Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Nov 10, 2023

Shinhan Bank to issue NFTs at 2023 Blockchain Grand Week in Seoul

Shinhan Bank to issue NFTs at 2023 Blockchain Grand Week in SeoulShinhan Bank, one of South Korea’s leading financial institutions, is set to issue non-fungible tokens (NFTs) and operate a promotional booth in celebration of its participation in the upcoming 2023 Blockchain Grand Week, scheduled for next Wednesday, according to a report by local news outlet Newspim.The Blockchain Grand Week, an annual event since 2018, is hosted by the Ministry of Science and ICT and organized by the Korea Internet and Security Agency (KISA), the National IT Industry Promotion Agency (NIPA) and the Institute of Information and Communications Technology Planning and Evaluation (IITP). Its objectives are to increase public awareness of blockchain technology and to facilitate the broader adoption of its ecosystem.Photo by Pete Linforth on PixabayNFTs to first 2,000 visitorsThe event is set to take place at the Convention and Exhibition Center, better known as COEX, in Seoul over two days. It will feature a conference centered around the theme “Adding Trust to Digital Platforms” and will include several academic seminars. Various blockchain companies will also be showcasing their products and services at their respective booths. For this event, Shinhan Bank is collaborating with Hexlant and Vircle to introduce their NFT project. They also plan to offer NFTs to the first 2,000 visitors to their booth.The NFTs will be distributed through Shinhan Bank’s NFT wallet, SOL Wallet, and will come with practical perks such as tickets for events at the booth and coffee coupons. Furthermore, these NFTs will be transferable to others.A representative from Shinhan Bank expressed hope that visitors will have the opportunity to experience the bank’s NFTs and gather diverse information related to blockchain technology. The official also emphasized the bank’s commitment to continually developing and introducing blockchain services that can be integrated into customers’ daily lives.Shinhan Bank’s endeavors in blockchainShinhan Bank’s efforts in the blockchain sector have been marked by various accomplishments in recent years. In 2021, the bank received the Ecosystem Transformation Award at the Enterprise Blockchain Awards, now known as the Web3 and Blockchain Transformation Awards (W3B Awards). This January, Shinhan integrated the SOL Wallet service into its financial services application. The bank remains dedicated to spearheading client-centric blockchain initiatives, one such effort being the development of NFT technology in collaboration with Hexlant and Vircle for corporate marketing purposes.Prohibition on discussing virtual assetsMeanwhile, there has been some dissatisfaction among industry insiders regarding the event’s restrictions. Those operating booths are prohibited from mentioning virtual assets in their projects. The application form for booth holders explicitly stated that exhibitions related to virtual assets are not allowed. This cautious approach is believed to be a response to recent cryptocurrency scandals, such as the $40 billion Terra-LUNA crash and the controversy surrounding a Korean lawmaker’s crypto holdings.

news
Web3 & Enterprise·

Jan 17, 2024

Klaytn Foundation and Finschia Foundation to jointly launch largest blockchain network in Asia

The Klaytn Foundation and Finschia Foundation have jointly submitted a governance proposal to launch a new mainnet created by merging their respective blockchain ecosystems. The proposals have been submitted for open discussion, with voting scheduled for Jan. 26 to Feb. 2, according to an official announcement on Wednesday (KST).Photo by Shubham's Web3 on UnsplashThe main objective of this initiative is to create Asia’s largest Web3 ecosystem by combining key features of both blockchains. To do so, the two foundations plan to share their technologies, services and business networks and fortify connections between their partners like their mother companies Kakao and LINE, who have contributed to their development and expansion. “We are excited to be taking the first step toward unlocking the enormous synergy of merging the public blockchains started by Kakao and LINE, which are both leading IT companies in Asia,” the two foundations said. “We will give our best to make this merge an opportunity to innovate and lead the Asian blockchain industry in both technology and adoption.” An unprecedented mainnet ecosystemThe merger will bring together Klaytn and Finschia’s networks in different Asian countries, like Klaytn’s leverage in South Korea, Singapore and Vietnam, and Finschia’s service network in Japan, Taiwan, Thailand and Abu Dhabi. Once the combined ecosystem is launched, it will offer over 420 decentralized apps (dApps) and services, 45 governance partners and some 450 Web3 resources, becoming a mammoth Web3 network capable of swaying the trajectory of the Asian market. In addition, the blockchain will be connected with both Kakao and LINE messengers – two well-known messenger apps in Asia – opening up access to a vast continental user base of over 250 million people. The integration is also expected to catalyze the creation of new Web3 infrastructure in Asia, boosting scalability and liquidity. Future business plansThe joint foundation is specifically set to undertake projects in areas like RWA tokenization, GameFi, DeFi verticals, messenger-based Web3 services and digital commerce through partnerships with Japanese, South Korean and Southeast Asian firms. By leveraging its access to Kakaotalk and LINE users, the new public blockchain has the potential to be a springboard for IT and entertainment enterprises in Asia. Improved tokenomicsWhat may especially interest shareholders and users alike is a new native token that will be issued on the merged network, replacing the foundations’ respective tokens KLAY and FNSA. Holders of KLAY and FNSA will be able to swap their tokens for the new one. The proposed tokenomics system for the new token emphasizes sustainable value creation. This includes a lower base inflation rate and a 3-layer burning model created to encourage deflation as activity on the network increases. 24% of newly issued tokens will also be burned immediately as a trustworthy Zero Reserve Tokenomics measure. This will all be supported via an ecosystem fund and infrastructure fund that are constantly replenished via block rewards, rather than relying on reserves.Enhanced governance and interoperabilityKlaytn and Finschia also plan to bring together their experiences in practicing good governance to build a  permissionless node validation system to put the spotlight on users and the community, promoting transparency, trust and openness. To support the seamless migration and interoperability of existing dApps and services on Klaytn and Finschia, the merged chain will support the smart contract platforms EVM and CosmWasm. Ethereum and Cosmos builders will thus be able to gain access to the network. The foundations are set to host an upcoming event called Klaytn Community Town Hall on Friday to introduce the proposal and facilitate open dialogue and feedback.

news
Markets·

Jun 30, 2023

Survey Reveals 45.9% of Korean Crypto Investors Reporting Losses

Survey Reveals 45.9% of Korean Crypto Investors Reporting LossesAccording to a recent survey, more than half of South Korean adults have experience of owning cryptocurrency. Most of them bought crypto for investment purposes, with 33% of respondents making gains and 45.9% losing money.Photo by RDNE Stock project on Pexels2,500 respondentsThe Korea Financial Consumers Protection Foundation, a public research and education institute, conducted an online survey to assess the prevalence and trends of cryptocurrency ownership among South Koreans. The study, conducted between March 3 and March 24, 2023, encompassed 2,500 participants between the ages of 20 and 69 residing in Seoul, its suburbs, and the six major metropolitan areas. The results shed light on the crypto landscape, including ownership patterns, investment purposes, asset holdings, funding sources, and the future intentions of respondents.Crypto ownership trendsAccording to the survey, 30% of the participants currently own cryptocurrency, while 23% revealed they had previously owned crypto assets but no longer possess them, indicating that more than half of the respondents have had exposure to cryptocurrencies at some point in their lives.Among current crypto holders, 74.5% stated that they had acquired their first digital assets between 2020 and 2022, which suggests a surge in crypto purchases during the COVID pandemic period.Purpose of holding cryptoRegarding the purpose of holding crypto, 80.9% of respondents who either currently own or have previous experience owning cryptocurrency (representing approximately 43% of all participants) cited investment as their primary motivation. Furthermore, 17.4% viewed crypto as a trading instrument, while 17.8% held it for specific service utilization. (Individuals were allowed to choose multiple options.) From this result, the authors estimated that around 24.2% of all respondents currently hold crypto for investment purposes.The survey revealed the distribution of virtual asset holdings among respondents, with the values quoted in Korean Won (KRW). Among the participants, 21.5% owned less than 1 million KRW ($760), while 45.8% held more than 1 million KRW ($760) but less than 10 million KRW ($7,600). Additionally, 28.8% possessed between 10 million KRW ($7,600) and 100 million KRW ($76,000), and 3.9% held more than 100 million KRW ($76,000) in crypto assets.Funding sourcesWhen asked about the sources of funds used to purchase virtual assets, 82.5% of individuals with previous crypto ownership experiences mentioned utilizing spare funds from deposits or other sources. Meanwhile, 17.7% disclosed that they had liquidated other assets, such as stocks or real estate, to invest in cryptocurrencies. (Individuals were allowed to choose multiple options.) In addition, 7.8% of respondents acknowledged borrowing from acquaintances, with a higher rate of 11.8% among those in their 20s. The proportion of respondents who borrowed from loans was 6.2%.Among those who borrowed funds to invest in crypto, 47.6% are currently facing difficulties in repaying their loans, while 28.6% experienced repayment challenges in the past. This data suggests that a significant portion of individuals who borrowed to purchase cryptocurrencies encounter difficulties in loan repayment.Regarding the financial institutions from which respondents borrowed, 57.1% borrowed from the banking sector, while the remaining 42.9% obtained funds from non-banking entities. Encouragingly, no respondents reported borrowing from loan sharks.Cumulative returnsRegarding the cumulative returns on crypto assets, 33% of respondents who currently hold crypto reported gains, with an average cumulative return of 25%. Conversely, 45.9% reported losses, experiencing an average cumulative loss of 41.5%.When liquidating their crypto assets, 24.7% of traders made a profit, while 47.9% incurred losses. The data reveals that the proportion of individuals who suffered losses in their crypto investments was nearly twice as high as those who reported gains. Furthermore, higher age groups exhibited a higher percentage of losses compared to younger respondents. Among those who profited, the average return was 38.4%, while those who suffered losses reported an average loss of 37.5%.Future intentionsThe survey also inquired about the future intentions of respondents regarding their crypto holdings. Among current crypto holders, 80.8% expressed their intention to continue holding crypto assets. On the other hand, among those who do not currently own any crypto assets, 72.8% stated that they do not plan to purchase cryptocurrencies in the future.

news
Loading