Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

Dec 19, 2023

Coinone adds new security features

Coinone adds new security featuresSouth Korean cryptocurrency exchange Coinone has recently added two new features — “Change Phone Number” and “Lock Account” — on its website and mobile app to bolster user security and convenience, according to local news site Greenpost Korea on Tuesday (KST). This comes after the platform recently rolled out plans to terminate its existing authentication services — identity verification via the Coinone PASS app was suspended on Dec. 4, and the service on the Kakao Pay platform will also be suspended on Dec. 28.Photo by FLY:D on UnsplashRobust protection measures“As the number of malicious smishing and phishing attempts to access customer accounts is increasing, it is essential to strengthen customer security. We will continue to implement security features that allow customers to use our services conveniently and safely,” said Myung-hoon Cha, CEO of Coinone.Enhanced user controlAccording to the exchange, users can change their phone number after completing the identity verification process in the “Change Information” option on the “My Page” tab. Notably, if a user’s account information is unintentionally disclosed, they can utilize the Account Lock feature to protect their account. These two features have been added to Coinone’s mobile app in its latest version upgrade.After announcing plans to suspend authentication via Kakao Pay, Coinone instead introduced authentication services via the KakaoTalk app on Dec. 14, which is generally more commonly used by Koreans. By registering a KakaoTalk mobile certificate on the “Additional Channel Authentication” tab, users can undergo identity verification without the hassle of logging in separately. This latest authentication channel was added as yet another option along with Naver, which was added earlier in August.

news
Web3 & Enterprise·

Dec 26, 2023

Bitget works towards goal of Bitcoin ecosystem support

Bitget works towards goal of Bitcoin ecosystem supportBitget Wallet, a Web3 trading wallet offered by the Bitget Seychelles-based crypto derivatives platform, has unveiled a plan designed to bolster its support for and development within the Bitcoin ecosystem.Photo by Kanchanara on UnsplashEnhancing user experienceIn an effort to elevate user experience and expand trading options, Bitget Wallet is committing to extensive product research, development initiatives and increased investments. The company plans on offering a wide array of services tailored to the Bitcoin ecosystem.This includes robust support for BTC asset management, cross-chain swaps, on-ramping for externally owned account (EOA)-based wallets, multi-party computation (MPC) wallets, Taproot compatibility and streamlined asset transfers for both BRC-20 tokens and NFTs. In October, Bitget announced that it was taking the route of enhanced security by embarking on integrating MPC.Integrated dApp browserThe platform also provides users with insights into macro and micro market trends through Bitget Swap, enabling interaction with popular projects via its dApp browser.Bitget Wallet’s move has already garnered support from several Bitcoin ecosystem projects, with integrations on official websites such as Unisat, ALEX Lab, LifeRestart and Bitmap Explorer. The integrated dApp browser ensures convenient user access to these projects, fostering increased engagement and accessibility.Looking forward, Bitget Wallet aims to capitalize on the medium to long-term market prospects within the Bitcoin ecosystem. The company is directing its efforts towards enhancing both technological infrastructure and product features, with a specific focus on critical areas such as Lightning Network, Nostr, Taproot Assets, BRC-20 and ARC-20 inscriptions.Facilitating cross-chain transactionsAn important facet of Bitget Wallet’s approach involves supporting multiple address formats, particularly within the Lightning Network. By doing so, the platform aims to improve asset transfer efficiency and introduce asset swaps between the Bitcoin mainnet and the Lightning Network. This move is geared towards facilitating cross-chain transactions between BTC and Ethereum Virtual Machine (EVM) assets on Bitget Swap, providing users with increased opportunities for portfolio diversification.Alvin Kan, the Chief Operating Officer of Bitget Wallet, underscored the significance of Bitcoin as the foundational cornerstone of the crypto industry. He emphasized the platform’s commitment to becoming a key player in the growing Bitcoin ecosystem, providing users with robust and seamless ways to manage and grow their assets.Formerly known as BitKeep, Bitget Wallet stands as Asia’s largest all-in-one Web3 trading wallet, boasting a five-year legacy and over 12 million users worldwide. On a global basis, the non-custodial wallet recently ranked fourth overall in terms of the number of wallet downloads.Bitget acquired the Singaporean startup wallet project in June. Its addition helped the broader Bitget platform to achieve the milestone of 20 million users. The product was rebranded as Bitget Wallet shortly afterwards.The company is keen to support other blockchain networks and ecosystems also. Earlier this month, the company announced an investment into Morph, a layer-2 blockchain that uses zero knowledge roll-up technology in an effort to focus on enhanced consumer experience.Last week, the platform added support for ZKFair, a zero knowledge layer-2 network which is based on the Polygon CDK.

news
Web3 & Enterprise·

Jul 26, 2023

Bitget Achieves 20M Users With Wallet Integration Driving Trading Volume

Bitget Achieves 20M Users With Wallet Integration Driving Trading VolumeSeychelles-based cryptocurrency derivatives exchange, Bitget, has experienced remarkable growth in the first half of 2023 surpassing 20 million users, driven by the successful integration of its recently acquired self-custodial wallet service, now renamed Bitget Wallet.Photo by Mike Hindle on UnsplashTop four exchangeThe wallet integration has propelled Bitget into the ranks of the four largest cryptocurrency exchanges by trading volume.According to a second-quarter report by Beijing-headquartered crypto research firm TokenInsight, the top four exchanges collectively account for 85% of the total market trading volume. Binance dominates the market with a 52% share, followed by OKX (15.13%), Bybit (10.6%), and Bitget (8.1%), securing its position among the industry’s leading players.$60 billion spot trading volumeBitget’s Q2 report, released on July 18, revealed that the platform’s spot trading volume surpassed $60 billion, with futures trading reaching a staggering $606 billion. Notably, research by blockchain analytics firm Nansen showcased Bitget as the only exchange to witness an increase in futures trading volumes in the six months following the collapse of FTX.The exchange attributes part of its impressive Q2 performance to the introduction of copy trading, a feature enabling users to emulate the trading strategies of select traders. This innovation proved highly successful, attracting 29,700 new elite traders and 169,800 followers, generating $33 million in profits by mid-2023.Bitget, aligning with leading exchanges like Binance, has released its proof-of-reserves to assure users that it maintains reserves exceeding 100% of all assets on the platform, including Bitcoin (BTC), Ether, Tether, and USD Coin. At the time of publication, the exchange’s current reserve ratio, calculated by dividing the platform’s assets by users’ assets, stood at an impressive 223%. According to that data, the crypto platform is claiming a debt-free status for the business.Regional expansionAs part of its expansion strategy, Bitget has obtained virtual asset service provider registration in Poland and Lithuania in 2023, solidifying its presence in Europe. Additionally, the exchange has announced plans to establish a hub for its operations in that region.Last week, it announced that it was also targeting the Middle East and North Africa (MENA) as part of its expansion plans. To support that effort, it has opened an office in Dubai in the United Arab Emirates (UAE) and hired 60 employees with plans on hiring up to 60 more over the course of the next two years.Crypto loans have been an area that has seen major failures within the sector over the last couple of years. However, this isn’t holding Bitget back from getting involved. Earlier this month, it announced the launch of its crypto loans product, which is aimed at market participants who are seeking alternative funding solutions, backed by digital assets.With Bitget’s rebranding efforts following the BitKeep acquisition and its exceptional growth in user numbers and trading volumes, the exchange is making a concerted effort to position itself so as to effect a global expansion strategy. As the market evolves further, it will be interesting to see how the crypto trading market settles, given that there are now a number of firms in the space actively vying for that business.

news
Loading