|

Poly Network recovers over $258 million of stolen funds in largest DeFi hack

  • Attacker behind the $600 million hack on the Poly network returned $258 million worth of crypto to the cross-chain protocol.
  • The hacker started returning funds merely a day after blockchain security firm SlowMist claimed to obtain the attacker's identity information.
  • By embedding messages to transactions with their own address, the hacker started communicating with the world. 

Poly Network expects to recover stolen funds after writing a letter asking the hacker to return the funds. Currently, less than 1% of the funds have been recovered. 

The largest DeFi hack in history may end in recovery of stolen funds

On August 10, a hacker drained the cross-chain protocol Poly Network of hundreds of millions of dollars. Over $600 million in several cryptocurrencies, Ethereum, Binance smart chain tokens, and stablecoins were stolen.  

The heist included $273 million in Ethereum tokens, $253 million in tokens on Binance Smart Chain, and $85 million in USD coin (USDC). In the aftermath of the attack, Poly Network reached out to exchanges and miners on its Twitter handle and requested them to blacklist the stolen funds. 

Tether was the swiftest to blacklist stolen USDT worth $33 million. Binance, OKEx and other exchanges extended support to Poly Network in the hours following the hack. Among exchanges and protocols coming out in support of the cross-chain protocol, SlowMist stood out since the blockchain security firm claimed to have the hacker's identity (ID) information. 

SlowMist's initial investigation revealed that the hacker used Hoo, a less popular Chinese cryptocurrency exchange, to gather funds for the attack. From Hoo, the blockchain security firm was able to obtain details of their digital footprint. 

Poly Network then reached out to the hacker through an open letter on Twitter, describing the magnitude of the hack and asking them to establish communication and work together to return the stolen funds. 

The team behind the Poly Network prepared a multi-sig address controlled by a known Poly address and identified three addresses where the attacker could return funds. 

Several hours later, the hacker sent the first transaction returning some funds by creating a token called "The hacker is ready to surrender" and sending it over to the designated Polygon address. Seven minutes hence the hacker's Polygon address returned $10,000 in a stablecoin USDC to a wallet set up by Poly Network at 8:46 UTC. 

Another transaction followed, 15 minutes hence, and $1 million was deposited in Poly Network's address.

$1 million in Ethereum returned by hacker

$1 million in USDC recovered from the DeFi hack

Another $1.1 million was returned in Bitcoin Brand (BTCB) on the Binance Smart Chain at 9:49 UTC. 

$1.1 million in BTCB returned on Binance smart chain

$1.1 million in BTCB recovered on the Binance smart chain

At 10:54 UTC, the attacker returned Shiba Inu coins worth $2 million on the Ethereum network. The cross-chain protocol informed users of the recovery through a tweet:

The process of obtaining hacked crypto assets has started. However, it will be a long one, given that the attacker has returned less than 1% of the funds. 

Author

Ekta Mourya

Ekta Mourya

FXStreet

Ekta Mourya has extensive experience in fundamental and on-chain analysis, particularly focused on impact of macroeconomics and central bank policies on cryptocurrencies.

More from Ekta Mourya
Share:

Editor's Picks

Injective token surges over 13% following the approval of the mainnet upgrade proposal

Injective price rallies over 13% on Thursday after the network confirmed the approval of its IIP-619 proposal. The green light for the mainnet upgrade has boosted traders’ sentiment, as the upgrade aims to scale Injective’s real-time Ethereum Virtual Machine architecture and enhance its capabilities to support next-generation payments.

Solana Price Forecast: SOL slips below $82 as hawkish Fed tone sparks risk-off sentiment

Solana is trading below $82 at the time of writing on Thursday after failing to break out of the upper consolidation range over the weekend. The Minutes from the Federal Open Market Committee on Wednesday kept interest rates unchanged, but a less dovish tone that followed dampened risk appetite and pressured risky assets.

Warren warns crypto bailout would enrich Trump family biz: Report

Senate Banking Committee ranking member Elizabeth Warren has reportedly sent a letter to Treasury Secretary Scott Bessent and Federal Reserve chair Jerome Powell, urging them not to bail out “cryptocurrency billionaires” with taxpayer dollars. 

Top Crypto Gainers: World Liberty Financial, Sky, and Cosmos confront major resistance

World Liberty Financial, Sky, and Cosmos rank among the top gainers over the last 24 hours but face critical overhead resistance levels. WLFI gained momentum at the World Liberty Forum, an invite-only conference held at Mar-a-Lago by US President Donald Trump’s family, while SKY and ATOM reversed off a crucial support level. 

Bitcoin Price Annual Forecast: BTC holds long-term bullish structure heading into 2026

Bitcoin (BTC) is wrapping up 2025 as one of its most eventful years, defined by unprecedented institutional participation, major regulatory developments, and extreme price volatility.

Bitcoin: BTC bears aren’t done yet

Bitcoin (BTC) price slips below $67,000 at the time of writing on Friday, remaining under pressure and extending losses of nearly 5% so far this week.