Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Jan 10, 2024

Thailand to move forward with $14 billion digital wallet program

Thailand's government has recently secured approval for a $14 billion digital handout program as part of its economic recovery strategy. The program hasn’t come about without considerable debate and a backdrop of concerns expressed about the Southeast Asian nation's sluggish economic growth. According to Reuters, the decision was confirmed by Deputy Finance Minister Julapun Amornvivat, who stated that the Office of the Council of State, an advisory panel, found no legal obstacles to utilizing state budget funds for the initiative.Photo by Oleksandr P on PexelsDigital handout programThe digital handout program, a key policy of the ruling Pheu Thai party, involves distributing 10,000 baht (approximately $300) to digital wallets set up for each of the 50 million Thai citizens. This financial injection aims to stimulate spending within local communities, providing a much-needed boost to the economy. While the program has faced concerns about potential inflation risks due to Thailand's slow economic growth, the government has argued that it will ultimately benefit the economy. Julapun emphasized that the government plans to proceed with the scheme in May, funded through borrowing. Council of State and opposition party concernsEarlier reports had indicated that the Council of State had initially advised against the government's plan to enact a loan bill for the digital wallet scheme. Concerns were raised about potential violations of constitutional articles, including Article 140, which requires the government to offset any loans outside the budget bill in the next fiscal budget. In addition to inflation worries, the opposition expressed concerns about a potential breach of Article 53 of the 2018 State Fiscal and Financial Discipline Act, which permits off-budget borrowing only in urgent situations. Despite these concerns, the Office of the Council of State ultimately found no reason to prohibit the cabinet from borrowing to fund the program. Thailand's move towards a $14.3 billion cash handout program, termed the "digital wallet" program, is expected to commence by May. Prime Minister Srettha Thavisin affirmed this timeline after the Council of State's approval. The program, allowing Thais to receive funds via a mobile app, aims to spur consumption and overall economic growth. Election campaign giveawayThe idea of the digital asset giveaway was first floated by the Pheu Thai Party (PTP) in April of last year as part of its election manifesto. Subsequently, the party won the election in August, with Srettha being installed as Prime Minister. That appointment was interpreted as being a positive one by crypto advocates, given that Srettha had worked with crypto and blockchain-related technologies in his previous business dealings. Critics, including some economists and former central bank governors, argue that the handout plan could be fiscally irresponsible and fuel inflation. Prime Minister Srettha, who is also the finance minister, plans to discuss the stimulus plan and related matters with the central bank governor. The Thai Chamber of Commerce anticipates a 3% year-on-year growth in the first quarter of 2024, with an annual growth rate of 3.2%, driven by tourism and exports. The digital wallet scheme, if implemented as planned, could potentially add 1.0-1.5 percentage points to this year's growth, according to the chamber. 

news
Policy & Regulation·

Jan 13, 2024

RBI Governor: No place for ‘crypto mania’ in India despite U.S. ETF approval

At the 16th Mint Annual BFSI Summit and Awards in Mumbai, Reserve Bank of India (RBI) governor Shaktikanta Das reiterated the central bank's cautious stance on cryptocurrencies, regardless of recent global developments. During the event, which was held on Thursday, Das took to the stage. He was asked if the approval of spot bitcoin exchange-traded funds (ETFs) in the United States gives legitimacy to cryptocurrency.Photo by rupixen.com on UnsplashUnwavering responseDas was unwavering in his response, maintaining that the RBI remains steadfast in its approach and opposition to cryptocurrencies. He stated: "The way we look at crypto remains unchanged, irrespective of who does what."  He emphasized that the RBI does not intend to emulate regulatory decisions made by other countries. Despite this global development, Das maintained the RBI's reservations, expressing concerns about the potential risks associated with venturing further into the cryptocurrency space. Favoring a crypto banLast month, officials from the Indian central bank told the Hindustan Times that the RBI believes that the Indian government should impose an outright ban on cryptocurrencies in India. One unnamed official stated:"The government cannot sidestep the RBI’s concerns while deciding on cryptocurrencies, as it is responsible for monetary stability in India and maintains price stability." Das acknowledged the potential of blockchain technology, the foundation of cryptocurrencies, highlighting its versatility for various applications. Both the central bank and the Indian government have encouraged the development of blockchain rather than crypto. Last year, an RBI-led initiative, the National Payments Corporation of India (NPCI), recruited blockchain expertise to further develop that project. However, he made it clear that the RBI's focus remains on strengthening governance and assurance in regulated entities, with an emphasis on early identification, close monitoring and effective management of risks. Citing ‘Tulipmania’Das cautioned against a “crypto mania,” drawing parallels to the historical tulipmania of the 17th century. He underscored the RBI's position that embracing cryptocurrencies could pose significant risks, echoing his previous warnings about the macroeconomic and financial stability risks associated with these digital assets. The governor emphasized the importance of instilling an appropriate risk culture within organizations, with active involvement from the board and senior management. Das stated that the RBI expects top officials and board members to play a more proactive role in risk management. India’s crypto community responded critically to the RBI governor’s comments. Ajeet Khurana, a Web3 growth investor, responded on social media, stating:”Dear RBI governor, I respect you a lot, and I don’t mind that you don’t like Crypto. Diverse points of view are healthy. Yet, using words like 'tulip mania' only gives the impression that you are out of touch with what is happening in Web3. My request, Sir, is that you update yourself.” Vivek Sen, the founder of Bitgrow Lab, wrote:”Dear RBI, First, don't club Bitcoin with ‘Crypto’. Secondly, Tulips did not experience an 80% drop on four occasions, and they recovered each time.”Despite opposition to cryptocurrencies in official circles in India, a report last year produced by Chainalysis found that India is leading the way in Asia in terms of grassroots adoption of cryptocurrencies. 

news
Web3 & Enterprise·

Oct 23, 2023

X-PLANET to Sell NFTs for 35th Anniversary of Choushinsei Flashman’s Korean Release

X-PLANET to Sell NFTs for 35th Anniversary of Choushinsei Flashman’s Korean ReleaseCom2uS Platform, a subsidiary of Korean game developer Com2uS Holdings, announced last Friday that it will launch non-fungible tokens (NFTs) on its NFT marketplace X-PLANET to celebrate the 35th anniversary of the Japanese television show Choushinsei Flashman’s Korean release.Photo by PJ Gal-Szabo on UnsplashFan-favorite showChoushinsei Flashman is a live-action superhero series that gained immense popularity when it was released in South Korea in 1989. The original series produced by Japan’s Toei Animation captivated fans with its dynamic action sequences and the exploration of deeper themes such as family separation and loneliness.Merging the retro and modern worldsX-PLANET is collaborating with Toei Animation and Korean publishing company Daewon Media to carry out the NFT project. The 35th anniversary NFT will officially drop on November 1 at 9:00 AM (UTC) for $150 each. Buyers will receive a 35th-anniversary merchandise set, which includes a Rolling Vulcan figure lamp, a set of Video Home System-themed photo cards, an acrylic phone pop socket, and an acrylic frame. The Rolling Vulcan figure lamp in particular is gaining the most attention, as it is being officially released for the first time in three decades.The marketplace also opened an official mini website dedicated to the event and announced that it would be airdropping NFTs of Mag, the show’s representative robot mascot, on a first-come, first-served basis from Friday until the end of the month.X-PLANET is also planning to hold a Choushinsei Flashman 35th anniversary fan meeting in Korea early next year, which will invite seven Japanese actors from the show plus a secret guest. The sale of NFT tickets to the fan meeting will open in December, the platform said.

news
Loading