Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Jul 28, 2023

Hong Kong and Saudi Arabia Collaborate on Tokenization and Payments

Hong Kong and Saudi Arabia Collaborate on Tokenization and PaymentsIn an effort to enhance financial collaboration, Hong Kong and the Kingdom of Saudi Arabia are expanding their ties and focusing on agreements related to tokenization and payments infrastructure.Photo by Ketut Subiyanto on PexelsBilateral meetingOn Wednesday, the Saudi Central Bank (SAMA) and the Hong Kong Monetary Authority (HKMA) held a bilateral meeting to discuss various initiatives aimed at integrating financial services between the two nations. During the meeting, the central banks explored areas such as financial infrastructure development, open market operations, market connectivity, and sustainable development. Additionally, they signed a memorandum of understanding (MoU) to facilitate joint discussions on financial innovation.HKMA chief executive Eddie Yue emphasized the potential for cooperation in fields like economy, trade, sustainable development, finance, and fintech between the two nations. He expressed optimism about the continued development of the relationship and the prospects it holds for the future.SAMA governor Ayman Al-Sayari echoed this sentiment, acknowledging the significance of the MoU in fostering stronger ties and assisting them in the future. “HKMA is an important partner for the Saudi Central Bank. Today’s MoU will support our relationship and contribute to the consolidation of efforts in developing the Fintech industry,” he stated.Tokenization and payment infrastructureNotably, the authorities of Hong Kong and Saudi Arabia also used the opportunity to exchange expertise in tokenization, payment infrastructure, and supervision technologies. This collaboration opens up possibilities for both countries to leverage each other’s strengths in these areas.Hong Kong has been actively participating in various inter-jurisdictional tokenization initiatives. In June, the Bank of China’s investment bank subsidiary, BOCI, issued a $28 million tokenized security in Hong Kong using the Ethereum blockchain. The project utilized Goldman Sachs’ tokenization protocol GS DAP and featured cash tokens representing claims on the Hong Kong dollar.Digital assets firm Ripple Labs has also participated in a HKMA pilot program that implicates real estate tokenization.No crypto discussionHowever, the joint announcement did not explicitly mention any joint efforts related to cryptocurrencies like Bitcoin. It is worth noting that Hong Kong recently allowed retail investors to trade crypto, but Saudi Arabia has not shown any specific plans to promote cryptocurrencies in recent years. In 2019, the Saudi Central Bank issued a warning that Bitcoin is not recognized by legal entities within the country.International collaborationRecent months have seen ever greater collaboration between international central banks and regulators relative to digital assets. Last month Japan’s Financial Services Authority (FSA) joined forces with the Monetary Authority of Singapore (MAS) on its Project Guardian initiative to further explore the potential of digital assets.In May, the central banks of Hong Kong and the United Arab Emirates announced a collaboration to work on cryptocurrency regulations and financial technology development. In the same month, MAS partnered with New York’s Federal Reserve Bank on an initiative that examined the use of central bank digital currency (CBDC) for wholesale cross-border payments.As the financial collaboration between Hong Kong and Saudi Arabia strengthens and other such international partnerships continue to unfold, the focus on tokenization and payment infrastructure and digital assets more broadly signifies a step forward in embracing these innovative financial technologies.

news
Policy & Regulation·

Apr 26, 2023

Web3 Offers Potential for Japan to Rediscover its Mojo

Web3 Offers Potential for Japan to Rediscover its MojoEveryone recognizes that Japan has been at the forefront of innovation and the development of technology in the past but can it rediscover that cutting edge through Web3 and blockchain? In a recent interview with Forkast News, Yudai Suzuki, Co-Founder of a Tokyo-based Web3 incubator, suggested that it has that potential.©Pexels/邱 韬Re-establishing a competitive edgeSuzuki, who heads up Fracton Ventures, believes that such a pivot is possible for Japan in making Web3 the means through which it can rediscover the innovative edge it has been lacking in more recent years.Despite an historical strength and depth in technology and innovation, Japan has struggled when it comes to adopting and implementing new technology on a global scale more recently.Legacy techEarlier this year, it emerged that leading Japanese technology companies were collaborating with a view to creating a new open metaverse infrastructure called “Ryugukoku.” That project implicates the creation of a Japan Metaverse Economic Zone. Suzuki cites this project as demonstrative of a key issue relative to the overall development of Web3 in Japan.The project involves Japan’s legacy tech companies such as Fujitsu and Mitsubishi. He goes on to clarify that the majority of Web3 projects in Japan are being led by the existing technology behemoths despite the fact that Japan is seeing the emergence of a Web3-native generation.Suzuki identifies that one of the fundamental aspects of Web3 is that every decentralized autonomous organization (DAO) that’s created is immediately global in nature. Allied with that, most of that 18–25 year old Web3 native generation in Japan want to break through language barriers and communicate on a global basis.That outward looking characteristic is positive but it’s not how venture investment has traditionally worked in Japan. He explains that the conventional approach to investing in start-ups in Japan has been to first look to dominate the Japanese market before going global. The Fracton Ventures founder believes that this is a flawed approach in today’s world and that by the time they’ve gotten to number one in Japan, it’s already too late in trying to achieve that on a global basis.Government responsibilitySuzuki places much of the responsibility in affecting a more appropriate approach on the Japanese Government. “If they focus only on these huge Japanese companies, they will not succeed,” he says. He is also critical of the regulatory approach. Suzuki believes that “the government wants to change the laws and set new regulations at an early date,” and with that, such over-regulation has resulted in crypto entrepreneurs leaving the field. Regulation needs to be set on a more flexible basis so that it can be easily updated and upgraded as the technology develops.Global MindsetHe highlights the importance of having a global mindset and being open to different ideas and perspectives in order to succeed in the Web3 space. The entrepreneur points to that Web3-native demographic in Japan, explaining that their mindset has changed to a more global one as a consequence of dabbling in Web3. The same he believes is necessary on the part of the government if Japan is to become a leader in the tech industry once again.

news
Web3 & Enterprise·

Jul 24, 2023

AIITONE Partners with UAE’s Royal Office to Boost Fintech Industry in Asia

AIITONE Partners with UAE’s Royal Office to Boost Fintech Industry in AsiaAIITONE, an immersive tech company based in South Korea, has taken a significant step towards expanding its reach to the Middle East, according to Korean news outlet Newsis. The company recently signed a memorandum of understanding (MOU) with the Royal Private Office of H.H Sheikh Ahmed Bin Faisal Al Qassimi in the United Arab Emirates (UAE). The partnership between the two entities aims to bolster the fintech industry in South Korea, China, and Japan.Photo by Editz central Editors on PexelsUAE and East AsiaThe Royal Office, known for its diverse business ventures in the fields of real estate, global trading, consulting, and others, provides valuable guidance and strategies to enterprises in the UAE and the Gulf Cooperation Council. Lately, the Royal Office has been looking to expand its operations into East Asia, making this collaboration with AIITONE a strategic move.Security token and CBDCAs part of their joint efforts, the Royal Office plans to invest in promising Korean startups and facilitate the establishment of UAE banks’ Korean branches. Furthermore, the Royal Office intends to support Korean businesses in entering the Middle East market. Emphasizing their commitment to cutting-edge financial technologies, both parties will also work together on security token projects and central bank digital currencies (CBDCs), areas where Dubai is at the forefront of innovation.To facilitate the smooth implementation of these plans, Royal Office officials will visit AIITONE’s headquarters in Busan, Korea, next month. This visit will foster greater understanding and cooperation between the two organizations.An AIITONE representative expressed enthusiasm about the partnership, recognizing it as an opportunity to witness the Middle East’s growing interest in blockchain-based financial technology. Leveraging its expertise in Web3 technologies, such as extended reality (XR), artificial intelligence (AI), and blockchain, AIITONE strives to contribute to the development of both countries in the realms of digital economy and technology.

news
Loading