{"id":10858,"date":"2021-08-12T03:54:25","date_gmt":"2021-08-12T03:54:25","guid":{"rendered":"https:\/\/www.buyucoin.com\/crypto-labs\/poly-network-defi-hacker-returns-a-large-fraction-of-tokens-chainalysis-evaluates-hackers-onchain-movements\/"},"modified":"2021-08-12T03:54:25","modified_gmt":"2021-08-12T03:54:25","slug":"poly-network-defi-hacker-returns-a-large-fraction-of-tokens-chainalysis-evaluates-hackers-onchain-movements","status":"publish","type":"post","link":"https:\/\/www.buyucoin.com\/crypto-labs\/poly-network-defi-hacker-returns-a-large-fraction-of-tokens-chainalysis-evaluates-hackers-onchain-movements\/","title":{"rendered":"Poly Network Defi Hacker Returns a Large Fraction of Tokens, Chainalysis Evaluates Hacker\u2019s Onchain Movements"},"content":{"rendered":"<p><strong>On August 11, the blockchain intelligence firm Chainalysis published its findings on the recent Poly Network hack which saw the loss of approximately $611 million crypto tokens. The assessment from Chainalysis backed up the claims made by the security company called Slowmist that shows the hacker left a fingerprint on the relatively unknown exchange Hoo.com. As of August 11, at 4:18:39 p.m. (UTC), Poly Network details that the hacker has returned $260 million in assets so far. <\/strong><\/p>\n<h2>Chainalysis Observes Hackers Onchain Fingerprints<\/h2>\n<p>The crypto community has been <a href=\"https:\/\/twitter.com\/search?q=poly%20network%20&amp;src=typed_query\">infatuated<\/a> with the recent decentralized finance (defi) hack that exploited the Poly Network protocol. Bitcoin.com News <a href=\"https:\/\/news.bitcoin.com\/poly-network-hacked-for-more-than-600-million-hacker-trolls-project-saying-it-could-have-been-a-billion\/\">reported<\/a> on the aftermath of the hack and how the hacker started to troll the project with onchain messages.<\/p>\n<p>On Wednesday, the blockchain surveillance firm <a href=\"https:\/\/www.chainalysis.com\/\">Chainalysis<\/a> published an <a href=\"https:\/\/blog.chainalysis.com\/reports\/poly-network-hack-august-2021\">in-depth report<\/a> on what it discovered when it investigated the situation. According to Chainalysis, the hacker stole <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ETH\">ETH<\/a>, WETH, WBTC, UNI, RENBTC, <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/USDT\">USDT<\/a>, USDC, DAI, SHIB, FEI, <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/BNB\">BNB<\/a>, and various BEP-20 tokens.<\/p>\n<p>In our most recent <a href=\"https:\/\/news.bitcoin.com\/poly-network-hacker-returns-4-7m-in-funds-attacker-asks-devs-to-unlock-frozen-tether-stash\/\">report<\/a>, Bitcoin.com News discussed how the organization Slowmist claimed to have found some fingerprints left by the hacker. Chainalysis has confirmed some of the findings Slowmist disclosed prior to the hacker sending back roughly $4.7 million in assets.<\/p>\n<p>Slowmist <a href=\"https:\/\/share.api.weibo.cn\/share\/242725121.html?weibo_id=4668781562960148\">said<\/a> that the hacker leveraged an exchange called Hoo.com and it was able to obtain an email address and associated IP address. Chainalysis explained why the hacker chose to leverage the relatively unknown crypto trading platform.<\/p>\n<p>\u201cWe can see that the day before, the attacker withdrew 0.47 <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ETH\">ETH<\/a> from Hoo.com, which was used to pay for gas fees on transactions associated with the hack,\u201d Chainalysis wrote. \u201cAdditionally, the attacker appears to have sent 13.37 <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/ETH\">ETH<\/a> to a user known as Hanashiro.eth, who sent an ether transaction to the attacker with a message <a href=\"https:\/\/etherscan.io\/tx\/0xae2442c5b5721df8c190fd8f59b53b6dc56a875fb03035ad34276a598ddf7d31\">warning them<\/a> that the <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/USDT\">USDT<\/a> they\u2019d stolen from Poly Network had been frozen.\u201d<\/p>\n<p>The blockchain surveillance firm also published a Chainalysis Reactor graph which shows how the hacker got started.<\/p>\n<p>Image via Chainalysis blog post on the Poly Network hack.<\/p>\n<h2>Hacker Compliments Poly Network and Says \u2018Cross-Chain Hacking Is Hot\u2019<\/h2>\n<p>Furthermore, the hacker has been <a href=\"https:\/\/docs.google.com\/spreadsheets\/d\/11LUJwLoHX8ZCyfjhg5YZ0V99iU6PafMNL_NET45FSVc\/edit#gid=0\">communicating<\/a> with the Poly Network team and an unknown white hat hacker. While returning fractions of the funds, the hacker has continuously said that the individual has \u201csaved the project.\u201d<\/p>\n<p><!-- growjs zone placement 31 -->    <!-- end of growjs zone placement --> <\/p>\n<p>There\u2019s been a little Q&amp;A as well and the hacker said that \u201ccross-chain hacking is hot\u201d and he or she was doing it \u201cfor fun.\u201d The discussion highlights that when the hacker spotted the bug, they had \u201cmixed feelings\u201d about the situation. The hacker noted that he or she was \u201ctired\u201d during the conversation and even complimented the Poly Network at times calling it a \u201cdecent system.\u201d<\/p>\n<p>Toward the end of the Chainalysis report, it notes that the hacker has been communicating with the team and the company highlighted some of the token addresses that saw returns.<\/p>\n<p>\u201cIt\u2019s possible this is a ruse to make off with the unstolen <a class=\"lar-automated-link\" href=\"https:\/\/markets.bitcoin.com\/crypto\/USDT\">USDT<\/a>, but so far nothing suggests the attacker won\u2019t continue to return the stolen funds,\u201d Chainalysis detailed. The Poly Network team has been updating the community when coins have been returned via the project\u2019s <a href=\"https:\/\/twitter.com\/PolyNetwork2\">official Twitter account<\/a>.<\/p>\n<p><em><strong>What do you think about the Poly Network defi hack that saw the theft of $600 million? Let us know what you think about this situation in the comments section below. <\/strong><\/em><\/p>\n<p>Bitcoin News<br \/>\nNews, $260 Million, $4.7 Million, $600 Million, Chainalysis, Chainalysis findings, Defi Project, ETH, Hacker, Hacker Troll, Hoo.com, multisig, neo, Poly Network, Poly Network Hack, Poly Network hacker, Poly Network Team, Polygon, Slowmist, tether frozen, USDC, USDT, Wallet, White Hat Hacker<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On August 11, the blockchain intelligence firm Chainalysis published its findings on the recent Poly Network hack which saw the loss of approximately $611 million crypto tokens. The assessment from Chainalysis backed up the claims made by the security company called Slowmist that shows the hacker left a fingerprint on the relatively unknown exchange Hoo.com.&hellip;<\/p>\n","protected":false},"author":0,"featured_media":10859,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[53,3],"tags":[],"class_list":["post-10858","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain-news","category-coin-news"],"_links":{"self":[{"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/posts\/10858"}],"collection":[{"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/comments?post=10858"}],"version-history":[{"count":0,"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/posts\/10858\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/media\/10859"}],"wp:attachment":[{"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/media?parent=10858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/categories?post=10858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.buyucoin.com\/crypto-labs\/wp-json\/wp\/v2\/tags?post=10858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}