Gerhard Wagener, a maker of mythX tools, discovered a flaw in Polygon’s plasma bridge that put $850 million in capital at risk
Polygon’s Immunifie bug bounty program awards between $1,000 and $2 million depending on the severity of the vulnerability
Polygon has processed more than 800 million transactions and secures $8 billion in assets
In one of the highest bounty rewards in the world of decentralized finance (DeFi), India’s Polygon awarded $2 million to a white-hat hacker for identifying a vulnerability that would have compromised $850 million in assets.
Gerhard Wagener, a white hat hacker and self-proclaimed “Retired DeFi Flashboy,” found a system vulnerability on Polygon’s plasma bridge, which is used to communicate and transfer tokens between Ethereum and Polygon. The company was able to fix the vulnerability in just 30 minutes.
This reward is part of Polygon’s bug bounty program on Immuneifi.
Polygon Bug Bounty Program
This year Polygon, had an Ethereum scaling platform announced a bug bounty program on Immuneify (DeFi bug bounty platform). The program offers rewards ranging from $1,000 to $2 million.
The program focuses on smart contracts and aims to prevent issues like loss of user funds, theft of unclaimed earnings, and network shutdowns, etc.

Rewards are paid based on Immuneifi’s vulnerability Severity Classification System, with a minimum bounty of $1,000, is awarded to security testers who uncover low-severity threats. The maximum of $2 million — awarded to Wagener — will go to those who uncover “critical” threats: deep cryptographic flaws, or flaws that can be used to empty contract inventories.
The beetle
Bridges are sets of contracts that help in communication between the root chain and a lower chain. In this case, the bridge can be used to move tokens and assets between Etherueum and Polygon. For example, if someone wants to take advantage of the fast transaction speeds and low gas fees of the Polygon network, they can use bridges to move tokens from Ethereum to Polygon.
There are two main bridges used to move assets between Ethereum and Polygon – the Proof of Stake (PoS) bridge and the Plasma bridge. In theory, the plasma bridge provides additional safety measures due to the plasma exit mechanism.
To conduct transactions on the Plasma network, the user deposits funds into the bridge contract at level 1 (Ethereum). These tokens are locked at the level and made available for transactions on the Plasma network.
An aggregator called Child Chain then aggregates all transactions on the Plasma network into blocks and submits checkpoints to Level 1. If a user wants to withdraw the funds, the tokens must be “burned” (permanently withdrawn) on the Plasma network. The user then submits the receipt of this “burn transaction” as proof that the tokens were burned.

After a seven-day “challenge period” from submission, the user can withdraw the funds. Gerhard Wagener found a way to launch an attack that could generate 223 alternate exit payloads with the same burn receipt.
This means that a malicious user with $100,000 in equity could win 223 times that amount – $22.3M – with a potential loss potential of up to $850M for users on the network. Right off the bat, a $2M bounty to keep from losing $850M seems like an exceptionally well-thought-out investment.
But the impact of this bounty program will impact the entire DeFi industry. Because platforms offer such high rewards to those who can expose their flaws, the best white hat hackers and security researchers are drawn to the program, resulting in a safer and more reliable system in the long run.
DeFi hacks accounted for more than 71% of major hacks in 2021 Cryptocurrency crime and anti-money laundering report According to CipherTrace, $361 million has been lost to DeFi hacks this year, compared to $129 million last year.
According to the report, one of the biggest DeFi hacks this year occurred on May 19, when the PancakeBunny protocol was subjected to a “flash loan exploit” that drained $45 million worth of assets. The exploit was used to manipulate the price of many PancakeSwap pools, resulting in the minting of 697,000 BUNNY tokens. The hackers sold the coins for Binance coins, causing the price of BUNNY to drop from $146 to $6.
But the developers at Bunny Finance haven’t exactly learned their lesson. On July 16, the company’s new Polygon blockchain fork, PolyBunny, was also hit by the same exploit that minted $2.1 million in PolyBunny, dropping its price from $10 to $2.
The very next month, Poly Network announced the biggest DeFi heist ever: $611M worth of assets were lost from the platform that enabled interoperability between different chains like Bitcoin, Ethereum, etc. The attacker stole funds in more than 12 cryptocurrencies, including $273M in Ethereum tokens, $253M in tokens on Binance Smart Chain, and $85Mn in USDC on the Polygon network.
However, within a day, the hackers began transferring the funds back to a wallet controlled by them and Poly Network. The crisis has been averted, but a point has been made: there is an increasing need for security research in the wild west world of DeFi.
Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers
Comments are closed.