Poly Network disclosed on August 10, 2021 that an attacker had moved assets from its cross-chain system to addresses on Ethereum, Binance Smart Chain and Polygon. Contemporaneous transaction analysis put the transferred assets at at least $611 million, making the incident the largest decentralized-finance exploit then reported.
The scale was only part of its importance. Poly Network was designed to connect otherwise separate blockchains, so one authorization failure propagated across several networks. The incident exposed cross-chain infrastructure as a concentrated security boundary even when the assets and users it served were distributed.
Three chains, one incident
Poly Network identified attacker-controlled addresses on Ethereum, Binance Smart Chain and Polygon and asked miners and exchanges to block assets coming from them. Chainalysis’s August 12 analysis confirmed those three addresses and catalogued stolen ETH, wrapped assets, stablecoins and other tokens.
The Block’s August 10 chain-by-chain estimate was $273 million in Ethereum tokens, $253 million in Binance Smart Chain tokens and $85 million in USDC on Polygon. Adding those rounded components produces $611 million. Chainalysis used a slightly different valuation of $612 million. Neither figure was an audited cash loss: each converted a changing basket of tokens into dollars around the initial-transfer window, and the publishers did not disclose a single common price timestamp for every asset. The defensible event-day description is therefore “at least $611 million,” not a precision claim about final damages.
Public ledgers made the outflows observable, but visibility did not make them reversible. Tether blacklisted roughly 33.4 million USDT associated with the Ethereum address, according to contemporaneous reporting. That intervention showed a distinction among the stolen assets: a centrally administered token issuer could freeze its token, while other transfers depended on protocol controls, exchanges and the attacker’s next actions.
The authorization failure
Inspex published a transaction-level investigation on August 10. It traced the Binance Smart Chain withdrawal through Poly Network’s `LockProxy` and `EthCrossChainManager` contracts. Its analysis found that a cross-chain call could reach the function that changed the keeper public key stored by `EthCrossChainData`. Once the attacker controlled that authorization state, a forged cross-chain message could pass verification and call the asset-unlock path.
That is a technical reconstruction from contract code and transactions, not proof of the attacker’s identity or intent. Poly Network’s September 2 postmortem cited independent analyses of the same flaw and described the response as an effort to lock assets, identify vulnerabilities and contact issuers. The postmortem strengthens the mechanism assessment, but it was not information available at the start of August 10.
The structural lesson was already visible on August 10. A bridge can distribute liquidity across networks while still depending on privileged verification logic. If that logic can be rewritten or deceived, the bridge may authorize valid-looking withdrawals on destination chains without a legitimate originating transaction.
What was unresolved on August 10
The controller of the three addresses had not been publicly identified. Claims that security firms possessed identifying data were not independently verified, and address control alone could not establish a person, location or motive. The amount ultimately recoverable was also unknown.
Poly Network’s September 2 account said more than $610 million in affected assets was restored within 15 days. That retrospective outcome was not knowable on August 10 and does not reduce the event-day severity: the protocol had suffered an authorization failure capable of moving assets across three networks, and users did not yet have a completed recovery or final forensic report.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

