Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Jul 01, 2023

OKX Strengthens Partnership with Manchester City Football Club

OKX Strengthens Partnership with Manchester City Football ClubSeychelles-based crypto exchange OKX has announced the expansion of its sponsorship deal with Manchester City Football Club, the treble-winning English Premier League soccer champions.The announcement was made through a virtual reveal video featuring player avatars, presented at Manchester City’s Etihad Stadium. News of the deal was also posted on the English club’s website on Friday.While the valuation of the deal remains undisclosed, the collaboration signifies a significant milestone for both parties. The new agreement, which spans multiple years, establishes OKX as the official sleeve partner on both the men’s and women’s first-team playing kits.Photo by Giero Saaski on UnsplashExtended partnershipUnder this extended partnership, the OKX logo will be prominently displayed on the sleeves of Manchester City’s playing kits, solidifying its position as a key sponsor. Additionally, OKX will retain its presence on the club’s training kit sleeve.City Football Group, the holding company that owns Manchester City and other soccer teams like New York City FC and Melbourne City FC, oversees the management and operations of the club.OKX initially became Manchester City’s official cryptocurrency exchange partner in March 2022. Subsequently, in July of the same year, the exchange secured a sponsorship deal to feature its logo on the front of the club’s training kit throughout the 2022/2023 season. At the time, the agreement was reported to be valued at over $12 million.OKX CollectiveIn February, OKX launched the “OKX Collective” alongside Manchester City players Jack Grealish, Rúben Dias, Ilkay Gündoğan, and Alex Greenwood. This immersive metaverse fan experience offered exclusive content and rewards, allowing fans to engage with the club in a unique way.OKX’s CMO Haider Rafique expressed satisfaction with the evolving partnership, stating: “Manchester City was our first official global brand partnership, and in just a year and a half, we have come a long way. We always intended to integrate with the sport and help the club lead on leaning into Web3. Fast forward fifteen months, we now have a metaverse, an NFT initiative, and a number of other new projects that we are excited about.”Additional sports sponsorshipsBesides Manchester City, OKX has also established partnerships with other prominent sports brands and athletes, including McLaren Formula 1, the Tribeca Festival, Olympian Scotty James, and F1 driver Daniel Ricciardo.While OKX’s partnership with Manchester City strengthens its global fan base, it’s worth noting that the sale of crypto derivatives, a product offered by OKX, was effectively banned by the UK’s financial regulator in January 2021. Consequently, OKX and other crypto exchanges have refrained from advertising such services in the country.As the Premier League clubs have collectively agreed to restrict gambling sponsorships on team shirts, there are concerns that similar restrictions may be imposed on crypto company sponsorships. However, any such developments are expected to be some years away, as the changes regarding gambling sponsorships are scheduled to take effect in the 2026/2027 soccer season.Marketing spend by crypto firms has sobered up quite a bit since the heady heights of the last bull run. However, OKX remains one entity which has been fairly consistent in continuing its marketing efforts regardless of market conditions.

news
Web3 & Enterprise·

Sep 27, 2023

Daehong and Animoca Brands Partner to Leverage NFTs in Expanding Web3 Projects

Daehong and Animoca Brands Partner to Leverage NFTs in Expanding Web3 ProjectsDaehong Communications, the marketing solutions arm of South Korean industrial conglomerate Lotte Group, has recently inked a partnership with Animoca Brands, a blockchain gaming company headquartered in Hong Kong.Animoca Brands gained attention earlier this year by raising $5.5 million through the sale of its Mocaverse NFTs. Mocaverse is the membership NFT collection for the Animoca Brands ecosystem. The Hong Kong-based publisher is also the owner of the renowned metaverse gaming platform, The Sandbox.Photo by Shubham’s Web3 on UnsplashConnecting two worlds of NFTsThis collaboration between Daehong Communications and Animoca Brands is intended to expand their respective Web3 projects, focusing on domains like games, communities, and tickets. As a move under this collaboration, Daehong’s Bellygom and Bellyland NFTs will see integration with Mocaverse. Daehong oversees the Bellygom NFT project, while the pink bear character of the project is a promotional tool for Lotte Homeshopping, a media commerce arm of Lotte Group.Moreover, holders of Mocaverse NFTs are set to experience a variety of games, missions, and rewarding systems introduced by Bellyland — Daehong’s second collection of the Bellygom NFT project.Bellygom’s expansion effortsIn recent times, Daehong has been actively driving the growth of the Bellygom NFT project by revealing the project’s details on GitBook in both Korean and English. Furthermore, Daehong has forged alliances with several burgeoning Web3 projects, including decentralized wellness ecosystem Yogapetz, Web3 social media platform Phaver, and Web3 social network CyberConnect.This partnership marks a strategic confluence of marketing solutions and blockchain gaming, aiming to spearhead innovations in a variety of Web3 projects, especially those related to gaming and community building. These efforts are poised to contribute to broadening the horizon of decentralized technologies.

news
Web3 & Enterprise·

Aug 10, 2023

Foblgate Strengthens Anti-Cybercrime Measures with Chainalysis Solutions

Foblgate Strengthens Anti-Cybercrime Measures with Chainalysis SolutionsKorean crypto exchange Foblgate last Thursday announced its adoption of virtual asset data analysis solutions from blockchain data analysis firm Chainalysis, which has significantly enhanced its ability to combat illegal money laundering of virtual assets and cybercrime.“As crimes involving virtual assets continue to rise, the introduction of Chainalysis’ solutions empowers us to address a wider range of diverse and advanced virtual asset-related crimes,” said Ahn Hyun-jun, CEO of Foblgate.Photo by GuerrillaBuzz on UnsplashChainalysis’ specialized solutionsChainalysis provides data, software, services, and research to governmental agencies, exchanges, financial institutions, insurance companies, and cybersecurity firms all over the world, aiding in solving high-profile criminal cases and expanding consumer access to cryptocurrency safely.Foblgate will use two of its products, Know Your Transaction (KYT) and Reactor, to strengthen safety and security measures on its exchange platform.KYT is a cryptocurrency compliance product that combines blockchain technology, a simple interface, and a real-time application programming interface (API) to map data, monitor crypto transactions, and provide safe access to decentralized finance.Meanwhile, Reactor is an investigation software that connects cryptocurrency transactions to real-world activity. This allows users to visualize cryptocurrency flows and trace transactions across blockchains.Both solutions automatically detect patterns of potential high-risk activities then issue alerts accordingly and link numerous addresses to actual entities (individuals or organizations associated with virtual asset wallet addresses.)By integrating this technology, Foblgate can restrict deposits and withdrawals made by high-risk entities, including unregistered overseas virtual asset exchanges. It can also ensure transparency in virtual asset trading within its domain.Taking security measures a step furtherFoblegate is also taking other measures to further earn trust as a secure exchange by bolstering its countermeasures to cybercrime. Notably, it has established a partnership with GTOne, a company specializing in governance and compliance solutions including anti-money laundering (AML). Through this collaboration, it will be able to thoroughly comply with the Act on Reporting and Using Specified Financial Transaction Information.This strategic move towards innovative blockchain data analysis solutions not only underscores Foblgate’s commitment to regulatory compliance and user security but also a proactive stance against emerging challenges in the realm of virtual assets and cybercrime.

news
Loading