Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

Jul 13, 2023

Japanese Survey Finds One-Third Familiar with Web3

Japanese Survey Finds One-Third Familiar with Web3bitbank, a Japanese cryptocurrency exchange, has released the findings of a survey conducted between June 2 and 8, targeting 547 Internet users to explore their awareness and understanding of Web3. Approximately one-third of the participants reported being familiar with the term Web3.Photo by Bastian Riccardi on UnsplashLevels of knowledgeThe remaining portion of the survey pertained to individuals acquainted with the term. Within this group, 21.6% claimed to possess adequate knowledge of Web3, while 47.9% possessed a general understanding.Familiar conceptsWhen asked about the word “Web3,” 42.1% associated it with the concept of the “metaverse,” followed by cryptocurrency (26.8%) and non-fungible tokens (26.8%). The concepts of decentralized finance (DeFi) and decentralized autonomous organizations (DAOs) were less familiar, with 15.3% and 12.6% of respondents selecting them, respectively.Web3 experienceConcerning initial steps for utilizing Web3 services, 23.7% identified creating an account at a cryptocurrency exchange as the first requirement, while 21.6% believed purchasing a non-fungible token (NFT) was necessary. Additionally, 28.4% stated they had invested in cryptocurrencies. The most popular Web3 service after cryptocurrencies was the metaverse, favored by 27.4% of respondents. Roughly 30% of participants hoped that the Japanese government’s Web3 initiatives include support for startups, followed by expectations of crypto tax revisions (27.3%) and blockchain and metaverse development (25.8%).Notably, among those possessing sufficient or general knowledge of Web3, over 80% expressed positive sentiments towards the Japanese government’s Web3 initiatives.

news
Markets·

Jan 06, 2024

Maelstrom CIO predicts temporary bitcoin plunge

As the cryptocurrency market anticipates the approval of a spot bitcoin exchange-traded fund (ETF) in the United States and the subsequent boost to bitcoin’s unit price, Arthur Hayes, Chief Investment Officer (CIO) of family office Maelstrom, has issued a warning of potential market turbulence. Hayes, better known as the founder of crypto derivatives platform BitMEX, has moved on to Hong Kong-based Maelstrom, a family office that invests in early stage infrastructure ventures that implicate a move towards the decentralization of everything.Photo by Kanchanara on UnsplashMacroeconomic risk factorsIn a detailed blog post on Friday, Hayes outlines a number of macroeconomic variables that could lead to a bitcoin unit price downturn. Hayes begins by highlighting the depletion of the Federal Reserve’s reverse repo program (RRP), which has served as a significant driver for risky assets over the past year. This program allows qualified banks and investment firms to park cash and earn interest on it. The RRP balance has rapidly declined from a record high of $2.5 trillion at the end of 2022 to $700 billion. Hayes projects it to reach its historical average of $200 billion by March. As this liquidity source dwindles, he anticipates negative impacts on bonds and stocks, as well as cryptocurrencies. Fed BTFP expirationThe second factor contributing to the potential market turmoil is the expiration of the Bank Term Funding Program (BTFP) on March 12. This crucial Fed facility is designed to provide longer-term loans to commercial banks. The mechanism aids banking sector stability. Hayes is concerned that the BTFP might not be extended. Such an eventuality could lead to bankruptcy for banks holding massive unrealized losses on their bond holdings. It could lead to a “liquidity rug pull” event reminiscent of the banking crisis in March of the previous year. The crypto OG predicts that such an eventuality would force a response. “The combination of a lack of liquidity gushing from the RRP and the lack of printed money to cover the bond losses on banks’ balance sheets will decimate the financial markets globally,” he wrote. Hayes asserts that the combination of reduced liquidity from the RRP and the lack of printed money to cover bond losses could have a global impact on financial markets. In response to this scenario, he predicts that the Fed will cut interest rates during its March 20 meeting and reinstate the BTFP funding line. ‘Healthy’ correctionIn terms of bitcoin’s price, Hayes foresees a “healthy” correction of 20% to 30% from early March prices if the outlined scenario unfolds. However, he suggests the decline could be as much as 40% if BTC rallies to $60,000-$70,000 in the coming weeks. Despite this temporary plunge, Hayes remains optimistic about bitcoin’s resilience, emphasizing its status as a neutral reserve hard currency that is not a liability of the banking system and is traded globally. In a recent podcast appearance, Hayes expressed the view that the business model of U.S. dollar stablecoin issuer Tether will be challenged once multinational banks receive the go-ahead to offer fiat-backed stablecoins. Overall, Arthur Hayes has urged investors to be cautious and to prepare for potential market volatility in March, emphasizing the importance of understanding the interconnected factors influencing both traditional finance and the cryptocurrency market. 

news
Policy & Regulation·

Jul 17, 2023

Blockchain Council Exec: Philippines Poised for Crypto Adoption

Blockchain Council Exec: Philippines Poised for Crypto AdoptionDonald Lim, the Founder of the Blockchain Council of the Philippines (BCP), believes that the country has all the necessary elements for mainstream crypto and blockchain adoption.In a recent interview with Cointelegraph, Lim discussed the potential for crypto adoption in the Philippines and explained why he is optimistic about the success of blockchain projects in the country.Photo by Krisia on PexelsFinding its place in blockchainAccording to Lim, the BCP recognized the global shift towards Web3 and organized the Philippine Blockchain Week to explore the ecosystem’s potential. That activity revealed to the organizers that the country has a vibrant community eager to find its place in the world of blockchain. Lim expressed confidence in the Philippines becoming the blockchain capital of Asia, citing the country’s technical expertise, young population with a median age of 25, and its ability to adapt quickly, as demonstrated by the popularity of the play-to-earn game Axie Infinity.Crypto interestAxie Infinity, a play-to-earn blockchain game, gained significant traction in the Philippines in 2021, with 40% of its player base coming from the country. This increased awareness of Web3 concepts and the creation of crypto wallets. Additionally, research carried out recently suggests the Filipinos are among the most interested in crypto in the region.Lim noted that international organizations have been eager to enter the Philippine market due to favorable demographics and the government’s open stance on crypto and blockchain. The executive emphasized that the government is not seeking to stifle innovation in the sector. On the contrary, it welcomes blockchain and Web3 projects, creating an environment conducive to their growth.Ethan Rose, founder of Pouch, a wallet service supporting the Bitcoin Lightning Network in the Philippines, corroborated this sentiment. Pouch has successfully onboarded over 400 businesses in the country to accept Bitcoin payments. While the onboarding of Filipino merchants into the crypto space is a positive step, Lim believes that it will take time before living solely on Bitcoin or crypto becomes a reality.Adoption inevitableHowever, he remains optimistic about the future, stating that it is only a matter of time before crypto adoption snowballs into something more significant.Lim highlighted the need for infrastructure development, expecting it to mature within the next four to five years. As the infrastructure improves, crypto will not only be used for payments but also for activities such as purchasing non-fungible tokens (NFTs) and participating in the metaverse. This comprehensive adoption will pave the way for a crypto-powered future in the Philippines.Philippine regulator, the Securities and Exchange Commission (SEC), recently delayed publication of its crypto regulatory framework. However, it appears that the move stems from an abundance of caution in getting the regulation right. Earlier this year, Robert De Guzman, Head of Legal Compliance at Philippines-based cryptocurrency exchange, Coins.ph, expressed his optimism that the authorities are developing a progressive regulatory framework for crypto in the Southeast Asian country.The Philippines shows promising potential for crypto and blockchain adoption, fueled by its young population, technical expertise, and supportive government. As the infrastructure continues to evolve, crypto adoption is expected to expand beyond payments, encompassing various aspects of the digital economy.

news
Loading