On August 10, 2021, someone drained roughly $610 million from Poly Network, a cross-chain interoperability protocol that lets users move tokens between different blockchains. It was, at the time, the single largest theft in decentralized finance history.
Then something weird happened. The hacker started sending the money back.
The heist and the return
The attacker exploited a vulnerability in Poly Network’s smart contracts, siphoning funds across three separate blockchains: Ethereum, Binance Smart Chain, and Polygon.
But within 24 hours, the person behind the exploit began returning tokens. By August 12, Poly Network confirmed the recovery of $342 million. The breakdown: $252 million from Binance Smart Chain, $85 million from Polygon, and $4.6 million from Ethereum.
The attacker, who the crypto community quickly dubbed “Mr. White Hat,” communicated their motives through on-chain messages embedded in transactions. Their claim: the whole thing was about exposing a critical vulnerability, not keeping the funds.
How the exploit worked
Poly Network’s vulnerability sat in its smart contract logic governing cross-chain transactions. The attacker found a way to trick the protocol into releasing funds it shouldn’t have, essentially convincing the system that it had been authorized to move tokens when no such authorization existed.
By late August 2021, Poly Network had regained control of the remaining assets through continued cooperation with the hacker. That included approximately 28,953 ETH and 1,032 WBTC. The only funds that didn’t make it back were $33 million in Tether, which the stablecoin issuer had frozen shortly after the hack was discovered.
Tether’s ability to freeze those tokens demonstrated that certain crypto assets aren’t as decentralized or censorship-resistant as their holders might assume.
White hat or cold feet?
The hacker described their actions via on-chain messages, emphasizing intent to reveal a vulnerability rather than to retain the stolen funds permanently.
Poly Network’s response was notably conciliatory. Rather than pursuing maximum legal action, the protocol engaged with the attacker and facilitated the return of funds.
The incident did accelerate conversations about bug bounty programs across DeFi. Many protocols have since implemented or expanded bounty systems that offer six- and seven-figure payouts for critical vulnerability disclosures.
What the Poly Network hack changed
The $610 million exploit forced a reckoning with how DeFi handles crisis response. Poly Network’s ability to recover the vast majority of funds was partly luck, the hacker chose to return them, and partly the result of rapid coordination between the protocol, blockchain analytics firms, exchanges, and even Tether’s compliance team.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 week ago
59








English (US) ·