Poly Network 2021 cross-chain exploit
In August 2021, Poly Network was exploited for more than $600 million across multiple chains. The case became a major reference point because the attacker later returned most or all of the funds, making it a recovery-centered bridge incident rather than a permanent-loss case.
Incident facts
- Incident title
- Poly Network 2021 cross-chain exploit
- Bridge
- Poly Network
- Incident date
- 2021-08-10
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain, Polygon
- Affected assets
- ETH, USDC, USDT, WBTC, BNB, MATIC
- Attack category
- Cross Chain Contract Exploit
- Reported loss
- $610 million
- Amount confidence
- Medium
- Loss amount basis
- Public Reports And Secondary Summaries
- Recovery
- Full Recovery
- Reimbursement
- Not Applicable
- Restart
- Reopened
- Current outcome
- Active After Incident
- Postmortem
- Unknown
- Resolution
- Final outcome known
- Last reviewed
- 2026-07-28
- Last verified
- 2026-07-28
Amount and valuation
Reported as more than $600 million, commonly around $610 million, in public coverage.
Public reports commonly cite more than $600 million; exact valuation depends on source timing and asset prices.
more than $600 millionabout $610 million
Used as the display loss amount in this seed record.
Timeline events
Stolen funds returned in stages2021-08
The attacker returned the stolen assets in stages after communicating publicly with Poly Network and the wider crypto community.
Exact final timing and asset-level reconciliation require later source-specific expansion.
Poly Network exploit disclosed2021-08-10
Poly Network disclosed a cross-chain exploit involving assets valued at more than $600 million across multiple networks.
Poly Network upgraded mainnet and began restoring cross-chain service2021-08-16
Poly Network reported that its upgraded mainnet was live and cross-chain functionality had begun returning for supported assets under a staged restoration process.
Recovery treated as substantially complete2021-09
Later reporting treated the Poly Network case as a near-complete or complete recovery of the stolen funds, distinguishing it from permanent-loss bridge incidents.
Needs later expansion with primary-source reconciliation details.
Poly Network completed its operations-resumption roadmap2021-09
Poly Network later reported that the roadmap for resuming operations and restoring user assets had been completed, after cross-chain services and advanced functions were progressively restored.
Evidence records
- Poly Network Attacker Returning Funds After Pulling Off Biggest DeFi Theft EverChainalysis · Tier 1 · High reliability · secondary · 2021-08-12Claim scope: Incident Case
Used for the $612 million estimate, cross-chain context, and early fund-return tracking.
- Security News This Week: A Hacker Stole $610M of Cryptocurrency—and Returned Most of ItWired · Tier 2 · High reliability · secondary · 2021-08-14Claim scope: Recovery
Used for staged return and multisignature-wallet recovery context.
- Crypto platform Poly Network says hacked funds returnedReuters via Euronews · Tier 2 · High reliability · secondary · 2021-08-23Claim scope: Recovery
Used for the later report that almost all of the approximately $610 million had been returned.
- Crypto's biggest hacks and heists after $1.5 billion theft from BybitReuters · Tier 2 · High reliability · secondary · 2025-02-24Claim scope: Recovery
Retrospective source confirming the approximate $610 million scale and near-total return of stolen funds.
- Poly Network mainnet upgrade went livePoly Network · Tier 1 · High reliability · primary · 2021-08-16Claim scope: Restart
Primary source for the start of staged cross-chain service restoration.
- Poly Network Monthly Report (Sep)Poly Network · Tier 1 · High reliability · primary · 2021-10-09Claim scope: Restart
Primary retrospective statement that the operations-resumption roadmap was completed in September.
- Security News This Week: A Hacker Stole $610M of Cryptocurrency—and Returned Most of ItWired · Tier 2 · High reliability · secondary · 2021-08-14Claim scope: Incident Case
Event-scoped duplicate of bir_src_000018: independently supports the Poly Network exploit disclosure, approximate amount, and cross-chain incident context; the original record remains recovery-scoped to bir_ev_000014.
- Poly Network Attacker Returning Funds After Pulling Off Biggest DeFi Theft EverChainalysis · Tier 1 · High reliability · secondary · 2021-08-12Claim scope: Recovery
Event-scoped duplicate of bir_src_000017: directly supports the staged return of stolen Poly Network assets; the original record remains incident-scoped to bir_ev_000013.
- Poly Network — Asset Recovery CompletePoly Network · Tier 1 · High reliability · primary · 2021-08-26Claim scope: Recovery
First-party notice that all affected user assets worth USD 610 million had been recovered and that the project was moving from asset recovery to service resumption.
- Poly Network — Asset Recovery CompletePoly Network · Tier 1 · High reliability · primary · 2021-08-26Claim scope: Incident Case
Event-scoped duplicate of bir_src_000270: first-party Poly Network evidence supports the attack occurrence and USD 610 million affected-asset scope; existing secondary evidence retains exact August 10 chronology and independent technical framing.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Exact asset-level composition and final operational timeline require later source-specific expansion.
- This seed does not yet include a full technical postmortem timeline.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.