Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Aug 31, 2024

Global crypto fraud suspect arrested in Istanbul

Accused of one of the world's largest cryptocurrency scams, Andreas Szakacs, a Swedish national who became a Turkish citizen under the name Emre Avcı, was detained in Istanbul. The alleged international fraud scheme, led by Szakacs, began in 2019 under the guise of OmegaPro, a company dealing in forex and cryptocurrency trading. OmegaPro claimed to generate significant profits for its investors through complex financial algorithms and high-risk leveraged trading. The company, registered in opaque jurisdictions like Saint Vincent and the Grenadines and headquartered in Dubai, promised returns as high as 300% within 16 months, attracting investors from across the globe. High-profile endorsements and lavish eventsTo bolster credibility, Szakacs and his partners, including well-known figures in the finance and crypto sectors like Dilawar Singh and Mike Sims, organized extravagant events. These included the OmegaPro Legends Cup, a football tournament featuring former stars like Ronaldinho, Kaka and Iker Casillas, who were branded as OmegaPro ambassadors. The company also sponsored car races and held opulent conferences in luxury hotels, where gifts and prizes were distributed to participants, further enticing new investors. OmegaPro's operations spanned multiple continents, with representatives in countries such as Colombia, Mexico, the UK and Nigeria. Over time, the company claimed to have attracted 1.5 million investors. However, in late 2022, as withdrawals were suddenly halted, suspicions grew. By July 2023, the company had shut down, leaving an estimated three million investors defrauded and $4 billion unaccounted for.Photo by Xiaoyi Huang on UnsplashAs OmegaPro collapsed, investors from around the world began filing complaints. In France alone, over 1,500 victims have initiated a class-action lawsuit. Similar legal actions have been reported in countries including Mexico, Congo and Myanmar. Despite multiple investigations, the whereabouts of Szakacs and his partners remained unknown—until recently. A tip-off leads to arrest in IstanbulThe breakthrough came on June 28, when an anonymous informant tipped off Turkish authorities about Szakacs' presence in a luxury villa in Istanbul's Acarkent neighborhood. Following an investigation, the Istanbul Gendarmerie identified 18 complainants connected to OmegaPro. On July 9, Szakacs was arrested in a raid on the villa, where authorities found 32 cold wallets containing cryptocurrencies, along with extensive documentation related to OmegaPro’s operations. During questioning, Szakacs denied all allegations, claiming that OmegaPro was a legitimate business that went bankrupt in late 2022, resulting in significant losses for him and his partners. He also refused to provide access to the cold wallets and the encrypted data on his devices. Despite his defense, Szakacs was charged with fraud using information systems and detained by the Beykoz Criminal Court of Peace on July 10. Ongoing legal battles and future implicationsAs the investigation continues, authorities are scrutinizing Szakacs' digital transactions, which reportedly involve $160 million in movements over a single month. His legal team argues that investors knowingly took on risks in the forex market, but the sheer scale of the losses—especially the $103 million claimed by a Dutch complainant representing 3,000 victims—has intensified the case. The outcome of this case could set a precedent for how international crypto-related fraud is handled, particularly in an era where digital currencies and high-risk investments are increasingly intertwined. 

news
Web3 & Enterprise·

Oct 03, 2023

SBI Holdings and TradeFinex Partner to Create a Trade Finance JV in Japan

SBI Holdings and TradeFinex Partner to Create a Trade Finance JV in JapanJapanese financial services conglomerate SBI Holdings has joined forces with UAE-based TradeFinex to establish a dynamic joint venture. The objective of the partnership is to propel the widespread adoption of the XDC Network within Japan’s trade finance sector.Details of the agreement between the firms emerged last Friday. The strategic collaboration represents a move toward harnessing blockchain technology to infuse transparency, efficiency, and accessibility into the fabric of trade finance and supply chain management.At its core, the XDC Network stands as an enterprise blockchain platform which is compatible with the Ethereum virtual machine (EVM). In recent times, the XDC Network has cultivated partnerships with several international organizations, including the World Trade Organization (WTO) and the International Chamber of Commerce (ICC). It has pioneered solutions aimed at cost reduction, transaction acceleration, and transparency augmentation within the trade finance sphere.Photo by Timelab on UnsplashBuilding upon related partnershipSBI Holdings, deeply ingrained in Japan’s financial services sector, has taken significant strides to embrace the potential of blockchain technology. Earlier this year, its subsidiary, SBI VC Trade, partnered with the XDC Network, becoming the inaugural Japanese exchange to facilitate the cryptocurrency asset XDC. Building upon this previous collaboration, SBI VC Trade has been proactive in championing the expansion of the XDC Network’s presence in Japan.The freshly minted joint venture between SBI Holdings and TradeFinex has the potential to serve as a catalyst for further XDC Network growth in Japan. A central goal is to localize XDC Network-related information, thereby rendering it more accessible to Japanese businesses and investors.Additionally, the venture is actively scouting for cryptocurrency exchanges who are prepared to use and promote the XDC network, further amplifying its adoption. Exploring collaborations with subnet and layer-2 enterprises forms an integral part of their strategy.Japan’s evolving stance on blockchainThe timing of this collaboration coincides with Japan’s evolving stance on blockchain technology and cryptocurrencies. Emerging reports indicate the Japanese government’s contemplation of allowing startups to raise capital through cryptocurrency tokens, marking a seismic shift away from conventional stock listing processes.In April the Japanese government released a whitepaper on Web3, in its efforts to explore ways to foster innovation in the emerging sector. Furthermore, Japan’s National Tax Agency has made adjustments to its cryptocurrency-related tax code, underscoring a proactive stance toward regulating the cryptocurrency industry. Related to that, the country’s Financial Services Agency (FSA) has been exploring tax exemptions relative to unrealized crypto gains.Japan has become known historically as a center of technological innovation. There have been soundings recently that it can rediscover its abilities in that respect through the development of Web3.The strategic alliance between SBI Holdings and TradeFinex charts a promising trajectory for the XDC Network within Japan’s trade finance sector. Anchored in a project that aspires to offer innovation, transparency, and operational efficiency, this joint venture offers considerable potential to spearhead the adoption of blockchain technology within one of the world’s most prominent financial markets.

news
Policy & Regulation·

Aug 25, 2023

Calls for Regulation of Crypto Investment Management Firms Amidst Growing Concerns

Calls for Regulation of Crypto Investment Management Firms Amidst Growing ConcernsThere have been recent calls in South Korea for crypto investment management companies to be subject to the Financial Investment Services and Capital Markets Act amidst concerns about potential regulatory blind spots negatively impacting crypto investors.Photo by Conny Schneider on UnsplashPushing for regulatory oversightKang Seong-hoo, chairman of the Korea Digital Asset Business Association (KDA) went into detail regarding the issue during a forum held by the association on Thursday to discuss the efficient use of technology and safety management in the era of the digital economy.He emphasized that dealings related to virtual asset management such as deposits, lending, and staking must be regulated by authorities under the Financial Investment Services and Capital Markets Act. This is due to the fact that crypto investment management companies are not within the purview of the Act On Reporting and Using Specified Financial Transaction Information or the Virtual Asset User Protection Act, the latter of which is set to take effect next year.The Act On Reporting and Using Specified Financial Transaction Information defines financial companies as those that provide services for selling, buying, exchanging, transferring, keeping, or managing virtual assets; or act as a broker, intermediary, or agent for these services. However, there is no mention of crypto management companies.Echoes of past crypto platform controversiesThese concerns are driven by the looming possibility of another debacle like the class-action lawsuits against crypto platforms like Haru Invest or Delio arising again as a result of regulatory gray areas. Two months ago, investors had filed a legal complaint after the two lenders unexpectedly suspended customer deposits and withdrawals, claiming that they suffered around KRW 50 billion (approximately $39 million at the time of the incident) in damages as a result.Furthermore, the Financial Intelligence Unit (FIU), a division under the Korean Financial Services Commission (FSC), recently stated in a report that virtual asset deposits, lending, and DeFi services do not fall under the obligations of the Act On Reporting and Using Specified Financial Transaction Information.“Given the context of the ongoing crypto winter since last year, the business model of virtual asset management companies, which is heavily reliant on arbitrage between exchanges, poses a high risk of incidents similar to the Haru Invest and Delio cases,” said Chairman Kang.“In order to ensure virtual asset user protection and market safety, authorities should promptly explore regulatory measures under the Financial Investment Services and Capital Markets Act for virtual asset management such as deposits, lending, staking, and the like.”

news
Loading