Newsdeck

World

Hackers Return Funds From Likely Record DeFi Crypto Attack

(Photo: Chris Ratcliffe / Bloomberg)

Hackers returned about half of the $610 million or so they pilfered Tuesday in what was likely one of the biggest cryptocurrency thefts on record in the burgeoning DeFi sector.

By Olga Kharif and Kartikay Mehrotra

Word Count: 422
(Bloomberg) — 

In a unusual twist, the online thieves pledged to return the entire amount stole from a decentralized finance, or DeFi, protocol known as PolyNetwork that lets users swap tokens across multiple blockchains. It isn’t clear from the PolyNetwork website who runs the protocol.

In a message the unidentified hackers said that they “just dumped all the assets,” adding, “hacking for good, I did save the project.” About $260 million has been returned so far, according to Tom Robinson, co-founder of blockchain forensics firm Elliptic.

Even more brazen, the hackers are asking for donations as a reward for returning the funds. So far, they’ve garnered $200, Robinson said.

The hackers also posted a Q&A online, explaining motivations for the attack as “for fun:).” The online pirates said they took the funds “to keep it safe” after spotting a bug in the computer code. The hackers ended the missive saying they will be impossible to trace. “I prefer to stay in the dark and save the world.”

Blockchain security researcher SlowMist had said that it’s found the attackers’ email address, IP address and device fingerprint.

Elliptic, as well as scores of cryptocurrency exchanges and trackers, have been on the hunt for the hackers. Thousands of people were affected by the attack, PolyNetwork said in a letter posted Tuesday on Twitter.

“This demonstrates that even if you can steal crypto assets, laundering them and cashing out is extremely difficult, due to the transparency of the blockchain and the use of blockchain analytics,” Robinson said. “In this case the hacker concluded that the safest option was just to return the stolen assets.”

Read More: Latest Hack Shows Power of Stablecoins in Decentralized Finance

The heist netted 11 different cryptocurrencies, including $93 million in Ether, according to blockchain researcher Chainalysis, which tracked some of the hackers’ transactions. The attacker had attempted to launder part of the money by using PolyNetwork to cash in Dai and USDC coins and converting them all back to Dai, Chainalysis said.

DeFi apps — which let people lend, borrow and trade coins without using intermediaries — have become frequent targets of attacks lately, as they gain in popularity. Some $156 million was netted from DeFi-related hacks in the first five months of the year, surpassing the $129 million stolen in such attacks through all of 2020, according to crypto security firm CipherTrace.

(Updates with additional information about the attack)
© 2021 Bloomberg L.P.
Gallery

Comments - Please in order to comment.

Please peer review 3 community comments before your comment can be posted

We would like our readers to start paying for Daily Maverick...

…but we are not going to force you to. Over 10 million users come to us each month for the news. We have not put it behind a paywall because the truth should not be a luxury.

Instead we ask our readers who can afford to contribute, even a small amount each month, to do so.

If you appreciate it and want to see us keep going then please consider contributing whatever you can.

Support Daily Maverick→
Payment options