Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

Aug 28, 2023

BC Card Accelerates Launch of NFT Guarantees for Secondhand Luxury Goods Trades

BC Card Accelerates Launch of NFT Guarantees for Secondhand Luxury Goods TradesSouth Korean credit card issuer BC Card announced on Sunday that it has applied for two domestic patents for blockchain technology that will be used to issue digital guarantees for purchases of luxury goods, such as bags, watches, and more. These guarantees will be minted as non-fungible tokens (NFTs) that can later be accessed by buyers or sellers during secondhand trades, which often pose risks and uncertainty regarding product quality or authenticity.Enhancing trust and securityThese NFTs will be based on paper or digital payment receipts — which contain detailed information on purchase receipts, such as product names, payment amounts, purchase dates, and shop information — that a customer receives after purchasing goods at stores that accept BC cards.Photo by Towfiqu barbhuiya on UnsplashBecause the guarantees are stored on a blockchain, they are almost impossible to tamper with. BC Card anticipates that this service will offer advantages like boosted safety, convenience, and security for both buyers and sellers who wish to partake in transactions of secondhand luxury goods.In addition, the data distributed across servers eliminates concerns about data loss. To achieve this, BC Card plans to collaborate with telecommunications provider KT and BC’s subsidiary, VP, which specializes in electronic payment services.“Through this patent application, we expect to significantly enhance the trustworthiness of secondhand luxury goods transactions in Korea,” said Kwon Sun-moo, Director of the New Financial Research division at BC Card. “After the patents are registered, we plan to collaborate with companies under KT Group like KT Alpha as well as other distribution companies in a business-to-business-to-consumer (B2B2C) system.”Access through a digital walletCustomers can take a photo of a receipt with their phones or download it, then upload it to BC Card’s financial platform, Paybook. The photo is then converted into an image that is automatically stored as an NFT on the blockchain network.Once a seller registers a payment receipt for a product that they bought, then the subsequent NFT guarantee can be accessed or sent through their BC Card digital wallet — a feature that the company plans to launch soon — at any time during future transactions. This offers a convenient solution to the possibility of losing receipts, which traditionally requires manually downloading them again from the card company’s website or app.Revolutionizing secondhand tradeThis new technology could play a significant role in the booming resell and secondhand goods trading market, the company said. According to data from the Korea Internet & Security Agency last year, the domestic secondhand market has grown from a scale of KRW 4 trillion in 2008 to KRW 24 trillion in 2021 and is projected to exceed KRW 30 trillion this year.“Through the registration of payment receipts, we can analyze consumption patterns and even suggest improvements in spending habits to our customers,” Director Kwon highlighted.BC Card is also considering offering luxury appraisal and authentication services along with the future launch of the NFT service.

news
Markets·

Jun 05, 2025

Multiple crypto corporate treasury announcements across Asia

A number of corporations across the Asian region have announced plans to introduce cryptocurrencies as a fixture within their corporate treasuries recently.Photo by Kanchanara on UnsplashReitar Logtech HoldingsAccording to a June 2 filing with the U.S. Securities and Exchange Commission (SEC), Hong Kong-based Reitar Logtech Holdings Limited, a logistics solutions provider listed on the Nasdaq (RITR), intends to purchase $1.5 billion worth of Bitcoin. The filing outlines that the company is at an advanced stage of negotiation with a consortium of institutional investors and high-net-worth individuals with expertise in the digital assets field regarding this strategic treasury diversification initiative. The firm foresees greater involvement in the future with digital assets beyond just holding Bitcoin as a reserve asset. It stated: “The BTC Program will also pave the way for the Company to engage in logistics real estate projects which may involve digital assets in the future by establishing a reserve of digital asset through this initiative and setting up the necessary internal organizational and technical infrastructure for managing such digital assets.” The tokenization of real-world assets (RWAs) is building momentum, with real estate being the standout use case for that activity. DigiAsiaLast month, DigiAsia, an Indonesian fintech firm listed on the Nasdaq (FAAS), outlined that it had launched a Bitcoin reserve strategy. The company stated that the initiative aligns it with the growing trend among publicly-listed companies to add digital assets to the corporate balance sheet. DigiAsia is understood to be actively exploring a capital raise of up to $100 million in order to fund its first Bitcoin purchases. Treasure GlobalOn June 4, yet another Nasdaq-listed firm with Asian origins announced the launch of its digital asset treasury initiative. Malaysia-based e-commerce platform operator Treasure Global stated that its digital asset treasury would be funded with $100 million raised through a new institutional funding partner and an existing equity financing agreement. It plans on buying Bitcoin, Ethereum and regulated stablecoins. K Wave MediaNasdaq-listed K Wave Media, a South Korean entertainment company, also announced on June 4 that it had put together a $500 million securities purchase agreement to facilitate the establishment of a Bitcoin-based treasury. XRP making corporate treasury inroadsWhile there has been a raft of Bitcoin-related corporate treasury announcements within the Asian region and globally, Ripple’s XRP is starting to see some corporate treasury-related activity. On June 3, Webus International, a Chinese international chauffeur service provider listed on the Nasdaq (WETO), outlined in a filing with the U.S. SEC that it plans to establish a $300 million XRP-based corporate treasury.  In addition, Webus plans to integrate corporate use of the XRP blockchain to facilitate cross-border payments for its partners and travelers worldwide. The move follows a recent announcement by London-based VivoPower International, yet another Nasdaq-listed (VVPR) company, outlining that it was establishing a $121 million XRP corporate treasury with funding for the initiative provided by a Saudi prince.

news
Policy & Regulation·

Jun 13, 2023

Sygnum Bank Achieves In-Principle MPI Licence Approval in Singapore

Sygnum Bank Achieves In-Principle MPI Licence Approval in SingaporeIn a significant milestone for its expansion efforts in Singapore and Southeast Asia, Sygnum Singapore has announced that it has received in-principle approval for its Major Payment Institution Licence (MPIL) application from the Monetary Authority of Singapore (MAS).Photo by Dids on PexelsOngoing global expansionThe Swiss-Singapore firm, headquartered in Zurich with an operational base in Singapore, disclosed this news via a press release published on Monday, marking a major stride forward for the company in its regulated crypto brokerage services.The world’s first digital asset bank also has offices in Abu Dhabi, the United Arab Emirates (UAE) capital, and Luxembourg. The digital assets innovation is progressing on a truly global basis. It’s also developing according to differing timelines on a regional basis relative to the regulatory approach being taken within individual jurisdictions. On that basis, we are seeing a move from many leading digital assets firms to expand internationally to benefit from jurisdictional regulatory arbitrage and in an effort to grow such businesses quickly, with a global reach.MPIL licensing significanceThe MPIL license will empower Sygnum Singapore to introduce a regulated crypto brokerage service that offers a fiat-digital asset gateway and facilitates trade execution for various cryptocurrencies. The platform aims to differentiate itself by providing competitive spreads, high liquidity, and swift trade settlements, in an effort to offer investors a seamless and efficient trading experience.This approval follows the extension of the Capital Markets Licence (CMSL) granted to Sygnum Singapore in 2022. With the CMSL extension, the company was able to launch an array of services encompassing corporate finance advisory, capital market products, and asset and security token custodial services.Wave of regulatory approvalThe approval of Sygnum Singapore’s MPIL application comes at a time when Singapore is witnessing a wave of regulatory acceptance for digital asset companies. Crypto.com and Circle are among the firms that have recently been granted full licenses, signifying a positive trend in the recognition and regulation of the digital asset industry in Singapore.Gerald Goh, Co-Founder and CEO of Sygnum Singapore, expressed his enthusiasm about the in-principle approval, highlighting its importance in the company’s growth plans: “This in-principle approval of our Major Payment Institution Licence by the MAS is a milestone in our strategic growth plans for Sygnum Singapore and South-East Asia.”He emphasized that Singapore’s regulatory framework provides the necessary clarity and confidence for investors to participate in the digital asset market: “Like Switzerland, Singapore has a progressive, robust regulatory framework that provides investors the clarity and confidence to invest in digital assets — and Future Finance — with complete trust.”The approval of the MPIL application is expected to bolster Sygnum Singapore’s position as a leading regulated digital asset service provider in the region. By obtaining this license, Sygnum strengthens its global position within the digital assets space while complementing Singapore’s efforts to develop as a regional crypto hub.

news
Loading