Security News > 2021 > August > I was offered $500k as a thank-you bounty for pilfering $600m from Poly Network, says crypto-thief
The mysterious miscreant who exploited a software vulnerability in Poly Network to drain $600m in crypto-assets, claims the Chinese blockchain company offered them $500,000 as a reward for discovering the weakness.
"We appreciate you sharing your experience and believe your action constitutes white hat behaviour ... Since, we believe your action is white hat behaviour, we plan to offer you a $500,000 bug bounty after you complete the refund fully," the thief wrote in their transaction metadata, seemingly quoting or paraphrasing a message received from Poly Network.
The miscreant claims Poly Networks offered the money as part of a "Completely legal bounty reward," and the biz told him it believed the massive heist "Is white hat behavior." However, it appears the thief won't accept the bounty, and may instead send back the rest of the digital dosh.
In a statement, Poly Network referred to the miscreant as "Mr White Hat," and said it hasn't recovered all the stolen tokens yet.
Poly Network said the crypto-pickpocket had returned about $260m out of the $600m digital assets on Wednesday, and is in the process of transferring another $238m back.
In a series of FAQ posts shared by Tom Robinson, chief scientist at crypto-coin analysis house Elliptic, the thief said they were not interested in keeping the money and had instead broken into Poly Network for fun and to raise awareness of the hole in Poly's security.
News URL
https://go.theregister.com/feed/www.theregister.com/2021/08/14/poly_network_payment/