Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Markets·

Apr 06, 2023

Asian Market Surge for XRP Amid Broader Market Implications

Asian Market Surge for XRP Amid Broader Market ImplicationsXRP, the cryptocurrency and native token used by real time gross settlement system, Ripple, has seen renewed activity in recent weeks in terms of trading volume. That trading volume appears to be more pronounced in Asian markets such as South Korea.©Pexels/RODNAE ProductionsThe XRP token has traded up 22% over the course of the past seven days, with a current unit price of $0.54. Trading volume has surged on South Korean exchanges such as Bithumb UpBit and Korbit where volume spiked 18%, 37% and 50% respectively over the past 24 hours. This trading activity is irregular as ordinarily the trading volume of Bitcoin and ether would account for the vast bulk of trading on the three leading Korean exchanges.Speculative interestXRP has under-performed in recent years and at the heart of its difficulties has been a multi-year legal battle with the Securities and Exchange Commission (SEC) in the United States. In its complaint, the SEC has claimed that XRP is an unregistered security. Speculation in recent weeks suggests that this highly litigated battle may be drawing to a conclusion. Many commentators have suggested that either a deal will be struck or the court could soon decide to rule on the matter.During the 2017 bull market, the token reached the heady heights of a $3.40 unit price. That’s a target that the cryptocurrency has never been able to reach ever since. During the last bull market, it rose to around $1.76 for a short time in April 2021. There’s little doubt but the regulatory cloud hanging over it has suppressed the price. Much depends on the outcome of this lawsuit, not just for XRP but for crypto as a whole.Another notion driving speculative interest is the idea that the Commodity Futures Trading Commission (CFTC) may classify XRP as a commodity. That line of thought is more recent and follows the CFTC classifying a number of cryptocurrencies as commodities in its lawsuit against global crypto exchange Binance. In follow up comments earlier this week, CFTC Chair Roistin Behnam reiterated the claim.The very fact that the CFTC has made this claim is significant in terms of the case being pursued by the SEC, potentially weakening the SECs case. Lawyers for Ripple have made the court aware of the CFTCs claims.Crypto moving forwardCrypto traders in South Korea have been notorious in the past for pursuing speculative trends within the industry with the Kimchi Premium on Bitcoin back in the day as a stand out example. Whether speculative or not, the outcome for XRP, Ripple and the broader cryptocurrency space relative to the cryptocurrency’s regulatory status will be significant.A positive result will not just be a fillip for XRP, Ripple and Asian and other crypto traders who have speculated on such an outcome. It will also serve to provide a level of regulatory protection for all other crypto projects within the United States. A negative outcome to the lawsuit will not be ideal for XRP, Ripple and US-based crypto projects. However, Ripple CEO Brad Garlinghouse has said in the past that if innovation is driven overseas, Ripple will focus on developing its product overseas.In an interview this week Ripple President Monica Long suggested that over and above the lawsuit, crypto innovation is generally being pushed outside of the United States. Long cites Asia as taking the lead on “thoughtful crypto policy”. On that basis, it’s likely that one way or another crypto moves forward and maybe South Korean speculators will be proven right regardless of the outcome of the XRP..

news
Web3 & Enterprise·

Aug 05, 2023

Bitget Report Finds Gen Z Dominates Crypto Copy Trading

Bitget Report Finds Gen Z Dominates Crypto Copy TradingA recent report by Bitget, the Seychelles-headquartered crypto exchange, sheds light on the growing trend of copy trading among younger investors, particularly Gen Z.Photo by rc.xyz NFT gallery on Unsplash44% under 25The report, released on Thursday, reveals that an impressive 44% of all copy traders on the platform are under the age of 25, indicating a strong inclination among this generation towards this type of investment and trading strategy.Copy trading, or social trading, involves emulating the trading activities of established investors. Bitget’s findings indicate that the younger demographic is more receptive to this approach, with individuals aged 25 to 35 constituting just under one-third of all copy traders. Comparatively, individuals aged 35 to 55 represented 17% of copy traders, while those over 55 constituted a mere 7%.Reliance on influencersInterestingly, this trend aligns with Generation Z’s penchant for seeking advice from social media influencers. Bitget’s report highlights that Gen Z’s tendency to turn to these influencers for investment decisions could be a driving factor behind their affinity for copy trading.A survey by Forbes Advisor in January found that approximately 80% of both Gen Z and millennials rely on financial advice from social media platforms. Notably, platforms like YouTube, Reddit, and TikTok have gained their trust, with half of the respondents claiming to have profited from advice received.The report also reinforces crypto’s status as the preferred investment choice among Gen Z. A joint study by the CFA Institute and the Financial Industry Regulatory Authority (FINRA) Foundation in May revealed that crypto was the most popular investment option for Gen Z in the United States, a striking 44% of Gen Z investors initiated their investment journey with cryptocurrencies, surpassing the 35% of millennials who did the same.Geographical differencesThe trend extends beyond the US, with 43% of British and 35% of Canadian Gen Z investors indicating crypto as their inaugural investment.Geographically, Bitget’s report showcases intriguing patterns among its copy-trading user base. While nearly a third of users hail from Western Europe, almost half originate from East or Southeast Asia. This distribution highlights the global reach of the platform and the appeal of copy trading across diverse regions.Of note, despite constituting only 1% of Bitget’s global copy traders, a remarkable 62% of African users expressed interest in copy trading. This proportion stands as the highest among all regions surveyed, reflecting a growing appetite for innovative investment methods on the African continent.Bitget’s report underscores the evolving landscape of investment practices, with Generation Z at the forefront of embracing new approaches like copy trading. It also builds on prior initiatives and research undertaken by the firm. In May Bitget launched a corporate social responsibility (CSR) project titled “Blockchain4Youth.” That initiative revealed that Bitget understands that the younger generation is where the greatest opportunity for mass market adoption lies for crypto and Web3.As the influence of social media on financial decisions continues to rise, the crypto industry may see further shifts in investment patterns and strategies among different demographic groups.

news
Web3 & Enterprise·

Aug 07, 2023

NEOPIN Strengthens Japanese Market Strategy for Its Global Expansion

NEOPIN Strengthens Japanese Market Strategy for Its Global ExpansionNEOPIN, the global CeDeFi platform of South Korean investment holding company Neowiz Holdings, announced the strengthening of its strategy to enter the Japanese market as part of its global expansion plan.Photo by Aditya Anjagi on UnsplashThree key initiativesTo achieve this goal, NEOPIN has devised three key initiatives. Firstly, it will make investments in Japanese partners and provide support for their entry into other markets such as Korea, the Middle East, and Africa. Secondly, NEOPIN aims to facilitate the entry of its existing partners into Japan. Lastly, the Korean platform plans to collaborate closely with the Finschia Foundation and its members to effectively drive its expansion efforts in Japan.Web3 landscape in JapanSince the Mt. Gox incident in 2014, wherein the major Tokyo-based cryptocurrency exchange went bankrupt due to hacking attacks, Japan has responded by implementing stricter regulations. However, in recent times, the Japanese government has displayed a more positive stance towards Web3 technology, aiming to attain dominance in this sector. Illustrating this commitment, the Web3 project team, operating under the ruling Liberal Democratic Party’s (LDP) Working Group for Digital Society Promotion, released the Web3 White Paper in April. The document underscores Japan’s determination to lead the global market by fostering a business-friendly environment for Web3 innovation.Moreover, Prime Minister Fumio Kishida recently delivered a keynote speech at Japan’s annual Web3 conference, WebX, reaffirming the government’s dedication to establishing a Web3-friendly ecosystem. These initiatives signal Japan’s potential to contribute to the growth of the cryptocurrency and decentralized finance (DeFi) industry.Adaptation to regulationsNEOPIN’s operator Neowiz Partners, formerly known as NEOPLY, became part of the Innovation Programme of the Abu Dhabi Investment Office (ADIO) in the United Arab Emirates (UAE), with an aim to become the world’s first regulated DeFi platform. It is also working with the Abu Dhabi Global Market (ADGM) to develop a DeFi regulatory framework for the Gulf nation. In a similar vein, NEOPIN strives to respond quickly to the changing regulatory landscape in Japan to ensure the Korean CeDeFi protocol firmly establishes its presence in the Japanese market.In addition to providing direct and indirect service offerings in Japan, NEOPIN will also invest in and partner with local Web3 projects. One significant step taken by NEOPIN was its participation in IVS Crypto 2023, a high-profile Web3 startup event held in Kyoto in June. At this event, NEOPIN engaged with various Japanese businesses, initiating important connections. Since then, the Korean platform has been making progress in advancing communication and collaborations with Japanese enterprises.NEOPIN as blockchain validatorCollaboration with the Finschia Foundation will also be strengthened to achieve success in the Japanese market. In July, the blockchain mainnet Finschia launched its governance consortium and revealed its members. Within just four hours of the consortium’s launch, NEOPIN, as a governance member, received more than 1 million delegated votes, maintaining its position at the top spot in terms of voting power ever since. The Finschia mainnet was established by Line Tech Plus, a blockchain subsidiary of Tokyo-based messaging app giant Line Corporation.Serving as validators on various blockchains, including Ethereum, Tron, Cardano, and Cosmos, since 2017, NEOPIN has acquired blockchain and technical expertise. Last month, NEOPIN launched liquid staking products for ETH and KLAY, making it Korea’s first blockchain project to introduce an ETH liquid staking product. Liquid staking is a mechanism that allows users to deposit their cryptocurrencies into a staking pool, where they receive liquidity provider tokens in exchange. By holding these tokens, users can further redeposit them to earn additional yield.In light of this development, NEOPIN CEO Kim Yong-ki emphasized the CeDeFi protocol’s global expansion strategy, establishing its bases in the UAE, Japan, and Indonesia. These locations will serve as hubs for NEOPIN’s expansion efforts in the Middle East and Africa, Northeast Asia, and Southeast Asia. Kim added that NEOPIN will leverage its physical and human resources to achieve notable outcomes in the Japanese market.

news
Loading