Poloniex Hack

Reported loss $50K
Bitcoin
Withdrawal Logic Flaw

What happened

In the early hours of March 4, 2014, an attacker took 97 BTC from the Poloniex exchange, about 12.3% of the bitcoin it held, by abusing a race condition in its withdrawal code. Poloniex owner Tristan D'Agosta disclosed the attack on BitcoinTalk the same day.

D'Agosta explained that if several withdrawals were placed at practically the same instant, they were processed at more or less the same time. The account went negative, but each withdrawal was still written to the database as valid and then picked up by the withdrawal daemon, which sent the coins.

Poloniex cut every customer's BTC balance by 12.3% to spread the loss, arguing that otherwise users would rush to withdraw and leave the last 12.3% with nothing. It temporarily raised trading fees from 0.2% to 1.5% to fund repayment. It rebuilt withdrawals to run one at a time from a global command queue and made the withdrawal daemon check for negative balances before sending. On July 2, 2014, Poloniex said all affected customers had been repaid from its trading profits: "97 BTC were taken and 97 BTC were paid back," as D'Agosta put it.

How it happened

  1. The attacker submitted several BTC withdrawal requests from a Poloniex account at practically the same instant.
  2. Poloniex processed the requests at more or less the same time, so all of them were written to the database as valid withdrawals even though together they pushed the account into a negative balance.
  3. The withdrawal daemon picked up those rows and sent the coins without checking for a negative balance, paying out 97 BTC in total.

Protocol details

Classification Protocol Logic / CeFi
Protocol Type CEX
Protocol links Website @Poloniex

Funds Recovery

100.0%

Recovered

$66K

Net Loss

$0

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.