DeFi Platform Poly Network stolen for $ 610 million by hackers, but almost all of it was eventually returned

[ad_1]

A brazen theft by crypto hackers cost users of a DeFi platform a total of $ 610 million, but only for a small while. Claiming it was only a display of vulnerability, the hackers have since returned all but $ 33 million in assets.

It’s still unclear if that was the intention from the start, or if the hackers were afraid to backtrack with promises to track them down from across the cryptocurrency community.

Hackers Soar With $ 610 Million, Then Return Most Of It With “Security Search” Claims

The initial theft put the brazen DeFi platform heist with the biggest cryptocurrency breaches in history (2018 CoinCheck and 2014’s Mt. Gox). However, when the dust settles, there may well be no more stolen funds.

The story begins with the DeFi Poly Network platform breach on August 10. Hackers quickly exfiltrated a variety of assets with a total value of around $ 610 million. This included hundreds of millions of Binance Smart Chain, Ethereum, and USDC tokens. However, less than a day later, the attackers had already started returning the funds; $ 260 million to start, then all but $ 33 million by August 13.

The hackers held a question-and-answer session on the blockchain account breach that began on August 11, claiming they were simply demonstrating a vulnerability and still had plans to return the funds. However, a quick and vocal response from the cryptocurrency community swearing a variety of colorful vengeance oaths may well have contributed to this decision. Stealing cryptocurrency is one thing, but due to the transparent recording of transactions, it is much more difficult to cash it out without revealing information about yourself. Poly Network has also blacklisted a good chunk of the stolen tokens, essentially freezing them, hampering transactions.

Breach Highlights DeFi Platform Security Issues

Most DeFi (decentralized finance) platforms run on the Ethereum blockchain and provide some kind of replica of traditional financial institutions (such as banks and exchanges). In addition to a familiar user interface, these services often provide approximations of common banking services: virtual “savings accounts” bearing interest in cryptocurrencies, the ability to trade or lend to other users of the bank. platform, take out insurance and speculate against price movements, for just a few examples.

It appears that hackers have targeted signatures that are roughly analogous to account passwords on DeFi platforms. This particular exploit was specific to the individual cryptography of the Poly Network. Hackers seem to have figured out how to replicate valid signatures over the network, allowing them to authorize transactions from other people’s accounts.

Cryptocurrency is often viewed as highly secure, but DeFi platforms represent an experimental weak point in the chain that has a small but persistent history of failures that lead to theft. A network is only as strong as its protocol, which can contain exploitable programming flaws or develop bugs. In this case, Poly Network said crypto hackers exploited a feature used in contract calls to link transactions from independent blockchains.

Hank Schless, senior director of security solutions at Lookout, points out that DeFi platforms are also ripe for social engineering and phishing attacks: “Since cryptocurrency and blockchain are still relatively new technologies. , they offer threat actors an opportunity for social engineering of targets. . Crypto investors are constantly looking for an edge in the market or the next big currency that will explode in value. Attackers can use this thirst for information against users to trick them into downloading malicious apps or sharing login credentials for the legitimate trading platforms they use. The attacker could then use the malicious application to exfiltrate additional data from the device they are on or take the login credentials they stole and try them on a number of cloud applications in use at a time. for work and personal life. In order to increase the chances of success, attackers target users on mobile devices and cloud platforms. For example, Lookout recently discovered nearly 200 malicious cryptocurrency apps on the Google Play Store. Most of these apps presented themselves as mining services in order to entice users to download them.

DeFi platforms are also a real “wild west” financial domain, totally unregulated and largely untouched by world governments. Anyone can create one, and there is often no real way to verify if they (or their code) are trustworthy. And while the type of blacklist that Poly Network did in response to the attack is respected by much of the cryptocurrency community, it is not a guarantee against the ability to cash out as it requires voluntary adoption by each potentially involved party.

John Callahan, CTO of Veridium, points out that even a user doing all the right things in terms of safety hygiene could still find themselves victimized: accounts directly. He highlights the risks associated with centralized cryptocurrency exchanges: any successful attack on the exchange results in losses for ALL users. This, in my opinion, strengthens the position of exchanges that support wallets with user-owned keys (i.e. non-custodial wallets). This allows users to hold their own private keys and supports interoperable transactions negotiated by any exchange. “

Expect an increase in fraud on the DeFi platform

Incidents like this have led financial experts, even those who consider themselves cryptocurrency evangelists, to give essentially the same advice that is given about a Las Vegas vacation: don’t put as much more money in DeFi platforms than you can afford to wipe out in a day. While DeFi platforms that have been around for years and can demonstrate regular external audits and security testing are more secure, none are absolutely secure as there is always the possibility of previously unknown vulnerabilities to develop.

Users of DeFi platforms shouldn’t expect the relatively happy ending here either. For now, it looks like almost all of the $ 610 million will be returned to its rightful owners; the only item still in question is the $ 33 million Tether coin which remains frozen by the issuer for now. China-based security firm SlowMist, with Poly Network, said it tracks hackers and has their email and IP addresses as well as the device’s fingerprints. However, even a positive identification may not matter much depending on where the hackers are.

The initial theft put the brazen #DeFi platform heist with the biggest #cryptocurrency breaches in history. The #hackers may have been afraid to return anything but $ 33 million in assets. #cybersecurity #respectdataClick to Tweet

Fraud on the DeFi platform in general is on the rise, accounting for 54% of all crypto frauds last year compared to 3% the year before. Prior to the Poly Network breach, approximately $ 361 million in theft was attributed to DeFi breaches in 2021 (an increase of about 3 times over 2020).

Sources

1/ https://Google.com/

2/ https://www.cpomagazine.com/cyber-security/defi-platform-poly-network-robbed-for-610-million-by-crypto-hackers-but-nearly-all-of-it-was-eventually-returned/

The mention sources can contact us to remove/changing this article

[ad_2]

Related Posts