Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Policy & Regulation·

Feb 22, 2024

Efforts continue in Japan to bring about optimized regulation

Japan’s Financial Services Agency (FSA) has moved recently to address concerns related to peer-to-peer (P2P) transactions while in a separate development, the country’s GameFi community is calling for regulatory change to enable greater liquidity. The two distinct developments both relate to getting the balance right in terms of crypto regulation from the perspectives of regulators and lawmakers and crypto sector entrepreneurs and participants.Photo by Manuel Cosentino on UnsplashAddressing concernsIt emerged last week that the FSA had proposed a number of measures to safeguard users against “unlawful transactions,” causing alarm that any such moves would inhibit the P2P transactions market. Responding to a query from Cointelegraph, the FSA elaborated that its recommendation does not encompass "transactions from one individual to another." Instead, it aims to bolster measures against illicit money transfers, particularly instances where an individual deposits cash from their bank account into an account belonging to a crypto asset exchange service provider. The regulator clarified that under the new recommendations, banks would intercept suspicious transactions where the sender seeks to alter their name for the purpose of depositing funds into the crypto platform. The FSA outlined that this situation arises where a fraudster convinces an innocent exchange user to effect the name change, so that exchange rules can be circumvented and the fraudster can receive funds from the scam victim. According to the FSA, numerous financial institutions have already implemented these measures, although the agency has not received any reports of specific cases raising concerns regarding crypto asset markets. Notably, the FSA emphasizes that its recommendations are not universally mandated for all financial institutions, with banks expected to devise and implement measures tailored to their specific circumstances. Solving crypto market liquidity issuesWith that clarification, it appears that the measures won’t have the negative impact on P2P crypto markets as many market participants originally feared. Meanwhile, in a distinct development, Japan's blockchain gaming community has approached the Liberal Democratic Party (LDP) to seek assistance in bolstering liquidity within Japan's crypto asset market. Taking to the X social media platform on Wednesday, Ryo Matsubara, director of Oasys, a GameFi blockchain, outlined that he had visited the LDP's digital society promotion headquarters on behalf of Japanese blockchain gaming projects to raise concerns about stringent regulations impeding liquidity in Japan, which directly impedes the growth of the GameFi ecosystem. Matsubara advocates for regulations that incentivize safe cryptocurrency investment, positing that increased liquidity, marked by a surge in buyers and sellers, could result from such measures. Oasys intends to continue collaborating with the government to enhance Japan's global competitiveness in the Web3 market, with Matsubara expressing confidence in Japan's potential to reclaim its illustrious gaming legacy on Web3. While Japan initially harbored skepticism toward crypto adoption, its stance has softened in recent times. Matsubara acknowledged the positive impact of a recent crypto-related tax reform which was enacted in December. In September 2023, the Japanese government commenced planning to permit startups to raise public funds through crypto asset issuance. That bill was approved last week and now goes forward to the Japanese parliament for further deliberation. These recent developments demonstrate that Japan is navigating regulatory complexities as it seeks to balance innovation with consumer protection in the burgeoning crypto space.

news
Web3 & Enterprise·

Aug 01, 2023

NPIXEL Wraps Up 2nd Community Test for Web3 Game “Gran Saga: Unlimited”

NPIXEL Wraps Up 2nd Community Test for Web3 Game “Gran Saga: Unlimited”Korean game developer NPIXEL announced on Tuesday the successful completion of the second community test for its Web3-based PC massively multiplayer online role-playing game (MMORPG) called “Gran Saga: Unlimited.”The test — conducted over the course of two weeks with some 8,000 global participants — was aimed at enhancing the gameplay environment and strengthening community-based content ahead of the official release of the game.Photo by Andrey Metelev on UnsplashExploring game features and player-based developmentAccording to local news outlet ETnews, participants had the opportunity to try out various features within the game, including new dungeons, a 16-player raid, and a player-versus-player (PvP) battleground called “Chaos Field.” In particular, the “Idol & Fan” system garnered significant attention, where 100 global influencers who received soulbound tokens participated as “idols” to create diverse content with their “fandoms.”NPIXEL’s development team was actively engaged in the testing process, collaborating with users to strategize dungeon conquests and partake in community activities. They implemented real-time communication with users, gathering feedback and opinions to build a game that players directly contributed to.“Proof-of-Play”: The expansion of blockchain in gamingOne of the key features of Gran Saga: Unlimited is its Proof-of-Play technology, NPIXEL explained, much like the Proof-of-Work process used in cryptocurrency. Proof-of-Play involves recording all the in-game items and commodities that a player receives on a blockchain, thus proving and disclosing the items’ randomness of acquisition. The difficulty of obtaining certain items is determined based on in-game demand, and users can search and verify real-time information such as time of acquisition, ownership identification, and random probability.Upcoming launch and exclusive rewardsThe developer is also offering rewards to all 8,000 testers, including a Mount NFT when the game is launched and a chance to win a whitelist spot raffle of Catcha NFT with 1,000 open spots to all testers.NPIXEL will thoroughly review user feedback and opinions collected during the test to further improve the game, after which they plan to officially launch the game through the web-based premier gaming ecosystem, METAPIXEL.METAPIXEL will be developed on the Layer 1 blockchain network Aptos, which is based on NPIXEL’s partnership with Aptos established back in November of last year.

news
Web3 & Enterprise·

Oct 17, 2024

Hybrid exchange Cube lists Access Protocol (ACS)

CUBE, a hybrid crypto exchange that settles trades on-chain using secure multi-party computation, announced on its official X account that it has listed ACS, the native token of Solana-based monetization platform Access Protocol.  The hybrid exchange utilizes its custom rewards platform, Blocks, to engage users through unique packages for listing traders and token holders. Participants in the listing will be eligible for campaign rewards.  Bartosz Lipinski, CEO and co-founder at CUBE, recently revealed plans around Isometric (ISO), an intent-based transaction network, enabling cross-chain trading to eliminate the need for asset bridging.  “When we started building Cube, we wanted everything to be an intent… Everyone will be able to submit intents to the network and verify settlements on multiple chains using the decentralised MPC that we’ve built,” Lipinski said during his presentation at the Solana Breakpoint conference. “Through the decentralised MPC integration layer, you will be able to actually use the value on different layer ones without cannibalising it,” he went on to share.  ISO will be the platform token powering governance, staking, and decentralized custody, according to Cube's announcement. Both Token and Mainnet launch are expected to happen some time in Q2 2025.  In a related development on Monday, Cube announced its partnership with the Argentinian government. The company plans to explore leveraging the Isometric network as a catalyst for the South American nation’s financial system. 

news
Loading