action, the attacker returned essentially all of the funds by April 18, 2025.
- CRITICALWEB3-RADIANT-2024
On October 16, 2024, the cross-chain lending protocol Radiant Capital lost roughly $50M (about $53M across Arbitrum and BSC) after attackers compromised the devices of at least three of its multisig signers. Initial access began September 11, 2024 via a Telegram message spoofing a trusted former contractor, delivering a ZIP with a decoy PDF that was actually a macOS application carrying INLETDRIFT backdoor malware. The malware sat between the signers' browsers and their hardware wallets, so the Safe (Gnosis) UI and Tenderly simulations displayed correct data while the signers blind-signed a malicious transferOwnership() call on the LendingPoolAddressesProvider contract; the 3-of-11 threshold was met and the attacker then upgraded the pools to a malicious implementation and drained them. Mandiant assessed with high confidence the attack was conducted by North Korea-linked UNC4736 (aka Citrine Sleet/AppleJeus), part of the Lazarus cluster. Funds were not recovered and the protocol later wound down.
- CRITICALWEB3-KELPDAO-LAYERZERO-2026
On April 18, 2026, North Korea's Lazarus Group drained about 116,500 rsETH (roughly $292 million) from KelpDAO's LayerZero-based bridge, the largest DeFi exploit of the year. No smart contract was broken; the contracts did exactly what they were written to do. The attack was against the bridge's off-chain verification. rsETH's LayerZero channel was configured to trust a single verifier (a 1-of-1 DVN), so the attackers compromised LayerZero's internal RPC nodes, knocked out the honest external node with a denial-of-service flood, and forced that single verifier to attest to a cross-chain message that never really happened. The Ethereum side then released unbacked rsETH from escrow, leaving wrapped rsETH stranded across more than twenty chains and triggering a bank-run across DeFi.
- HIGHWEB3-FRONTEND-DNS-HIJACK-2022
A frontend hijack leaves the on-chain contracts untouched but replaces the Web2 surface serving the dApp UI with a wallet-drainer clone, so no Solidity audit can catch it. The recurring pattern: attackers take over the domain registrar or DNS provider account (or a CDN/tag-manager account), repoint the domain to a cloned site, and prompt visitors to sign malicious token approvals, EIP-2612 permit signatures, or transfers. Curve Finance was hit twice: on August 9-10, 2022 its curve.fi domain was DNS-hijacked via a compromised nameserver and drained ~$570K in USDC/DAI; and again around May 12, 2025 at the registrar level, after which Curve permanently migrated to curve.finance and announced an ENS move (Convex Finance and Resupply, which depend on Curve's data feeds, suffered dependency-driven outages but were not themselves compromised). In July 2024 a mass wave hit DeFi domains registered through Squarespace, whose forced migration off Google Domains stripped 2FA: Compound's frontend redirected to an Inferno Drainer clone and 100+ protocols were exposed (Celer blocked its takeover via domain monitoring). Ambient Finance's domain was hijacked through stolen registrar credentials on October 17, 2024. Most recently, on April 14, 2026 attackers used forged identity documents to social-engineer the registrar into handing over DNS control of CoW Swap's swap.cow.fi and cow.fi domains, redirecting users to a pixel-perfect drainer clone for about 90 minutes; over $1M was taken in roughly three hours, including 219 ETH (~$750K) from a single wallet, while CoW's contracts, backend APIs, and solver network were untouched. The same bucket includes CDN-account injections (KyberSwap's September 2022 Cloudflare/Google Tag Manager compromise, ~$265K) and BGP route hijacks that swap signed bundles for drainer code.
- HIGHWEB3-CURVE-DNS-2025
On May 12, 2025, attackers hijacked Curve Finance's primary domain, curve.fi, at the registrar and DNS level and pointed visitors at a wallet-draining clone of the site. Curve's smart contracts and on-chain funds were never touched; this was a Web2 attack on the domain, the soft underbelly that no Solidity audit can protect. The nameservers for curve.fi were swapped to attacker-controlled infrastructure at the registrar (iwantmyname, the same registrar implicated in Curve's 2022 hijack), and the clone prompted users to approve malicious token transactions. On-chain analysts estimated user losses around $520,000, most of it taken in the first ninety minutes. Curve repointed the domain to neutral nameservers, then permanently migrated to curve.finance and signaled a move toward decentralized (ENS) hosting.
- CRITICALWEB3-BYBIT-2025
On 21 February 2025, the crypto exchange Bybit lost about $1.5 billion in ether, the largest hack in history, to North Korea's Lazarus Group. Bybit had done what custody best-practice prescribes: the funds sat in a cold wallet behind a multisig requiring several human signers. The attackers beat it anyway, not by stealing keys but by tampering with what the signers saw. Weeks earlier they had compromised a developer at Safe, the multisig-wallet provider, and slipped malicious code into the Safe web app, so that when Bybit's executives reviewed a routine transfer, the screen showed a legitimate transaction while their hardware wallets were actually signing a malicious one that handed the wallet to the attacker. It is the defining lesson that a multisig is only as trustworthy as the screen you approve it on, and that blind-signing is the modern crypto catastrophe.