Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Oct 07, 2024

Zetrix launches product to simplify KYC for Chinese nationals

Zetrix, a layer-1 blockchain project for real-world applications, has launched an electronic Know Your Customer (KYC) verification product for Chinese nationals. The Malaysian enterprise, which is a subsidiary of digital services company My E.G. Services Berhad (MYEG), has launched ZCert. The offering is available to Chinese nationals who opt to have their digital identities published to the Xinghuo BF network, a Chinese national blockchain infrastructure network developed under the guidance of China’s Ministry of Industry and Information Technology and managed by the China Academy of Information and Communications Technology.Photo by Diego Jimenez on UnsplashFirst-of-its-kind applicationZetrix acts as an international super-node relative to the Xinghuo blockchain. In a press release published by PR Newswire on Oct. 3, the company outlined that ZCert had been launched as a first-of-its-kind application, enabling Chinese nationals “to be authenticated and verified digitally overseas, paving the way for a seamless, efficient, and secure verification process for verifiers and identity holders. ” The service simplifies the issue of identity verification for verifiers located outside of China, as a consequence of Zetrix’s integration with the Xinghuo BIF network.  Connecting to ‘China Web3’Xinghuo signed a memorandum of understanding (MoU) with Zetrix’s parent company, MYEG, to establish the international super-node back in November 2022. The tie-up was seen as an opportunity to provide access to Chinese government agencies and businesses internationally.  At the time, MYEG Managing Director and Zetrix Co-Founder Wong Thean Soon said that “with the commencement of the Xinghuo International Supernode, the rest of the world can connect and be part of the China Web 3 evolution that will promote the establishment of international communities and facilitate global trade and finance.”  On this occasion, Wong said that the new product “enables a new wave of services powered by smart contracts.” He added that KYC processes can be simplified and automated, while “user data is retained by users at all times and only critical information is shared in an encrypted manner." The company has already digitized Chinese driving licenses for the purpose of overseas verification. Furthermore, it has plans to expand its offering beyond ID verification soon. In April of this year, Zetrix and MYEG signed an MOU with MaiCapital, a Hong Kong-based virtual assets manager, with a view towards collaborating on the launch of a digital asset fund or digital asset-based exchange-traded fund (ETF). Last year Zetrix engaged in a pilot project with the Bank of China with the aim of offering supply chain financing products. On a similar theme, its parent company entered into a partnership with the Philippines Bureau of Customs (BOC) and Cargo Data Exchange Center Inc. (CDEC), also in 2023. The collaboration involved the use of Zetrix’s ZTrade product, a Web3 platform that enables digitized trade document verification. Zetrix launched its ZETRIX token in October 2023 through an initial exchange offering (IEO) facilitated by the Coinstore exchange.

news
Web3 & Enterprise·

Mar 08, 2024

Crypto.com joins hands with AI fashion-tech firm Altava Group

The global crypto trading platform Crypto.com has signed a memorandum of understanding with AI fashion-tech firm Altava Group, Korean media outlet Digital Daily reported. According to the press, the signing ceremony took place on Wednesday at the office of Crypto.com Korea, attended by Andrew Junhoe Ku, CEO of Altava Group and Eric Anziani, COO of Crypto.com. Photo by freestocks on UnsplashAs the initial step of the partnership, they aim to integrate Crypto.com’s NFT marketplace and payment solutions with Altava Group’s digital fashion services. Altava Group provides innovative virtual fashion experiences to major fashion brands worldwide, including LVMH, Balmain and Bulgari. By leveraging Altava Group’s network, Crypto.com plans to lay the groundwork for innovation in the digital fashion industry, with various joint promotional events with Altava Group in store.  Fashion-tech meets crypto payment“We are excited to partner with Altava Group, a leader in the digital fashion sector. We hope to leverage our technology and expertise for the growth and advancement of the global digital fashion market – an area in which we see great potential,” said Anziani. Ku also expressed his excitement about the partnership and the integration of crypto payment solutions, saying “We are extremely pleased to explore Crypto.com Pay through the partnership with Crypto.com, a global virtual asset leader with over 80 million users. We expect the addition of cryptocurrency as a payment option to help lower entry barriers for fashion brands and creators, and further strengthen the foundation for the digital fashion ecosystem.”  

news
Policy & Regulation·

Oct 13, 2023

Short-Term Crypto Investment Prevails Among Hong Kong’s Retail Investors

Short-Term Crypto Investment Prevails Among Hong Kong’s Retail InvestorsHong Kong’s retail investor interest in virtual assets has experienced a significant surge in recent years, albeit a recent survey suggests that most retail investors take a short-term investment view relative to crypto assets.Photo by Robert Bye on UnsplashIFEC studyThis newfound enthusiasm for virtual assets emerges from a recent study published by the Investor and Financial Education Council (IFEC), a subsidiary of the Securities and Futures Commission (SFC), Hong Kong’s securities regulator. The survey found that 6% of retail investors in the city had entered the virtual asset market in 2023, as compared to merely 1% in 2019.Conducted from June to July of this year, the study encompassed 1,000 individuals aged between 18 and 69. The survey uncovered a trend toward crypto investing among retail investors who’ve been enticed by the allure of the emerging asset class. Intriguingly, every single one of the digital asset retail investors in the study held cryptocurrencies in their portfolios. Non-fungible tokens (NFTs) and stablecoins, while still relatively niche, were also present in the portfolios of 6% and 2% of investors, respectively.11% to invest in crypto within 12 monthsAnticipating a further uptick in interest, the IFEC report posits that 11% of those surveyed have intentions to invest in virtual assets or related products within the next 12 months. This indicates that the allure of virtual assets continues to exert its magnetic pull on investors in Hong Kong.Despite the growing interest, a noteworthy finding in the survey is that 75% of retail virtual asset investors admitted to their primary motivation being the pursuit of short-term gains. Simultaneously, 74% of these investors perceived virtual assets as a prevalent investment trend, and 73% cited the fear of missing out on popular investment opportunities as a driving factor. These statistics underscore the need for enhanced investor education within the sphere of virtual assets.Lack of regulatory awarenessAnother interesting aspect of the data which emerged from the survey was the finding that only 47% of all surveyed investors are aware of Hong Kong’s recently introduced virtual asset trading regulations, which came into effect on June 1.An additional facet of this investor behavior study was illuminated by research conducted by the Department of Applied Social Science at Hong Kong Polytechnic University (PolyU). This research, based on data from a separate IFEC report that surveyed 501 people from November to December of last year, revealed that many retail investors in virtual assets exhibited overconfidence in their judgment.These investors were also found to have a proclivity to overemphasize past information, lean heavily on readily available and easily recalled information, and overestimate personal intuition.With that in mind, Eric Chui, Head of PolyU’s Applied Social Science unit, advised virtual asset investors to adopt a more deliberate and rational approach. Chui emphasized the importance of building financial literacy and collecting high-quality market information to make informed investment decisions, while steering clear of irrational investment behavior and biases.

news
Loading