The US sanctioned Funnull over the polyfill.io supply chain attack
Assessment
The sanctions are real and the company is the same one. On 29 May 2025 OFAC designated Funnull Technology Inc. and its administrator Liu Lizhi under Executive Order 13694 as amended by Executive Order 14144, blocking their US property and including Ethereum and Tron addresses in the designation. The stated basis is different. Treasury's press release describes Funnull as providing computer infrastructure for websites involved in cryptocurrency investment scams, causing over $200 million in US victim-reported losses, with average individual losses above $150,000. The FBI published a parallel advisory covering infrastructure used to manage domains for cryptocurrency investment fraud between October 2023 and April 2025. Neither document mentions polyfill.io. This paper examined the full text of the Treasury press release and of the OFAC SDN designation entry; the word does not appear in either. The connection is drawn by researchers and journalists rather than by the designating authority, and it may well be correct — a company that sells criminal infrastructure at the scale described would have no difficulty absorbing a domain acquisition. But "sanctioned over the polyfill attack" states a causal basis the public record does not contain, and the distinction matters for anyone citing the sanctions as evidence of what the polyfill compromise was for.
Where this claim appeared
SecurityWeek · 2025-05-30
https://www.securityweek.com/polyfill-supply-chain-attack-impacting-100k-sites-linked-to-north-korea/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
Polyfill.io: How a CDN Acquisition Backdoored Hundreds of Thousands of SitesThink this assessment is wrong? Report an error.