Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Aug 08, 2023

Singapore Pledges $112M to Boost Fintech Solutions Including Web3

Singapore Pledges $112M to Boost Fintech Solutions Including Web3Acknowledging the growing significance of collaboration with industry stakeholders in propelling advancements in emergent technologies such as Web3, Singapore’s central bank, the Monetary Authority of Singapore (MAS), has unveiled plans to allocate up to 150 million Singapore dollars (approximately $112 million) towards supporting a spectrum of financial technology solutions, with a special focus on Web3.Photo by Jason Leung on UnsplashDistributed over three yearsThis financial commitment, outlined in a press release published to the MAS website on Monday, will be distributed over a three-year period as part of the revamped Financial Sector Technology and Innovation Scheme (FSTI 3.0), designed to invigorate and fortify innovation by backing projects that leverage cutting-edge technologies.The renewed innovation scheme encompasses multiple avenues, including the Enhanced Centre of Excellence track, the Environmental, Social and Governance (ESG) fintech track, and the Innovation Acceleration track — the last incorporating the realm of Web3.Emphasizing industry partnershipsMAS underlined the importance of forging partnerships with industry participants to bolster inventive fintech solutions originating from emerging technologies such as Web3.“MAS will conduct open calls for the use of innovative technologies in industry use cases. Grant funding will be provided to support actual trial and commercialization,” the central bank stated.In addition to these efforts, the initiative will maintain its commitment to encouraging adoption across domains like artificial intelligence, data analytics, and regulatory technology (RegTech). Furthermore, there will be an emphasis on fostering adoption within companies that are still digitally maturing and seeking to integrate RegTech solutions.Applicants across the various program tracks will be required to allocate resources toward nurturing talent. This strategy aims to augment Singapore’s fintech talent pool, ultimately contributing to the nation’s expertise in the sector.Ravi Menon, the Managing Director of MAS, underscored the substantial investment that the Financial Sector Development Fund (FSDF) has funneled into the FSTI program since its inception in 2015.Menon highlighted that this initiative’s overarching objective is to spur innovation and facilitate the seamless integration of novel technologies within the financial landscape. Over the years, the program has exemplified its commitment to driving transformation and pioneering the adoption of new technology across the financial sector.Nurturing Web3 innovationPotential Web3 and crypto hubs have come and gone, but Singapore has been vying to take its place as a center for Web3 innovation over a sustained period after it suffered some setbacks in 2022 related to a string of crypto business failures.While Binance had not been permitted to serve customers in the city-state, that meant that a disproportionate number of Singaporeans got caught up in the failure of the FTX crypto exchange. Alongside that regulatory failure, state investment giant Temasek had to write off a substantial investment in the company, while suffering reputational damage for not having detected the FTX fraud.The city-state has also been home to the failure of crypto lender Hodlnaut and crypto hedge fund Three Arrows Capital (3AC). Despite these setbacks, Singaporean authorities are continuing to work towards setting the proper stage to further develop Web3 innovation. In June, MAS proposed a comprehensive framework for the design of open networks relative to tokenized digital assets. This latest initiative will further Singapore’s ambition to grow its Web3 sector.

news
Policy & Regulation·

Oct 30, 2023

Gyeonggi Officials with Cryptocurrencies Clear of Professional Conflicts in Virtual Assets

Gyeonggi Officials with Cryptocurrencies Clear of Professional Conflicts in Virtual AssetsGyeonggi Province, South Korea’s most populated province surrounding the national capital of Seoul, announced on October 26 (local time) that the duties of all crypto-holding officials ranked 4 or higher in the provincial government are not associated with virtual assets. In Korea, public officials are ranked from nine to one, with one being the highest position.In anticipation of the amended Public Service Ethics Act coming into effect on December 14, the Gyeonggi provincial government introduced a revised employee code of conduct in August. This required officials of rank 4 or higher to report their crypto holdings within 10 days starting from August 21.Photo by Nattu Adnan on UnsplashReported crypto ownershipThe result indicated that out of 228 officials, 23 reported owning virtual assets. Among these, 15 officials held cryptocurrencies valued at less than KRW 1 million ($738), while the remaining 8 had holdings exceeding that amount.To determine any potential involvement with cryptocurrencies in their official duties, the Gyeonggi government examined the roles and responsibilities of these officials within their respective departments. Following this review, the matter was forwarded to the Gyeonggi Public Service Ethics Committee for further scrutiny.Ethics committee reviewOn October 20, the committee convened to assess the relationship between the officials’ duties and their crypto holdings. They unanimously concluded that none of the 23 officials had any ties to crypto in their official roles.The newly revised code of conduct elaborates on the conditions under which a public official’s responsibilities are associated with virtual assets. Specifically, an official’s duties are considered linked to virtual assets if they are involved in formulating or implementing crypto-related policies or laws; conducting related investigations, inquiries, or inspections; engaging in the registration and oversight of cryptocurrency exchanges; or if they are involved in supporting or overseeing the development of crypto technologies.In light of these definitions, officials who engage in any of the above roles are strictly prohibited from capitalizing on any crypto-related information they encounter during their professional duties for personal trading or investment. Furthermore, officials who either currently shoulder or have previously carried out such responsibilities are required to disclose any crypto holdings they acquire.In the future, once the revised Ethics Act is implemented, the Gyeonggi government will remain fully committed to preventing conflicts of interest among public officials. To bolster these efforts, Gyeonggi will introduce additional measures, including a thorough verification process for the accuracy of their cryptocurrency holdings reports.In situations where a public official with cryptocurrency holdings is assigned a position related to virtual assets, Gyeonggi will issue individualized instructions. These directives may entail either the liquidation of their cryptocurrency holdings or their removal from the specific role in question.Meanwhile, Gyeonggi will enhance its endeavors to furnish educational resources pertaining to virtual asset reporting. Moreover, the local government will restrict officials from holding virtual assets if they fall under financial disclosure obligations and are deemed to possess information about or exert influence on virtual assets.

news
Web3 & Enterprise·

Oct 06, 2023

Architecture Metaverse Platform STELSI Attracts Strategic Investment from Nexus One

Architecture Metaverse Platform STELSI Attracts Strategic Investment from Nexus OneSTELSI, a blockchain-based metaverse construction project, has announced that it has secured a strategic investment from global crypto asset venture capital firm Nexus One.Bridging architecture and the metaverseSTELSI is a Build-to-Earn (B2E) decentralized metaverse island that provides a realistic and intuitive extended reality (XR) experience where users can design, construct, and manage their own buildings. Built with the 3D creation tool Unreal Engine, it aims to support the seamless application of blockchain technology across various fields of the construction industry, including architectural planning and design, construction, and real estate. The platform also has its own token, STELSI, which users can earn by staking building NFTs.Photo by C Dustin on Unsplash“At STELSI, we are building a metaverse platform that converts the works of architects and artists into digital assets, providing new economic value and creative opportunities that have not been experienced before,” said the platform’s CEO Ryan Shim. “I believe that our efforts to make the traditionally conservative construction industry more flexible appealed to Nexus One as an attractive investment point.”Nexus One professionally invests in blockchain and crypto projects such as Klaytn, PlayDapp, and ProBit. Through its latest investment in STELSI, Nexus One aims to contribute to the development of more diverse content related to architecture, producing economic benefits and creative value within the realms of Web3, construction, and lifestyle.On the other hand, STELSI plans to use this opportunity to expand its services to produce various copyrighted content and foster its ecosystem.Promoting the world of digital artSTELSI had previously hosted the first STELSI Media Art Biennale on its metaverse platform back in June, where the company highlighted the potential of metaverse media art, a budding artistic field. Furthermore, it is consistently striving to promote the value of art through technology, as seen in “One Earth: Art Pia,” a digital art survival show currently streaming on the Korean OTT platform Wavve.The platform is also preparing for a token airdrop event ahead of the launch of its decentralized application (dApp) on October 16.

news
Loading