Poloniex Hack
Incident Overview
Poloniex exchange suffered a 122,981,391 USD access control exploit affecting Bitcoin, Ethereum, and Tron wallets on Nov 10, 2023.
An attacker exploited Poloniex's wallet, withdrawing funds across Bitcoin, Ethereum, and Tron chains. The stolen assets were exchanged to native tokens and transferred to newly generated EOA addresses. Justin Sun, owner of the exchange, offered a 5% bug bounty to the hacker and gave them 7 days before involving law enforcement.
Market research platform X-explore suggests the Lazarus Group, a North Korea-backed cybercriminal entity, may be responsible.
Ethereum:
Attacker Address:
https://etherscan.io/address/0x0a5984f8…dbf9e7
Affected Address:
https://etherscan.io/address/0xa910f92a…7722ba
Malicious Transactions:
- https://etherscan.io/tx/0x686429f0…31a8a5
- https://etherscan.io/tx/0x4ecd5131…a3eca0
Bitcoin:
Attacker Address:
https://www.blockchain.com/explorer/addresses/btc/bc1qnpc7u2ha7ct9c458rrqsawylz9e9j6jvkvzttt
Affected Address:
https://www.blockchain.com/explorer/addresses/btc/1H1YS6GyCPyA5Q6rmx58UzmeeDd3wXuFpN
Malicious Transaction: https://www.blockchain.com/explorer/transactions/btc/ee4bb55722d1a89e1a0f63d9c561ea34eaa1c6e37d051437d388bce9145b4d5f
Tron:
Attacker Address:
https://tronscan.org/#/address/TKK6d1YALy8HCSoCSWWd1ZJhyC9NPPx4wa
Affected Address:
https://tronscan.org/#/address/TNCmcTdyrYKMtmE1KU2itzeCX76jGm5Not
Malicious Transaction: https://tronscan.org/#/transaction/0e972904705e54074d8e135c111fc276d87f846398b07d8a05e0515d78fd19c4
Incident Report
Protocol Information
What the Attacker Needed to Succeed
Understanding the prerequisites for this type of attack helps auditors identify protocols that are most at risk and helps developers build better defenses.
What Auditors Should Check
If you're auditing a protocol with similar architecture to Poloniex, these are the critical security checks that could have prevented this incident (November 2023).
- Verify all logic paths related to Private Key Compromised (Unknown Method) / Access Control are guarded by proper access controls and input validation - see the Access Control Attacks attack class for patterns
- Review privileged functions (owner, admin, governance) for potential abuse vectors - centralization risks should be documented and bounded with timelocks or multi-sigs
Master these auditing techniques with hands-on labs and real exploit scenarios in the Smart Contract Hacking course.
Free TrialRelated Attack Classes
The technique used in this hack maps to these vulnerability classes in our security curriculum:
Sources & References
- 01
-
02
Web Archive https://archive.li/KzYNw
- 03
- 04
- 05
Learn to Prevent the Next Poloniex
The Poloniex hack is one of many attacks that skilled auditors are trained to detect before deployment. Master real exploit patterns and defense techniques with hands-on Web3 security training.