
Hackers have successfully exploited a vulnerability in Poly Network and stolen over $600 million, making this the largest hack in recorded history.
The hackers were able to change the "keeper role" of a blockchain contract, allowing them to make any transaction, such as a withdrawal. The vulnerability was due to a keeper’s private key being leaked.
Poly Network, a decentralised finance platform that facilitates peer-to-peer transactions, confirmed that they have “the attacker’s mailbox, IP and device fingerprints through on-chain and off-chain tracking.”
Poly Network confirmed the attack on Tuesday on Twitter and urged the hackers to ’return the hacked assets’.
And surprisingly, the request seems to have worked. Hackers have since gotten in contact and have returned almost half of the stolen assets.
They sent a message to Poly Network embedded in a cryptocurrency transaction saying they were “ready to return” the funds. Poly Network responded requesting the money be sent to three crypto addresses.
One of the hackers has supposedly claimed that they carried out the attack "for fun" and wanted to "expose the vulnerability" before others could exploit it, according to digital messages shared by Elliptic, crypto tracking firm, and Chainalysis.
It was "always the plan" to return the tokens, the purported hacker wrote, adding: "I am not very interested in money."
Tom Robinson, Co-Founder of Elliptic, said the decision to return the money could have been prompted by the headaches and difficulties of laundering stolen crypto on such a large scale.
"Even if you can steal crypto-assets, laundering them and cashing out is extremely difficult, due to the transparency of the blockchain and the broad use of blockchain analytics by financial institutions," said Robinson.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543