Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Dec 28, 2023

China disrupts massive crypto-related laundering operation

While cryptocurrencies may be banned in China, crypto trading activity continues in some corners, nonetheless, sometimes through accessing overseas exchanges. With that, authorities recently uncovered a massive underground banking operation that exploited crypto trading platforms to evade local forex regulations.Photo by Manuel Joseph on Pexels$2.2 billion laundering operationOn Sunday, an account on popular Chinese social media platform WeChat run by China’s State Administration of Foreign Exchange (SAFE) published details of the $2.2 billion laundering operation bust. Xu Xiao, the Inspector at the Qingdao Branch of the State Administration of Foreign Exchange, revealed that the scheme involved underground banks who purchased virtual currencies and then sold the virtual currencies through overseas trading platforms to obtain the foreign currency they needed. This process, he explained, completes the conversion of yuan and foreign currencies, constituting the illegal act of buying and selling foreign exchange. Stringent capital controlsChina enforces stringent rules on money transfers outside the country. Citizens are limited to exchanging up to $50,000 in foreign currency and require a permit for transactions beyond that limit. Any transaction exceeding the limit without a permit is considered money laundering. During a recent investigation, authorities seized cryptocurrencies valued at approximately $28,000 in Tether, Litecoin and other digital currencies. However, the operation is estimated to have facilitated the movement of over $2.2 billion, involving more than a thousand bank accounts across 17 provinces and municipalities. Monetary control loopholesChina, once the largest cryptocurrency market, imposed a comprehensive ban on crypto exchanges in September 2017 and subsequently expanded its restrictions to include crypto mining and trading. Despite these measures, reports have surfaced about underground crypto exchange operations. Earlier this year, an investigative report by the Wall Street Journal found that global exchange Binance continues to do thriving business with Chinese customers. Global crypto exchanges are reportedly still onboarding Chinese clients indirectly. The South China Morning Post (SCMP) recently accused Binance of facilitating Chinese crypto trading accounts by falsely claiming they are from Taiwan. While mainland China adopts a hostile stance towards cryptocurrencies, the special administrative region of Hong Kong remains progressive in the sector. Hong Kong’s regulatory authorities have introduced specific rules for cryptocurrencies and are licensing crypto exchanges operating within the jurisdiction. Arthur Hayes, the co-founder of the BitMEX crypto derivatives platform, recently described Hong Kong as the gateway for mainland China to global capital markets. Hayes asserted that wealthy Chinese individuals all bank in Hong Kong and with that, they all have access to crypto exchanges and brokers. In Cambodia, it is understood that illicit Chinese-linked activities oftentimes implicate the use of U.S. dollar stablecoin Tether (USDT) to move funds in and out of China even though Tether is banned in Cambodia. The latest crackdown in China underscores the ongoing challenges faced by authorities in controlling crypto-related activities, highlighting the dynamic nature of such activity within and adjacent to mainland China. As regulatory scrutiny intensifies, the contrast between mainland China’s approach and Hong Kong’s more open stance toward cryptocurrencies becomes increasingly evident. 

news
Web3 & Enterprise·

Jun 20, 2025

Lion Group secures $600M facility to fund HYPE token treasury

Lion Group Holding Ltd (LGHL), a Nasdaq-listed financial services firm that provides an all-in-one platform for traders, has announced that it has secured $600 million to fund a Hyperliquid (HYPE) treasury. In a press release published by PR Newswire on behalf of the firm on June 18, the company outlined that a $600 million funding facility has been put in place by ATW Partners, a New York-headquartered investment firm that manages a number of private equity funds. Global investment bank Chardan Capital acted as the placement agent in facilitating the funding, with the first closing of $10.6 million, as per the subscription agreement.Photo by Towfiqu barbhuiya on UnsplashCorporate treasury strategyLion Group will use that money to launch a new corporate treasury strategy built around Hyperliquid’s HYPE token. Hyperliquid is a decentralized exchange (DEX) which was created by Hyperliquid Labs, a startup founded by Jeff Yan.  The HYPE token is the native token of the Hyperliquid platform. It’s used to secure the network through staking and for project governance. The token is also used to provide transaction incentives, while the Hyperliquid platform buys back HYPE tokens using trading fee revenues. Lion Group’s platform offers its users access to contract-for-difference (CFD) trading, total return swap (TRS) trading, over-the-counter (OTC) stock options trading, while also acting as a futures and securities brokerage. Up until 2022, the firm was based in Hong Kong, opting to relocate to Singapore at that point. Primarily, the company serves corporate clients, individual professional investors and retail investors located in China and throughout the Southeast Asian region. Future of trading is on-chainIn explaining its rationale for pursuing a HYPE treasury strategy, the company’s CEO, Wilson Wang, stated: “Hyperliquid represents a natural extension of LGHL's existing derivatives business into decentralized markets, and reflects our conviction that decentralized on-chain execution is the future of trading." Going forward, the company will pursue a strategic accumulation of HYPE, with the token serving as the firm’s primary reserve asset. In addition to HYPE, Lion Group outlined that it may also allocate funds to purchase Solana (SOL) and Sui (SUI), with these tokens to be staked and custodied with institutional-grade digital asset custodian, BitGo. Lion Group asserted that both of these assets would form “key pillars” of a treasury strategy “focused on execution-first protocols.” Wang added that the company views “protocols like HYPE, with decentralized sequencing, as foundational to building scalable DeFi systems.” The company is not the first mover in terms of launching a HYPE-based corporate treasury. On June 17, Eyenovia, Inc. (EYEN), a Nasdaq-listed ophthalmic technology firm, announced that it had entered into a securities purchase agreement with a view towards financing a $50 million HYPE treasury. Additionally, the firm plans to change its name to Hyperion DeFi and its stock ticker to HYPD later this week to reflect its new HYPE-based reserve strategy. Shares in Eyenovia closed at $4.83 on June 18, down 30.7% over the course of 24 hours. Lion Group shares closed at $3.33, up 19.78%.

news
Web3 & Enterprise·

Aug 11, 2023

NS Studio and Factor Labs to Enhance Military Security with Blockchain Technology

NS Studio and Factor Labs to Enhance Military Security with Blockchain TechnologyKorean game developer NS Studio announced on Thursday its collaborative research effort with blockchain-based security solutions company Factor Labs to boost the security system of its specialized virtual reality simulator used in military training centers and multinational security firms.Photo by Filip Andrejevic on UnsplashProtecting special combat forcesThe two companies signed a memorandum of understanding (MOU) to develop a blockchain-based security system to be integrated into military training equipment that aims to safeguard the identity and behavioral data of special combat forces. Factor Labs’ security technology and blockchain expertise will be integrated into NS Studio’s military training programs, facilitating safer training sessions.“Given the fact that special combat forces are important assets whose identities are considered national secrets, we want to amp up the security of the simulation programs that keep a record of their identities and behavioral patterns using blockchain technology,” the two companies said in a joint statement.“We have begun developing the necessary technology for this project and are preparing to implement the security program starting in the latter half of this year.”Blockchain’s role in military securityThis collaboration underscores the increasing role of cutting-edge technologies like blockchain in ensuring the security and privacy of sensitive data not just in the financial context but also in military and security contexts. The combined efforts of NS Studio and Factor Labs are poised to contribute to the advancement of secure training simulations for special operations personnel.

news
Loading