Polygon Technology Pays $2M Bug Bounty to Protect $850M Crypto Fund

Cryptocurrency
(Image credit: Shutterstock)

Immunefi announced that a researcher named Gerhard Wagner was paid $2 million for a vulnerability affecting the Polygon Technology decentralized finance platform. This is believed to be the highest bug bounty ever paid, Immunefi said, and that's because the flaw put an estimated $850 million worth of cryptocurrency at risk.

The vulnerability was found in one of the bridges between the Polygon and Ethereum blockchains. "A bridge is basically a set of contracts that help in moving assets from the root chain to the child chain," Polygon explains in its docs, and users can tap either the Plasma Bridge or the Proof of Stake Bridge to move their assets.

Latest Videos FromTom's Hardware
Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • peachpuff
    Dude gave up 850mil for 2mil? Idiot... 😂
    Reply
  • GenericUser
    Successfully making off with $850 million worth of Polygon would require about $3.8 million worth of ETH first.

    I'm not exactly sure if he had nearly 4 million in crypto based capital laying around in order to actually act on this exploit.
    Reply
  • derekullo
    GenericUser said:
    I'm not exactly sure if he had nearly 4 million in crypto based capital laying around in order to actually act on this exploit.
    They way I'm reading it is he could start with "a large amount of eth/tokens" this might be 1 Eth or 100 Eth.

    Then he does his magic and withdraws his original amount 223 times.

    The only bottleneck is the 7 day wait period and how confident you are that you wont get caught during that period.

    Day 1
    Deposit 1 Eth

    Day 7
    Withdraw 223 Eth
    Deposit 223 Eth (Absolute baller move to use your stolen eth to steal more eth from the same company!)

    Day 14
    Withdraw 49729 Eth
    Buy Pagani Huayra

    Day 15
    Convince IRS agents that a stranger randomly gifted you $203M worth of Eth
    Reply
  • cryoburner
    This might be the rare example of responsible disclosure being more lucrative than exploiting the bug or selling it to a vulnerability broker would've been.
    How do we know this wasn't a ransom to not release or exploit the vulnerability before they had a fix? >_>
    Reply