Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Policy & Regulation·

Jan 17, 2024

Crypto exchange Flybit passes post-audit for ISMS-P certification

South Korean cryptocurrency exchange Flybit, which is operated by the Korean Fintech Industry Association, has passed the post-audit for its Information Security and Privacy Management System certification (ISMS-P), according to local news website News1 on Wednesday (KST).Photo by FlyD on UnsplashRigorous certification standardsThe ISMS-P is a security management system jointly operated by South Korea’s Ministry of Science and ICT and the Personal Information Protection Commission, representing the highest level of security management in the country. It combines 80 requirements for Information Security Management System (ISMS) certification and 22 requirements for Personal Information Management System (PIMS) certification, totaling 102 requirements that must be met. Once obtained, certification is valid for three years, and annual post-audits are required to maintain its validity. Flybit’s commitment to security"Cryptocurrency exchanges are businesses that manage customers' valuable assets. All Flybit members approach their work by recognizing the fact that the protection of personal information is our most important value,” the exchange said. "We will continually strive to maintain security accidents since the establishment of the exchange." Flybit first obtained the ISMS certification in December 2020 and the ISMS-P certification two years later in December 2022. The most recent ISMS-P follow-up audit was conducted last month. After a thorough examination, the results of the audit were delivered by the Korea Internet and Security Agency (KISA) on Dec. 12, which stated that the exchange could maintain its certification. In October last year, the firm also received the highest rating in the comprehensive anti-money laundering (AML) evaluation conducted annually by the Financial Intelligence Unit (FIU) under the Financial Services Commission.

news
Web3 & Enterprise·

May 04, 2023

Korean Crypto Firms Organize Consortium for Real-World Asset Tokens

Korean Crypto Firms Organize Consortium for Real-World Asset TokensElysia, a Korean decentralized autonomous organization (DAO) project, announced today that it organized a consortium to promote an ecosystem for real-world asset (RWA) tokens.Tangible assetsRWA tokens are virtual assets underpinned by tangible assets such as real estate properties and cars.The consortium comprises Neopin, a blockchain platform of Korean online game publisher Neowiz; Galaxia Metaverse, a blockchain subsidiary of Korean industrial conglomerate Hyosung Group; and BKEX Labs, a British Virgin Islands-based crypto investment firm. The companies will collaboratively research and develop a decentralized finance (DeFi) lending protocol supported by RWA tokens.Photo by Jessica Bryant on PexelsLending protocolsLending protocols based on physical assets offer better security and higher profitability compared to those based on unbacked virtual assets, which often experience high price volatility. As a DAO LLC approved by the state of Wyoming in the US, Elysia will leverage its RWA tokenization system to bolster security within the protocol and provide legal safeguards to investors.In addition, tokenized tangible assets are expected to offer small investors a chance to invest in markets that were previously out of reach due to the requirement of a significant amount of capital.According to Aju Business Daily, an Elysia official said that an RWA-based lending protocol would not only appeal to retail investors but also to institutions and projects. These entities are expected to park their excess funds and introduce RWA liquidity pools into their DeFi, the official added.Better liquidity of physical assetsElysia’s RWA tokens can be liquidated on its DeFi platform Elyfi. Users can create RWA tokens based on their tangible assets and visit Elyfi to sell those tokens or borrow virtual assets against them. Elysia aims to facilitate the liquidity of physical assets and offer a diverse range of financial services based on this model.

news
Web3 & Enterprise·

Nov 03, 2023

Dubai’s VARA grants WadzPay ‘initial approval’ of trading license

Dubai’s VARA grants WadzPay ‘initial approval’ of trading licenseIn the latest demonstration of the emirate’s crypto-friendly credentials, Dubai regulator, the Virtual Assets Regulatory Authority (VARA), has granted an “Initial Approval” license to WadzPay.WadzPay was founded in 2018 in Singapore as a business-to-business (B2B) technology firm that concentrates its efforts on enabling digital asset-based transaction processing and settlement. This licensing approval is a significant step forward for the startup, as it inches closer to obtaining a full-fledged Virtual Asset Service Provider (VASP) license.Photo by Paul MARSAN on UnsplashGearing up for service roll-outWith this approval in hand, WadzPay is gearing up to offer a range of virtual asset services, specifically under the forthcoming VASP License for Transfer and Settlement, as well as Broker-Dealer trading activities.That said, the current VARA license places certain restrictions on WadzPay’s offerings. While WadzPay is known for providing a wide array of services to businesses (B2B) and individual users through its B2B2C platform, the “Initial Approval” license limits its scope to only a subset of its virtual asset products and services.Flurry of approvalsDubai has taken center stage in the realm of crypto-friendly jurisdictions, granting a flurry of operational licenses to numerous crypto firms and exchanges in recent months. The regulatory framework in Dubai is underpinned by robust guidelines for VASPs. To operate fully within this framework, crypto firms must navigate a meticulous three-tier licensing process, starting with provisional approval, followed by a minimal viable product (MVP) license, culminating in a total market product license.One of the recent beneficiaries of VARA’s approvals is Backpack, a virtual currency wallet provider. Last month, Backpack received its VASP license, allowing the introduction of the Backpack Exchange to the market. However, similar to WadzPay’s situation, Backpack’s license comes with certain limitations.It permits the offering of crypto exchange services within Dubai but restricts the rollout of other virtual asset services. The Backpack Exchange sets itself apart with advanced features, including zero-knowledge (ZK) proof-of-reserves, multi-party computation (MPC) for secure custody and lightning-fast order execution capabilities.Nomura portfolio company approvalsKomainu, a collaborative venture involving financial heavyweights like Nomura, CoinShares and Ledger, is another notable success story. After a diligent licensing journey, Komainu secured its full operating license from VARA, approximately 10 months after obtaining its MVP license in November 2022.Laser Digital, a crypto division under the vast umbrella of financial giant Nomura, also earned its operational license from VARA in August. Through its dedicated subsidiary, Laser Digital Middle East FZE, based conveniently in Dubai, Nomura has showcased its VASP license. The permit enables the firm to offer a suite of services, including brokerage, virtual asset management and investment offerings within the emirate.Notably, Laser Digital’s licensure followed closely on the heels of Binance, the global crypto exchange. Binance secured its operational minimum viable product (MVP) license from VARA, paving the way for providing crypto exchange and virtual asset broker-dealer services within the region.This flurry of licensing activities and approvals in Dubai is suggestive of the emirate’s commitment to fostering a progressive and regulated crypto environment.

news
Loading