Polygon disclosed on December 29, 2021 that its developers had quietly coordinated an emergency network upgrade after security researchers identified a critical vulnerability in the contract governing native MATIC tokens. The flaw exposed approximately 9.28 billion MATIC held by the contract, and an attacker extracted 801,601 MATIC before the fix reached mainnet.

The disclosure supplied the first detailed public account of an upgrade completed more than three weeks earlier. Polygon said white-hat researchers reported the vulnerability through Immunefi on December 3. Developers prepared a testnet release, validators installed an emergency update and the mainnet change took effect on December 5 at block 22,156,660.

Polygon said it withheld the full explanation while the vulnerability remained exploitable. That decision limited information available to attackers, but it also meant validators and users initially had little public context for a consequential network change.

A missing balance and signature safeguard

Immunefi’s technical review identified the vulnerable component as the MRC20 contract used to support MATIC transfers on Polygon. Its `transferWithSig` function permitted a token holder to authorize a transfer while another party paid the transaction fee.

According to Immunefi, the function did not adequately verify that the recovered sender address was valid or that the sender had sufficient balance. A malformed signature could resolve to the zero address and still pass into internal transfer logic. Because the relevant transfer functions lacked the necessary balance check, an attacker could construct a transaction drawing tokens from the genesis contract without a valid authorization.

Immunefi calculated that 9,276,584,332 MATIC was exposed as of December 5, the date of the fix. That quantity describes the tokens vulnerable under the contract logic; it is not a claim that all of them were stolen or sold. The documented unauthorized extraction was 801,601 MATIC.

The repair removed `transferWithSig` from the contract. Polygon’s public repository preserves the associated code change, which was proposed on December 9 and merged into the repository’s main branch on December 23. Those repository dates describe publication and integration of the source change, not the earlier mainnet activation.

The emergency response contained—but did not prevent—loss

Polygon said validators and full-node operators helped upgrade 80% of the network within 24 hours and that the December 5 change caused no major interruption to network liveness or performance. Contemporaneous reporting nevertheless found validator complaints about the limited notice and reported that some unprepared validators went offline.

That tension was central to the December 29 disclosure. A public warning could have accelerated exploitation before operators installed the fix. A quiet upgrade, however, concentrated information and coordination among core developers and selected infrastructure operators while leaving other participants unable to assess the change independently.

The response also demonstrated the financial role of bug bounties. Immunefi said the researcher known as Leon Spacewalker received $2.2 million in stablecoins. A second researcher, identified only as Whitehat2, received 500,000 MATIC after independently reporting the same vulnerability on December 4. Polygon said its foundation would absorb the loss from the stolen tokens rather than pass it to users.

What the December 29 record established

The surviving primary record establishes the vulnerability, reporting timeline, emergency upgrade, exposed token quantity, theft and bounty awards. It does not independently establish the identity or number of malicious actors, whether the extracted tokens were sold, or the incident’s isolated effect on MATIC’s market price.

Dollar estimates for the exposed and stolen tokens varied across contemporaneous reports because MATIC traded continuously and publications used different observation times. This reconstruction therefore reports token quantities rather than presenting a single dollar valuation as definitive.

As of December 29, the defensible conclusion was that Polygon’s emergency response prevented a much larger contract failure but did not eliminate the loss or the governance questions created by a security-driven, minimally disclosed network upgrade.

Primary sourcePolygon — All You Need to Know About the Recent Network Upgrade, December 29, 2021

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.