Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

Dec 05, 2023

Foblgate adds Ripple market for increased investor opportunities

Foblgate adds Ripple market for increased investor opportunitiesSouth Korean cryptocurrency exchange Foblgate has added a Ripple (XRP) market, where cryptocurrencies can be traded for XRP, according to an article published by South Korean news outlet Blockchain Today. This is the third crypto-to-crypto market on Foblgate along with Bitcoin and Ethereum, providing users with expanded investment opportunities and convenient trading options.Photo by Kanchanara on UnsplashThe Ripple market opened at 10 a.m. today (local time) with a transaction fee of 0.01% and a minimum order amount of 6.5 XRP. Currently, it supports trading for EOS and BNB. Foblgate plans to add more trading pairs in the future.Ripple’s rise in South KoreaThe exchange revealed that it decided to add a Ripple market due to the cryptocurrency’s fast transaction speed and low trading fees, along with its popularity in the South Korean market. The company also emphasized the widespread expansion of Ripple’s ecosystem based on its blockchain network, XRP Ledger, and active participation from the country’s Ripple community.Foblgate’s vision“We have always been sensitive to the demands of investors and market changes,” said Ahn Hyun-jun, the CEO of Foblgate. “The launch of our XRP market aims not only to provide new investment options but also to play a role in promoting the growth and innovation of the crypto industry.”

news
Web3 & Enterprise·

Apr 11, 2023

NH Bank Establishes Consortium to Build Security Token Ecosystem

NH Bank announced today that Korean banks and fractional investing companies have teamed up to establish a consortium with the aim of building an ecosystem for security tokens. Consortium between banks and fractional investorsThe consortium comprises NH Bank, Suhyup Bank, and Jeonbuk Bank as well as six fractional investing companies, including Seoul Auction Blue, Tessa, and Galaxia Moneytree.The banking sector will contribute to the security token industry by building infrastructure for distributed ledger technology, conducting research on promoting security tokens, and bolstering investor protection. Korean banks’ crypto initiativesNH Bank has been in partnership with domestic Korean crypto exchanges Bithumb and Korbit to provide them with real-name registered bank accounts, demonstrating continued interest in crypto services. Under current law, crypto exchanges in Korea are obliged to hold real-name bank accounts if they want to provide Korean won trading services.This move led by NH Bank shows that traditional banks, which have been more conservative compared to securities companies, are actively striving to secure a position in the security token market.

news
Web3 & Enterprise·

Jan 23, 2024

Coinone receives over 600 applications for development staff recruitment

South Korean cryptocurrency exchange Coinone disclosed that it has received more than 600 applications in two weeks following the start of its mass recruitment for development staff for 2024, according to local news outlet Law Issue on Tuesday (KST).Photo by Clem Onojeghuo on UnsplashOffering hope in a job market downturn"We believe this large influx of applications is due to our recruitment’s role in revitalizing the job market of both domestic and foreign virtual asset industries, which has been inactive lately," the exchange explained. Coinone opened applications on Jan. 8, recruiting employees for a total of eight fields related to development. As of Monday, more than 600 people have applied. The exchange’s website received over 3,000 visitors on the first day of recruitment. The final number of applicants is expected to increase as the application deadline is January 26th. More applications are expected to flood in until the deadline on Jan. 26. Job category preferencesAccording to the applications by job category, applicants were most interested in front-end positions (57.1%), followed by back-end (24.4%) and data (18.4%) positions. More specifically, positions in front-end development (29.8%), data analytics (21.3%) and Android development (15.8%) had the highest application rates. The popularity of these categories can be attributed to a combination of Coinone's corporate identity rooted in its solid technology and a positive outlook for this year’s cryptocurrency market. Throughout last year, the exchange also implemented more than 13 service updates across its trading, information and security services, demonstrating its commitment to service integrity and improvement.

news
Loading