Incident Report & Remediation
On January 6, 2025, Polycule (formerly PMX) experienced a security breach originating from a compromised third-party dependency. Our withdrawal server relied on the aiohttps library to handle asynchronous, scalable HTTPS requests—the core purpose the library was designed for. This library was used to construct headers for all outbound POST requests from the server.
At the time, private keys were stored using AWS KMS (Key Management Service). The compromised aiohttps library allowed an attacker to intercept withdrawal requests by exploiting the request headers, redirecting funds to wallets under the attacker's control.
The incident was detected within hours. Emergency recovery procedures were executed, and the majority of affected assets were recovered.
Following the incident, we undertook a complete overhaul of our security infrastructure:
The platform is fully operational with a significantly hardened security posture. All audits have been passed, and we continue to maintain the highest standards for protecting user assets.
If you have questions about this incident or your account, reach out to our support team.
Contact SupportLast Updated: January 2025