Poly Network Loses $4.4M as Multisig Signers Approve Forged Withdrawals
Poly Network, the cross-chain protocol that suffered a record-setting $600M+ hack roughly two years earlier, was exploited again — this time for a comparatively modest $4.4 million. Where the first incident stemmed from a deep contract-logic flaw, this one came down to something far more mundane: a multisig that didn't hold.
01What happened

Three of the bridge's four multisig signers approved deposit proofs that had been forged, giving the attacker the access needed to authorize withdrawals the protocol never actually received. The method was straightforward: lock a small amount of a given token on one chain, then use the compromised signing process to withdraw a much larger amount of the corresponding asset on a different chain. The attacker repeated this pattern across multiple assets and multiple chains.
A detailed technical breakdown of the exploit is available from Dedaub.
Poly Network eventually acknowledged the attack, announcing that bridging services had been paused and appealing to the wider security community for assistance. A follow-up statement specified that 57 assets across 10 blockchains had been affected, with a full breakdown by chain published separately.
02Scale of the numbers
As with the 2021 incident — where headline figures dwarfed the combined total of every other hack tracked at the time — initial reporting focused on eye-catching notional figures. Early estimates, including one from CertiK, put the notional value of assets minted by the attacker at roughly $42 billion. That number reflected what the forged proofs could theoretically claim, not what was actually extracted.
In practice, thin liquidity on the destination chains capped what the attacker could convert into real value. Despite minting claims reaching into the tens of billions notionally, only around $4.4 million of Poly's actual liquidity was accessible, with additional assets left sitting untouched in the attacker's wallet.
Attacker's primary Ethereum address: 0xe0Afadad1d93704761c8550F21A53DE3468Ba599
Sample transactions: deposit on Ethereum — 0x1b8f8a38…; withdrawal on BSC — 0x5c70178e…
EthCrossChainManager contract: 0x14413419452aaf089762a0c5e95ed2a13bbc488c

03The broader pattern
Cross-chain bridges concentrate liquidity at chokepoints, and that liquidity is frequently protected by a small number of externally-owned accounts rather than more robust validation. The same underlying weakness has surfaced before and again, with hundreds of millions of dollars lost across the industry to compromises of just a handful of signing keys. Notably, when Lazarus Group breached the Ronin bridge and displaced Poly Network from the top of the loss rankings, that attack required compromising 5 of 9 validator keys — a higher bar than the 3-of-4 threshold that failed here.
Poly Network's first hack ended with an unusual resolution: on-chain negotiation led to the return of the stolen funds, and the attacker was even offered a Chief Security Advisor position along with a $500,000 bounty. This second incident, while far smaller in dollar terms, again raises the question of whether the protocol's key-management practices have kept pace with the risks bridges of its size are exposed to.
Get new scam files the moment we publish them — usually 2–3 emails a week.