Incident case

pNetwork 2021 pBTC-on-BSC exploit

A bug in pNetwork's Rust event-log extraction caused malicious peg-out requests to be processed on the pBTC-on-BSC bridge. The attacker stole 277 BTC collateral; other pTokens bridges were stopped and were not successfully drained.

reviewedcurrent

Incident facts

Incident title
pNetwork 2021 pBTC-on-BSC exploit
Bridge
pNetwork
Incident date
2021-09-19
Incident type
Exploit
Major incident
Yes
Affected chains
Bitcoin, BNB Chain
Affected assets
BTC
Attack category
Event Log Parsing Bug
Reported loss
277 BTC
Amount confidence
High
Loss amount basis
Official PNetwork Postmortem
Recovery
None Confirmed
Reimbursement
Announced
Restart
Partial Reopen
Current outcome
Bridge Family Later Deprecated
Postmortem
Full
Resolution
Unresolved
Last reviewed
2026-06-15
Last verified
2026-06-15

Amount and valuation

pNetwork's official postmortem reported that 277 BTC was stolen from collateral backing pBTC-on-BSC.

The canonical amount is retained in BTC rather than converted using a later fiat price.

Why this remains unresolved

Timeline events

  • pBTC-on-BSC exploited and pNetwork bridges paused2021-09-19

    The team stopped all bridges after detecting the pBTC-on-BSC exploit and reported 277 BTC stolen from collateral.

    Exploit Detected And Bridges PausedHigh

    Other pTokens bridges were not successfully drained.

  • Fix deployed and unaffected bridges gradually reactivated2021-09-19

    pNetwork implemented a fix and gradually reactivated unaffected bridges after additional review and security checks.

    Fix Deployed And Gradual ReactivationHigh

    This does not establish restoration of the exploited pBTC-on-BSC bridge itself.

  • pNetwork announced a community compensation process2021-09-21

    The postmortem said DAO proposals would be used to develop compensation for current pBTC-on-BSC holders.

    Compensation Process AnnouncedHigh

    Final completion is not established.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.