Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Dec 14, 2023

KuCoin resolves lawsuit through settlement and New York market exit

KuCoin resolves lawsuit through settlement and New York market exitKuCoin, one of the largest global cryptocurrency exchanges, has arrived at a comprehensive settlement with the authorities in the state of New York in the United States, agreeing to pay $22 million.Photo by Michael Discenza on UnsplashSubstantial fine and refundsThe settlement not only involves a substantial fine but also includes refunds to New York investors and the cessation of trading activities in the state. This resolution comes amidst an assertive effort by New York authorities to shape and regulate the crypto landscape within the state.According to a statement released by New York Attorney General Letitia James on Tuesday, KuCoin will refund a total of $16.7 million to 177,800 New York investors. In addition to the refunds, KuCoin will pay a $5.3 million fine to the state.The settlement addresses allegations that KuCoin failed to register as a securities and commodities broker-dealer while falsely presenting itself as a cryptocurrency exchange.Taking to social media platform X, James wrote:”My office is making crypto platform @kucoincom pay over $22 million for illegally operating in New York. KuCoin is also banned from doing business in our state. Shady cryptocurrency platforms must play by the same set of rules as everyone else or face the consequences.”At the time of taking action against KuCoin in March, James described the lawsuit as “our eighth action to rein in shadowy cryptocurrency platforms that disregard our laws and put New Yorkers at risk.”Lack of registrationKuCoin, based in the Seychelles, allows investors to trade digital assets through its website and app. However, the state of New York argued that KuCoin could not legitimately claim to be an exchange due to its lack of registration with the U.S. Securities and Exchange Commission (SEC) and the proper designation by the Commodity Futures Trading Commission (CFTC), as mandated by state law.Ranked as the fourth-largest exchange by spot and derivatives trading volume, KuCoin’s KCS token, a profit-sharing token on the platform, has experienced a 39% increase since the start of the week. At the time of writing, it has a unit price of $13.80. This surge is a consequence of the clarity and finality brought about by the settlement, alongside rising expectations for a U.S. exchange-traded fund (ETF) directly investing in Bitcoin, sparking a broader rally in lesser-known cryptocurrencies over the past month.Potential rumorsKuCoin CEO Johnny Lyu took to the X platform on Tuesday to outline details of the settlement. Interestingly, Lyu included this notification:”I also want to give you a heads-up about potential rumors surfacing in the next few weeks. Please stick to the official website of KuCoin for accurate information.”While the settlement may have brought a certain degree of clarity to the KuCoin platform, Lyu’s comment suggests that there may be other issues about to emerge in the short term.The lawsuit against KuCoin is part of a broader regulatory trend in New York, with Attorney General James having previously filed a similar complaint against CoinEx. Additionally, a settlement in January involving crypto companies Nexo Inc. and Nexo Capital Inc. resulted in a financial resolution of up to $24 million for New York and nine other states.

news
Web3 & Enterprise·

Jan 27, 2024

OKX to shut down mining-related services

Leading crypto exchange platform OKX has disclosed plans to discontinue its mining pool services, marking a strategic shift for the platform.Photo by engin akyurt on UnsplashService shutdown within one monthThe move, outlined by the firm in a notification to platform users on Friday, involves ceasing new user registrations effective immediately. Existing users will be granted access to the mining pool until Feb. 25. All mining pool-related services on OKX will be completely halted by Feb. 26. Mining Pools data reveals that OKX holds the 36th position among the top 70 bitcoin-focused mining pools, boasting a total hash rate slightly exceeding 496 TH/s. The decision to phase out mining pool services was attributed to "business adjustments," as communicated by OKX, though further details were not provided regarding the specific nature of these adjustments. Previously, OKX's mining pool supported various proof-of-work cryptocurrencies and offered staking services. However, over recent years, many supported assets had been terminated. Presently, the website only displays bitcoin, litecoin and ethereum classic pool services. Once accounted for 5% of all BTC blocks minedOKX's bitcoin mining pool had once accounted for around 5% of the blocks mined on the network. However, a setback occurred on October 16, 2020, when the crypto exchange temporarily suspended withdrawals due to one of its private key holders “cooperating with a public security bureau in investigations.” This led to a significant drop in hashpower connected to the pool, from 9,000 PH/s to 20 PH/s. The pool's current 528 TH/s now represents less than 0.0001% of bitcoin’s total hash rate. Industry trend formingThis strategic move by OKX reflects the evolving landscape of the crypto industry and the challenges faced by mining pools, particularly in the context of regulatory and operational adjustments within the market. The decision may even amount to a formative trend, given that global crypto exchange platform rival KuCoin made a similar move back in August. At the time, KuCoin outlined its plans to temporarily suspend its bitcoin and litecoin mining pools. Although it suggested a temporary halt to such services, there was no indication of when such mining-related services would resume. A company spokesperson stated:“We will see if it is needed to restart based on the market and users’ demand in the future.” Bitcoin halving pressuresOKX’s decision to discontinue mining pool services comes ahead of bitcoin's anticipated fourth halving in April, which is expected to reduce miner rewards from 6.25 to 3.125 BTC. The halving is casting a shadow over the mining sector. Miners' business cost per bitcoin mined is going to increase significantly. Some industry commentators speculate that the break-even point for miners will reach an unsustainable level. NASDAQ-listed Riot Blockchain, in particular, is being singled out as potentially being susceptible due to its cost structure. Miners have had a difficult couple of years, working their way through the bear market component of the last market cycle. That period saw leading miner Core Scientific declare bankruptcy. The company has since restructured and has been relisted on the NASDAQ.  

news
Web3 & Enterprise·

Dec 13, 2023

NEOPIN works with Japan’s Jasmy to develop RWA-based DeFi products

NEOPIN works with Japan’s Jasmy to develop RWA-based DeFi productsSingapore-headquartered centralized decentralized finance (CeDeFi) protocol NEOPIN has formed a strategic partnership with Jasmy, a Japanese developer specializing in blockchain-based Internet of Things (IoT) platforms. This collaboration represents a step in their joint effort to expand into the global blockchain market, with a particular emphasis on data assetization.Founded in 2016, Jasmy has a management team in which most have a background with tech conglomerate Sony. In contrast to the dominance of tech giants like Google, Apple, Meta and Amazon over data, Jasmy concentrates on achieving data democratization. This concept empowers individuals to have control over their own data. The growing Japanese firm is convinced that the integration of IoT and blockchain technology is the key to realizing this vision of data democracy.Notably, Jasmy has its native token called JasmyCoin. As a regulated virtual asset in Japan, it is listed on centralized exchanges like Binance, Coinbase, Kraken and KuCoin.Photo by Shubham Dhage on UnsplashReal-world assets and security tokensThrough this partnership, the two will explore joint business ventures involving real-world assets (RWAs) and security tokens. They plan to utilize their combined business networks to expand their ecosystems beyond Korea, Japan and the Middle East. NEOPIN will introduce DeFi products using its native token, NPT, and JasmyCoin. Additionally, NEOPIN will become a validator on Jasmy’s mainnet to support its growth.Their collaboration is poised to boost NEOPIN’s advancement into the Japanese market. NEOPIN has been actively pursuing expansion into Japan since its announcement in August. With the Japanese government advocating for Web3 initiatives, a rise in the creation of tokens from local projects is anticipated, leading to a growing demand for DeFi and wallet services.NEOPIN’s partnerships in JapanAs Japan’s digital asset landscape evolves, NEOPIN is actively working to increase its market share in the country. This effort includes a variety of strategies such as focusing on gaming, developing their mainnet, engaging in local marketing activities and launching DeFi products. NEOPIN has also previously announced partnerships with other entities in the Web3 space, including SBINFT, Lena Network and Rokubunnoni, as part of its broader strategy to strengthen its presence in the Japanese market.NEOPIN’s CEO, Ethan Kim, highlighted the company’s goal to lead in the global RWA market. In partnership with Jasmy, they aim to develop and showcase DeFi products related to RWAs and security tokens. NEOPIN is also committed to strengthening its position in Japan by providing Japanese language support this year and actively forming alliances with promising Japanese blockchain enterprises.Hiroshi Harada, CFO of Jasmy, acknowledged NEOPIN’s proven expertise in the Korean market and expressed enthusiasm about the collaboration between the two companies in the blockchain sector. Harada said that their joint efforts will focus on building networks, developing use cases and expanding the market.

news
Loading