Poly Network suspended its cross-chain services on July 2, 2023 after an attacker caused unauthorized token issuance across multiple networks. The protocol said 57 assets on 10 blockchains were affected and asked cybersecurity specialists for help while it assessed the incident.

That was the consequential fact available on July 2: a bridge designed to carry instructions between chains had accepted messages that should not have been trusted. Poly Network contacted centralized exchanges and law-enforcement agencies, urged affected project teams to withdraw decentralized-exchange liquidity, and advised holders of affected assets to unlock liquidity-provider positions. The shutdown limited further bridge activity, but it did not by itself establish how the attacker obtained authority or how much value could actually be realized.

A huge balance was not a huge realized loss

Security monitors reported that the attacker had created enormous quantities of tokens on destination chains. Some dashboards assigned those balances a notional value above $34 billion. That figure was a mechanical mark using displayed token prices, not an estimate of cash proceeds, recoverable value or protocol liabilities. Many of the newly issued tokens had little or no liquidity at those quantities, so selling them at quoted prices was impossible.

SlowMist's incident record dates the attack to July 2 and says its tracking later identified more than $10 million in mainstream-asset proceeds. That is later incident-level accounting, not a number that was fully settled during the first hours. A contemporaneous July 2 update cited by Odaily put identified mainstream assets at $4.39 million and said $1.22 million of certain tokens had been swapped through Uniswap and PancakeSwap at that stage. Those figures describe different observation windows and categories; they should not be added together or treated as a final loss total.

The distinction mattered. The attacker could mint a token balance whose screen value looked extraordinary without finding enough buyers or pool liquidity to convert it. The market impact was therefore concentrated in affected assets and liquidity venues rather than equivalent to a $34 billion withdrawal from the broader crypto market.

The trust boundary behind the bridge

Dedaub's July 2 reconstruction found that the relevant cross-chain manager accepted a crafted header signed by three of Poly Network's four keeper addresses. Its analysts said the transfer contracts executed as designed once they received that signed state root; the likely failure was stolen or misused keeper keys, or compromised off-chain keeper software, rather than a logic error in the destination contracts.

That conclusion was technical analysis, not a confirmed Poly Network finding on July 2. Dedaub explicitly said there was no definitive proof at that point that the keys had been stolen. What the observed transactions did show, in its assessment, was that three authorized signatures validated a maliciously constructed proof.

For bridge users, that was the institutional lesson. A cross-chain system can spread one trust failure across several otherwise separate networks. The contracts may be public, but security can still depend on a small set of off-chain signers, their key custody and the speed of monitoring and emergency controls. Poly Network's second major security crisis after its 2021 exploit made those dependencies especially material.

Later-confirmed context

In a January 3, 2024 incident review, Poly Network said its investigation found that attackers had obtained validator private keys and used them to alter cross-chain parameters. The team said it shut down cross-chain manager contracts, coordinated with token projects and exchanges, replaced relay-chain validators and restored only selected unaffected services.

That later confirmation clarifies the mechanism but was not available to readers on July 2, 2023. The event-day record remains narrower: Poly Network acknowledged an attack, suspended service, identified 57 affected assets across 10 blockchains, and began containment while independent analysts worked to distinguish nominal token creation from realizable proceeds.

Primary sourcePoly Network service-suspension announcement

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.