On 10 August 2021 Poly Network said it had been attacked on Ethereum, BNB Chain and Polygon. On the order of $610 million in tokens moved to addresses the attacker controlled — later tallies split the pile roughly as $273 million on Ethereum, $253 million on BNB Chain, $85 million on Polygon. Tether froze about $33 million USDT. The next day the attacker, messaging on-chain as a self-styled white hat, said they would return funds to expose the hole. Returns started 11 August. Poly called them a white hat. Security people who do actual white-hat work were not amused. Full recovery, including the thawed USDT, was announced 25 August — later, not this day’s lede.
This is not Wormhole (Solana signature check, 2022) and not Ronin (validator keys, 2022). Cross-chain message verification with a privileged keeper is its own failure mode. Do not write a how-to. The contract did what the privileged path allowed.
What happened
Poly moves tokens between chains by locking on one side and minting on another. If the message that says “lock happened” can be forged or a keeper can be told to reassign authority, the mint is unbacked and the pool drains. Users of the protocol had a claim on a bridge. Users of ether who never touched Poly had a red candle and a headline.
Why it matters
Make-whole by a thief who changed their mind is not a security model. Neither is a bounty offered after the fact. If your coins were in that lockup, you spent a week as a spectator. See how crypto wallets actually work. See the practical checklist. We will not romanticise the return as a community win.
What happens next
Multisigs, a post-mortem, and larger bridge thefts that do not come back. Nothing here is an instruction to bridge, unwrap, buy, or sell.






