Cross-chain interoperability protocol Poly Network released a security incident investigation report on July 2nd, which affected 58 assets on 11 chains during the vulnerability incident.
Analysis found that the attacker implanted a Trojan virus in the program compilation environment to obtain the consensus key of the Poly Network relay chain. Subsequently, they manipulated the number of pending unlocked assets on the target chain by transferring transactions from the original chain to the attacker's relay chain, and executed a forged cross-chain transaction. The attacker then transferred the transaction on the relay chain to the target chain. The target chain contract verified the signature of the relay chain, resulting in the modified asset quantity being released to the attacker's wallet address.