Poly Network Hack

Reported loss $611.0M
Ethereum BNB Chain Polygon
Privileged keeper replacement through unconstrained cross-chain call

What happened

Poly Network's cross-chain bridge was exploited on Ethereum, BNB Smart Chain, and Polygon on August 10, 2021. Contemporaneous estimates placed the transferred assets at roughly $610 million to $612 million; the figure shown here is $611 million. Poly later reported recovery of all affected user assets worth $610 million.

Technical root cause

A user-controlled cross-chain operation could reach a privileged keeper-update function through the bridge manager's general dispatch path. Cross-chain execution must restrict callable target contracts and methods, and privileged key-management state must not be reachable through relayed user data. Poly's later changes added limits and whitelists for callable contracts and methods.

How it happened

  1. Poly's EthCrossChainManager accepted an insufficiently constrained cross-chain target and method, then dispatched the decoded call after normal relay verification.
  2. Because the manager owned the EthCrossChainData keeper registry, crafted call data could reach putCurEpochConPubKeyBytes and replace the keeper with an attacker-controlled key.
  3. The new keeper authority could then authorize otherwise-valid bridge messages and release assets from LockProxy custody across the affected chains.
  4. The failure did not rely on a leaked pre-existing keeper key.

Protocol details

Classification Cross-chain Bridge / Keeper Authorization Takeover
Protocol Type Bridge
Category Bridge Hack
Implementation language Solidity
Protocol links Website @PolyNetwork2

Security review history

Funds Recovery

98.6%

Recovered

$602.2M

Net Loss

$8,554,000

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.