Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Apr 26, 2024

Phemex introduces Lending Protocol and Pulse Season 3

Stella Chan, the chief operating officer of Phemex, a crypto derivatives exchange with a presence in Turkey and Singapore, recently provided details of the company’s unveiling of its Lending Protocol and SocialFi initiative Pulse Season 3. In an interview with Cointelegraph, Chan outlined that since the founding of the firm in 2019, the company has been evolving and working towards carving out a niche for itself in the industry. The executive confirmed that the exchange business has reached a point where daily trading volume now exceeds $2 billion across more than 300 trading pairs. Pulse Season 3Chan is also the co-founder of Phemex’s Pulse, a social trading platform that rewards users while attempting to foster a community spirit within the crypto sphere. As part of Phemex events held at Token 2024 in Dubai last week, the company announced Pulse Season 3, a SocialFi mechanism to incentivize community engagement. The initiative introduces casting and tipping features. Casting is a means through which community members can post up content. Meanwhile, tipping serves as a method through which other community members can acknowledge and reward high-quality community member contributions. Through this initiative Phemex is hoping to deliver an enhanced experience where trading seamlessly intersects with trending topics and insightful content.Photo by Shubham Dhage on UnsplashPhemex Lending ProtocolAlongside Pulse Season 3, the company has also launched the Phemex Lending Protocol, a feature allowing users to borrow crypto at competitive rates while earning interest. As part of that offering, all loans are safeguarded through the collateralization of the user’s digital assets. With an initial liquidity allocation of $22 million, this protocol has been established with an eye towards empowering traders to amplify their capital without selling their assets, while aligning in a more general sense with the user’s overall trading needs. Phemex is attempting to spearhead the transition towards greater user autonomy without compromising security. The Phemex Lending Protocol is central to that effort, offering users competitive borrowing rates and opportunities for passive income generation.  Standing testament to that, the platform offers interest rates on USDT starting at 3.57%. For those that hold vePT, the wrapped version of the platform's native Phemex token (PT), an additional 30% discount on borrowing rates is being offered. vePT is destined to act as a token which confers voting authority in the not too distant future, relative to Phemex’s governing decentralized autonomous organization (DAO). The platform is further enabling capital efficiency from the service user’s perspective by applying very little restriction so that funds can be withdrawn and redeployed at will, with minimum delay. Coming off the back of these announcements during Token 2024, the company appears to be following through on that momentum. Taking to the X social media platform on April 25, Chan outlined details of a plethora of user experience (UX) upgrades relative to its Pulse offering. Future plansLooking ahead, Phemex envisages the offering of a broader range of products tailored to user needs. Plans for an automated market maker (AMM) protocol aim to provide users with passive earning opportunities by contributing to liquidity. Additionally, Phemex is exploring the development of an on-chain credit scoring mechanism, leveraging its soulbound digital identity token to enhance access to decentralized finance (DeFi).

news
Policy & Regulation·

Feb 13, 2024

Philippines to move forward with CBDC without blockchain

The Philippines' central bank has confirmed it has no plans to issue a retail version of a central bank digital currency (CBDC) but that it has definite plans to introduce a wholesale-level CBDC, albeit without using blockchain as the underlying technology. Avoiding retail-level bank run riskThe bank expressed concerns that a retail CBDC could potentially trigger bank runs, given the velocity at which digital currency can be transacted. However, in an interview with local media outlet, the Inquirer, the central bank governor Eli Remolona clarified that within the next two years, the country has definite plans to roll out a wholesale CBDC. CBDCs come in retail and wholesale forms, with the former accessible to the general public and the latter exclusively for institutional use. While the Philippines central bank initiated an exploratory study previously relative to CBDC use, concerns have been raised by the Bank for International Settlements (BIS) about the readiness of institutions to handle the risks associated with CBDCs.Photo by Krisia on PexelsDismissing blockchainDespite this move, the bank does not intend to utilize blockchain or digital ledger technology, which are fundamental to many virtual assets. Remolona stated: "Other central banks have tried blockchain, but it didn’t go well." Instead, the CBDC will operate on a payment and settlement system owned by the central bank, with a focus on wholesale transactions mediated by banks. This marks a shift in the central bank's approach to underlying technology where a CBDC is concerned. The Bangko Sentral ng Pilipinas (BSP) initially embarked on an exploratory study regarding CBDCs in 2022, known as Project CBDCPh. Upon completion of that study, it followed up with a pilot project called Project Agila, concentrating on a wholesale CBDC. Project Agila leaned on the use of the Hyperledger Fabric blockchain, considering it for use on the first wholesale CBDC.  Hyperledger Fabric is an open-source blockchain framework hosted by the Linux Foundation. Companies like IBM, SAP and Intel have all contributed to the development of the enterprise-grade permissioned blockchain network. However, it appears that the BSP is shying away from using any type of blockchain-based solution in establishing its CBDC. Regional steps towards CBDC useThe central bank of the Philippines is among several in the Asia-Pacific (APAC) region that are working towards the introduction of a CBDC. Earlier this month an official from the Reserve Bank of India (RBI) outlined that the central bank will move forward with CBDC development while working towards addressing privacy concerns that citizens may have with a digital rupee. Towards the end of last month, the Japanese government, in collaboration with the Bank of Japan, appeared to be gearing up for the rollout of a CBDC. In a recent meeting between both parties, several legislative matters were identified as key to ensuring a smooth path to the unobstructed launch of a digital currency. There has also been a lot of activity relative to attempts to utilize CBDCs for cross-border trade over the course of the past year. In the United Arab Emirates (UAE), the country announced the first-ever use of its CBDC or digital dirham in a trade deal with China using mBridge, a multi-CBDC platform that supports peer-to-peer, cross-border payments in real time.

news
Policy & Regulation·

Sep 21, 2023

Mt. Gox Extends Repayment Deadline to 2024

Mt. Gox Extends Repayment Deadline to 2024In a development that has captured the attention of the cryptocurrency community, failed Japanese crypto exchange Mt. Gox has officially announced a one-year extension of its repayment deadline.The decision, authorized by the Tokyo District Court, represents a one-year delay from the previously stipulated date of October 31, 2023.Photo by Andre Benz on UnsplashInfamous collapseAt its height, Mt. Gox was the world’s largest cryptocurrency exchange, facilitating over 70% of all cryptocurrency trades. However, its fall from grace began in 2014 when it fell victim to a colossal hack, resulting in the loss of 850,000 Bitcoins. The collapse left approximately 24,000 creditors in its wake, each of them agonizing over a multi-year period for the return of their digital assets.In a letter dated September 21, Rehabilitation Trustee Nobuaki Kobayashi announced the extension of the repayment deadline. This extension applies to the base repayment, early lump-sum repayment, and intermediate repayment, all of which have been rescheduled to October 31, 2024.The rationale behind this delay is twofold. Firstly, to provide creditors with additional time to furnish essential information required for the repayment process. Secondly, it will allow the trustee to coordinate with associated banks, fund transfer service providers, and cryptocurrency exchanges to facilitate the repayments.Potential payout for diligent creditorsA glimmer of hope exists for creditors who have diligently provided the necessary information. Repayments may commence sequentially as early as the close of this year. That said, it should be noted that the specific timing of repayments for each creditor remains uncertain.Kobayashi emphasized that the schedule is subject to change depending on circumstances, and further adjustments are possible. The Mt. Gox Debtor has encouraged creditors who have as yet not provided required information to facilitate payments to do so.Naturally enough, long suffering creditors are frustrated by this latest update. Taking to X (formerly Twitter), one user named “Mt.Gox’ed” wrote: “People will not get their Mt.Gox money back.” . . . “I’ve been tweeting for a long time that infinite delays are coming.”The move evoked a similar response from distressed debt specialist Thomas Braziel, who wrote: “Another delay from the MtGox trustee’s office — COME ON!”Mt. Gox’s journey towards rehabilitation has been arduous and protracted since its declaration of insolvency in 2014. Legal battles, extensive delays, and the need for meticulous coordination have all contributed to this postponement. Nonetheless, creditors are holding onto the hope that, with this extension, the path to recovering their lost assets will become smoother.Crypto market impactThis latest news has drawn considerable attention within the broader crypto sector as it may have implications for the market as a whole. The repayment delay holds the potential to impact Bitcoin prices, given the sheer volume of tokens that will be released when repayments begin. The Mt. Gox estate holds 142,000 BTC, 143,000 BCH, and 69 billion JPY.As per UBS analysts, while this influx of funds could influence the market, it is unlikely to destabilize Bitcoin. Notably, the recovery of approximately 20% of the stolen tokens after the hack reflects a positive step in the ongoing rehabilitation process.

news
Loading