True crime news logo
  • Krimidex

Sign up for our newsletter and get the latest stories

Never miss the latest true crime news, reviews and top lists — plus new podcasts, series, films and books.

You can unsubscribe with one click from any email.

True crime news logo

The international true crime destination. Cases, documentaries, podcasts and travel routes.

© 2026 truecrime.news. All rights reserved.

Sagsmappe

Hacker Steals $610M in Crypto, Then Returns It All

In what became the largest DeFi hack to date, an unknown attacker exploited Poly Network's smart contracts—then gave the money back

A computer screen displays the Poly Network logo in an office setting, with multiple open browser tabs showing cryptocurrency transactions detailing the return of $600 million dollars.
BEVIS

Sagsdetaljer

Quick Facts

Klassifikation:

Crypto
Economic crime
Fraud
Internet
Money laundering
Conspiracy theory
Money

An unidentified hacker breached Poly Network, a decentralized finance platform facilitating peer-to-peer token exchanges across blockchain networks, stealing $610 million in cryptocurrencies in August 2021. The theft marked the largest DeFi hack on record at the time, but the attacker's next move confounded the industry: they gave nearly all of it back.

The stolen funds were distributed across three major blockchain networks. Approximately $273 million in Ethereum tokens were taken, along with $253 million from Binance Smart Chain and $85 million in Polygon stablecoins. The hacker targeted at least 12 different cryptocurrencies in total, exploiting a vulnerability in Poly Network's smart contract calls, according to the platform's forensic investigation.

Poly Network announced the theft and immediately called for action. The platform threatened legal consequences, offered a $500,000 reward for information, and urged cryptocurrency exchanges and token issuers to blacklist the attacker's wallet addresses. The company's statement emphasized that thousands of users had been affected by the breach.

What happened next was unprecedented in cryptocurrency crime. Within a day of the theft, the hacker began returning funds. By the second day, partial recovery was underway, with $4.77 million in assets already restored. The attacker subsequently returned the vast majority of the stolen cryptocurrency, ultimately recovering all funds for Poly Network.

The hacker's methods during the recovery phase were equally unusual. They locked over $200 million in cryptocurrency in an account protected by dual passwords—one controlled by the attacker and one by Poly Network—effectively preventing either party from accessing the funds alone. This forced cooperation ensured the platform's participation in the final recovery process.

Data breach
kryptovaluta
blockchain
justitsmordet
hvidvaskning
cybersikkerhed
Sagsstatus
Løst

Messages appended to blockchain transactions offered clues to the attacker's motives, though interpretations varied across reporting. The hacker claimed the breach was "for fun" and suggested they were "hacking for good" and had "saved the project." Some sources indicate the attacker described themselves as conducting security testing and contributing to Poly Network's security improvements. Poly Network subsequently referred to the perpetrator as "Mr. White Hat," adopting the terminology used for ethical hackers who expose vulnerabilities responsibly.

Blockchain security firm SlowMist tracked the transfers and identified the hacker through email addresses, IP addresses, and device fingerprints, though this information did not lead to a public identification or arrest. When the attacker requested compensation for their work, they reportedly received approximately $200 in donations. Poly Network's $500,000 reward offer remained outstanding.

Tether, the issuer of USDT stablecoins, froze approximately $33 million in tokens held in the hacker's wallets, a significant barrier to converting stolen assets into traditional currency. Analytics firm Elliptic tracked approximately $258 million of the returned funds and noted that the transparent nature of blockchain technology had made it exceptionally difficult for the hacker to launder the stolen cryptocurrency through conventional methods.

The incident illustrated the growing vulnerability of decentralized finance platforms. Data from CipherTrace revealed that $156 million had been stolen in DeFi hacks during the first five months of 2021 alone, compared to $129 million across all of 2020—a dramatic acceleration in attack frequency and sophistication.

As of the latest available reports, no arrests, prosecutions, or legal verdicts related to the Poly Network hack have been announced. The case remains a singular event in cryptocurrency crime: a record-breaking theft followed by a complete recovery and an attacker who, for reasons still unexplained, chose to return what they had taken.

**Sources**

https://www.occrp.org/en/news/hacker-steals-us610-million-in-cryptocurrency-then-gives-it-back

https://www.engadget.com/the-morning-after-crypto-heist-hacker-returns-all-610-million-they-stole-111630131.html

https://www.investmentnews.com/alternatives/hackers-return-funds-from-likely-record-crypto-attack/210186

https://worldecomag.com/the-crypto-heist-hacker-returns-the-610-million/

Timeline

10 August 2021

Angriff auf Poly Network

Ein unbekannter Hacker stiehlt rund 610 Millionen Dollar durch Ausnutzung einer Schwachstelle in den Smart Contracts der Plattform.

13 August 2021

Erste Rückgabe

Der Hacker gibt innerhalb von zwei Tagen 342 Millionen Dollar zurück. 268 Millionen Dollar bleiben in einer Multi-Signatur-Wallet gesperrt.

13 August 2021

Angebot von Poly Network

Poly Network bietet dem Hacker eine Belohnung von 500.000 Dollar und eine Stelle als Chief Security Advisor an – beide Angebote werden abgelehnt.

18 August 2021

Nahezu vollständige Rückgabe

Fast alle Gelder sind zurückgegeben, mit Ausnahme von 33 Millionen Dollar in USDT-Tokens, die von Tether eingefroren wurden.

18 August 2021

Freigabe des privaten Schlüssels

Der Hacker teilt den privaten Schlüssel zur Multi-Signatur-Wallet über eine Blockchain-Nachricht, sodass Poly Network Zugriff auf die restlichen Vermögenswerte erhält.

Read more

A computer screen displays Binance's cryptocurrency dashboard, a red alert notification flashing next to the balance showing a missing 7,000 bitcoin, symbolizing the massive cyberattack that rocked the exchange.
Case

Hackers Steal $570 Million in Binance Coin Cyberattack

The Missing Cryptoqueen uncovers cryptocurrency pitfalls
Podcast

BBC Podcast Exposes OneCoin: The $4 Billion Crypto Scam

Dirty Billions expose money laundering at Danske Bank
Book

Danske Bank's $230 Billion Money Laundering Scandal

Related Content
A computer screen displays Binance's cryptocurrency dashboard, a red alert notification flashing next to the balance showing a missing 7,000 bitcoin, symbolizing the massive cyberattack that rocked the exchange.

Hackers Steal $570 Million in Binance Coin Cyberattack

The Missing Cryptoqueen uncovers cryptocurrency pitfalls

BBC Podcast Exposes OneCoin: The $4 Billion Crypto Scam

Dirty Billions expose money laundering at Danske Bank

Danske Bank's $230 Billion Money Laundering Scandal

American Greed exposes the dark world of financial crime

American Greed: How CNBC Documents White-Collar Crime

Advertisement
SS

Susanne Sperling

Se alle artikler →
Del dette opslag: