Curriculum·G106 The Research Report·about 31 min
Attribution: tying an address to an actor
By the end of this lesson you can
- →Distinguish what an address did, which the chain shows, from who controls it, which it usually does not
- →Explain how the Poly Network hacker was partly identified from off-chain leaks despite returning the funds
- →Compute the degrees of attribution from cluster to real-world identity, and the confidence at each
- →Combine on-chain behavior with off-chain leaks to attribute, and state the residual uncertainty
Graduate · enrolled learners
This lesson opens with Poly Network, August 2021.
- What happened
- In August 2021 an attacker exploited a cross-chain flaw in Poly Network and took about 611 million dollars across three chains, the largest DeFi theft to that point. What happened next was unusual: the attacker embedded messages in on-chain transactions, said they had done it to expose the vulnerability, and returned nearly all of the funds over several days, earning the nickname Mr. White Hat. The chain showed exactly what the attacker's addresses did, in complete detail. Who the attacker was is a different question. The security firm SlowMist reported it had found off-chain traces, an exchange account, an email, an IP address used to fund the operation, that pointed toward an identity, but no full, confirmed public identification was ever established. The case is a clean split: the on-chain actions were known at total certainty, and the real-world identity behind them rested on off-chain leaks and remained, publicly, uncertain.
- The decision point
- Attribution is two claims that people constantly merge, and keeping them apart is the second discipline of the report. The chain shows what an address did with near-total certainty, and it almost never shows who controls that address. Bridging from one to the other, from a cluster of on-chain behavior to a named person, requires off-chain evidence, an exchange deposit tied to a verified identity, an IP, a reused handle, a leak, and the strength of an attribution is the strength of that bridge, not of the on-chain trail. Poly Network is the illustration: the on-chain conduct was perfectly known, and the identity rested on off-chain clues that pointed somewhere without publicly confirming it. So an analyst attributes in degrees, this address did X at near-certainty, this cluster is one entity at high confidence, this entity is person Y at whatever confidence the off-chain bridge supports, and states the residual uncertainty rather than letting the certainty of the on-chain half leak onto the identity.
- Recorded loss
- $611,000,000
What you will be able to answer
- →What did the chain show, and not show, in Poly Network?
- →What bridges an address to a real-world identity?
- →What are the degrees of attribution?
- →What is wrong with naming a person from clustering alone?
Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.
It is free. We do not sell the list and there is nothing to buy at the end of it.
Sources and review
- https://www.slowmist.com/en/news-detail.html?id=poly-network
- https://www.chainalysis.com/blog/how-crypto-tracing-works/
- https://rekt.news/polynetwork-rekt/
Confidence high·Volatility medium·Reviewed 2026-09-15·Owner unassigned
Contested
Poly Network lost about 611 million dollars in August 2021 and nearly all was returned. SlowMist reported off-chain traces pointing toward an identity; no full public identification was confirmed, so the identity attribution remained uncertain, which is the lesson's point.
The reliability of any specific off-chain bridge (exchange KYC, IP, handle reuse) varies and can be spoofed or shared; attribution strength is a function of the bridge's quality, stated here as a general principle.
