Incident case

Poly Network 2023 validator-key exploit

In July 2023, Poly Network suffered a second major cross-chain incident in which unauthorized cross-chain messages enabled large notional token minting across multiple chains. Independent technical analysis and affected-ecosystem reporting support a validator-key compromise boundary, while realized economic loss was far below the notional minted value.

reviewedcurrent

Incident facts

Incident title
Poly Network 2023 validator-key exploit
Bridge
Poly Network
Incident date
2023-07-02
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, BNB Chain, Metis, Unknown
Affected assets
Unknown
Attack category
Validator Key Compromise
Reported loss
Notional unauthorized minting was extremely large, but realized loss/profit estimates vary materially by source and liquidity; no single canonical USD loss is asserted.
Amount confidence
Low
Loss amount basis
Notional Minting And Realized Loss Estimates Are Kept Separate
Recovery
Unknown
Reimbursement
Unknown
Restart
Partially Reopened
Current outcome
Limited After Incident
Postmortem
Full
Resolution
Unresolved
Last reviewed
2026-08-23
Last verified
2026-08-23

Amount and valuation

Notional unauthorized minting was extremely large, but realized loss/profit estimates vary materially by source and liquidity; no single canonical USD loss is asserted.

Metis documented affected assets in its ecosystem; security analyses describe very large notional issuance but much smaller realized extraction. BIR does not collapse those concepts.

Why this remains unresolved

Timeline events

  • Poly Network 2023 exploit disclosed2023-07-02

    A second major Poly Network cross-chain exploit affected many assets and chains; analyses distinguish enormous notional token issuance from much smaller realized extraction.

    Exploit DisclosedHigh

    No single USD loss is asserted.

  • Poly Network cross-chain contracts paused2023-07-02

    Poly Network cross-chain activity was halted during containment; independent reconstruction attributes the incident boundary to compromised or misused keeper/validator keys rather than a simple target-chain contract bug.

    Bridge PausedHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.