📈 Get daily crypto insights that make you smarter about your money

Poly Network Cross-Chain Bridge Compromised: How Forged Relays Minted Billions in Fake Tokens

The decentralized finance ecosystem faced another severe security incident as Poly Network, a cross-chain interoperability protocol, fell victim to a sophisticated exploit that allowed attackers to mint billions of dollars worth of fraudulent tokens across multiple blockchains. The attack, which surfaced over the weekend of July 1, 2023, exposed critical vulnerabilities in the way cross-chain bridges verify and relay transaction data between networks.

The Exploit Mechanics

The attacker exploited a vulnerability in Poly Network’s cross-chain messaging mechanism, specifically targeting the protocol’s relay chain verification process. By manipulating the way the bridge validated cross-chain transactions, the attacker was able to forge transaction proofs that made it appear as though legitimate token transfers were occurring. In reality, the attacker was minting new tokens out of thin air on destination chains without corresponding locks on the source chain.

Blockchain security firm PeckShield estimated that approximately $42 billion worth of cryptocurrency tokens were minted during the attack, while another firm, Dedaub, placed the figure at around $34 billion. However, the actual extractable value was far lower due to limited liquidity on decentralized exchanges. Security firm Beosin reported that approximately 5,196 ETH, worth roughly $10 million at the time, was actually stolen and could be liquidated by the attacker.

The discrepancy between the minted face value and realizable losses highlights a common pattern in cross-chain bridge exploits: attackers can create enormous notional values, but converting them to spendable assets depends entirely on available market liquidity.

Affected Systems

The attack impacted 57 distinct crypto assets across 10 different blockchains, including Ethereum, Binance’s BNB Chain, Metis, and Polygon. Poly Network confirmed the scope in a public statement, sharing a detailed spreadsheet listing all affected assets and their corresponding blockchain networks. The wide reach of the attack underscores how a single vulnerability in a cross-chain protocol can cascade across an entire multi-chain ecosystem.

Several other DeFi platforms with integration ties to Poly Network were forced to take emergency action. Multiple projects announced emergency liquidity withdrawals from decentralized exchanges to prevent further exploitation. Binance CEO Changpeng Zhao publicly stated that the incident did not affect Binance users directly, as the exchange did not support deposits from the compromised network.

The Mitigation Strategy

Poly Network responded by immediately suspending all services and initiating communication with centralized exchanges and law enforcement agencies. The team urged all projects holding affected assets to promptly withdraw liquidity from decentralized exchanges and advised individual users to expedite the process of withdrawing liquidity and unlocking their LP tokens.

Security firms including PeckShield, Beosin, and MetaSleuth collaborated to trace the stolen funds in real time. Their analysis revealed that the attacker held approximately 2,266 ETH (around $4.3 million at the time) with additional crypto assets that needed valuation based on liquidity and price volatility. Approximately $260 million worth of BNB was also taken but was unlikely to be cashed out due to low liquidity on affected platforms.

Lessons Learned

This incident bears a striking resemblance to Poly Network’s first major exploit in August 2021, when over $610 million was stolen in what was then the largest DeFi hack in history. That the same protocol suffered a second catastrophic breach raises serious questions about the adequacy of security audits and the pace of vulnerability remediation in cross-chain infrastructure. Key takeaways include:

  • Cross-chain bridges remain the weakest link in DeFi security. Their complexity — managing state across multiple independent blockchains — creates attack surfaces that single-chain protocols do not face.
  • Minting-based exploits can create panic far exceeding actual losses. Users and investors should distinguish between notional minted values and realizable theft when evaluating the severity of bridge hacks.
  • Repeated breaches erode trust permanently. Protocols that suffer multiple major incidents face an uphill battle to maintain user confidence and institutional partnerships.
  • Rapid incident response coordination between security firms, exchanges, and affected projects is critical to minimizing real losses during active exploits.

User Action Required

If you held assets on Poly Network or any integrated platform during the July 1 attack window, take the following steps immediately. First, check the official Poly Network spreadsheet listing all 57 affected assets to determine whether your holdings are at risk. Second, revoke any outstanding token approvals connected to Poly Network contracts using tools like Revoke.cash or Etherscan’s token approval checker. Third, move remaining assets to a fresh wallet address as a precaution against any undiscovered backdoors or secondary exploits. Finally, monitor official Poly Network channels for updates on fund recovery efforts and any proposed compensation plans. Bitcoin was trading at approximately $30,590 and Ethereum at $1,924 at the time of the incident, providing context for the real-dollar value of stolen assets.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Always conduct your own research before making any financial decisions.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Poly Network Cross-Chain Bridge Compromised: How Forged Relays Minted Billions in Fake Tokens”

  1. $42B in minted tokens from forged relay proofs. the fact that a cross-chain bridge didn’t verify transaction data properly is negligence not a hack

  2. relay_auditor_

    PeckShield said $42B, Dedaub said $34B. the fact that two security firms disagreed by $8B on the same exploit tells you how chaotic bridge security was in mid-2023

    1. cross-chain bridges remain the weakest link in DeFi. Chainalysis identified 70% of all crypto thefts in 2023 came from bridge exploits

  3. forged relay proofs enabling unlimited minting. every bridge that relies on a trusted relayer set has this exact same vulnerability

    1. 42B vs 34B is a 23 percent gap. for a security firm thats basically saying we have no idea. bridge monitoring is still in the stone age

  4. PeckShield putting the minted total at $42B and Dedaub at $34B. when the numbers are that far apart you know the situation is messy

    1. 42B vs 34B is a 20% difference. when security firms cant even agree on the damage amount you know the monitoring tools need work

      1. relay_check 20% variance between security firms is embarrassing. we need standardized bridge monitoring not competing estimates

        1. peckshield_gap

          Tamara Osei 20% variance between PeckShield and Dedaub on a july 1 2023 exploit shows how raw bridge monitoring still is. 42B vs 34B is a 8 billion dollar disagreement

    2. the discrepancy is because different firms count different token pools across different chains. the real number is somewhere in between but either way its massive

    3. minting tokens on destination chains without locks on the source. this is the exact same class of bug as Wormhole and Nomad. bridges never learn

  5. the attacker minting tokens without corresponding locks on the source chain is the oldest bridge attack in the book. how does this still happen in 2023

    1. Priya S. because bridge developers keep reinventing the wheel instead of usingbattle-tested verification layers. every new bridge thinks they solved it

    2. mint_without_lock

      Priya S. minting on destination chains without locks on the source is literally the exact vulnerability Wormhole had. same class of attack one year apart and nobody learned

      1. minting tokens on destination chains without locks on the source is the same vulnerability Wormhole had. same class of attack, one year apart, nobody learned anything

      2. mint_without_lock Cosmos IBC exists since 2021 and Poly Network still used trusted relayers in 2023. the bridge space keeps shipping the same bug with a new name

        1. cosmos_ibc_kep

          fault_inject_ Cosmos IBC solved this by having the source chain verify the destination. Poly Network using trusted relayers in 2023 when IBC was battle-tested since 2021 is pure hubris

  6. Poly Network got hit for 42B in fake tokens because their relay verification was basically a yes button. Cosmos IBC solved this in 2021 with light client verification but bridges keep reinventing trusted relayers

  7. PeckShield said $42B, Dedaub said $34B. an 8 billion dollar disagreement between two professional security firms tells you bridge monitoring is completely broken

    1. PeckShield said 42B, Dedaub said 34B. an 8 billion gap between two professional security firms tells you bridge forensics is basically guesswork

    2. bridge_audit_skip

      relay_fault_ the 8B gap was because Poly Network minted across 8 different chains and each firm counted different token contracts. its not bad monitoring its genuinely hard to track fake tokens across fragmented liquidity

      1. mint_forensics_

        bridge_audit_skip tracking fake mints across 8 chains is genuinely hard but thats the job. security firms disagreeing by 8B means nobody has a reliable methodology

  8. $42B vs $34B between two reputable firms is a 20% gap. imagine your bank being off by 20% on your balance and thats basically the state of bridge monitoring

    1. Bea H. 20% measurement gap between firms is wild. bridges need canonical asset registries or this keeps happening silently

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$63,918.00-2.0%ETH$1,872.56-2.7%SOL$76.14-1.7%BNB$598.68-1.7%XRP$1.01-3.2%ADA$0.1919-3.3%DOGE$0.0696-1.4%DOT$0.8055-0.5%AVAX$6.42-2.1%LINK$8.26-1.1%UNI$3.95-3.8%ATOM$1.40+0.6%LTC$45.04-2.2%ARB$0.0793-1.3%NEAR$1.60-2.3%FIL$0.6991-2.0%SUI$0.6839-2.6%BTC$63,918.00-2.0%ETH$1,872.56-2.7%SOL$76.14-1.7%BNB$598.68-1.7%XRP$1.01-3.2%ADA$0.1919-3.3%DOGE$0.0696-1.4%DOT$0.8055-0.5%AVAX$6.42-2.1%LINK$8.26-1.1%UNI$3.95-3.8%ATOM$1.40+0.6%LTC$45.04-2.2%ARB$0.0793-1.3%NEAR$1.60-2.3%FIL$0.6991-2.0%SUI$0.6839-2.6%
Scroll to Top