Poly Network offers a $500K “bug bounty” to the hacker who returned $340M+ in assets and placed the rest in a wallet jointly controlled by the hacker and Poly
Poly Network, the cryptocurrency platform which lost $610 million in a hack earlier this week, confirmed on Friday …
Context & Ripple Effects
The offer follows the theft from Poly Network’s cross-chain protocol and the attacker’s return of more than $342M in crypto assets. Rather than treating the recovery solely as a law-enforcement matter, Poly Network is pairing a bounty with joint control of the remaining funds.
The episode’s immediate objective is asset recovery for affected holders; related coverage later records full recovery of the $610M stolen, followed by a process of returning funds to their owners.
First-order effects
- Poly Network gives the attacker a $500,000 incentive to complete the return while retaining a shared-control mechanism over the unrecovered assets.
- Affected asset holders gain a clearer recovery path, but must wait for Poly Network to unwind and return the recovered cryptocurrencies.
Second-order effects
- The bounty turns the attacker’s cooperation into part of Poly Network’s incident-response process, making control of the remaining wallet central to the recovery outcome.
- Other cross-chain and DeFi protocol operators face a sharper incentive to prioritize recovery controls alongside vulnerability remediation after a breach of this scale.
Third-order effects
- If negotiated returns and jointly controlled wallets recur, major crypto exploits may be handled through a hybrid of technical custody controls and adversarial settlement rather than recovery efforts alone.
- The case underscores that cross-chain protocol security failures can shift operational risk from a protocol operator directly onto users awaiting restoration of assets.
The trend: Crypto-protocol incident response is increasingly combining on-chain custody controls with financial incentives to recover assets after exploits.