Top

Wemade Unveils Blockchain-Powered Platform for Various Communities

Web3 & Enterprise·June 26, 2023, 5:23 AM

South Korean gaming company Wemade today unveiled their latest creation, Wepublic, a blockchain-powered platform for various communities. The objective of Wepublic is to establish a transparent and trustworthy digital society on the WEMIX3.0 Mainnet.

Photo by Pixabay on Pexels

 

From political parties to NGOs

Initially built as a fundraising platform, Wepublic caters to entities of any scale or domain, be it political parties, religious groups, or non-profit organizations. Wepublic is committed to transforming itself into a platform for everyone.

By leveraging blockchain, Wepublic ensures that all information and records stored on the platform are transparent, making them immune to counterfeiting and diversion. Furthermore, Wepublic is dedicated to fostering inclusivity and democratic decision-making. Every member within a group on Wepublic has the ability to engage in organizational activities and contribute to fair decision-making processes.

 

Four proof protocols

In the near future, Wepublic will introduce the “Wepublic Wallet,” enabling users to create or participate in decentralized autonomous organizations (DAOs). To ensure transparency and reliability of DAO operations, Wepublic relies on four proof protocols. These protocols serve to verify user identities, credentials, account balances, and the outcomes of governance processes.

The first protocol utilizes decentralized identifiers (DIDs) to safeguard personal information, prioritizing user privacy and security. The second protocol employs soulbound tokens (SBTs) to effectively manage groups within the platform. The third protocol provides visibility into account balances and transaction records, adding an additional layer of transparency. Lastly, the fourth protocol ensures the transparent recording of all governance processes on the blockchain, promoting accountability and trust.

More to Read
View All
Web3 & Enterprise·

Jan 18, 2024

Socket's Bungee resumes operations following exploit

Socket, a cross-chain infrastructure protocol, and its interoperability bridging platform, Bungee, have restarted operations following a temporary pause prompted by an exploit that led to the apparent theft of $3.3 million.Photo by Anna Tarazevich on PexelsSecurity incidentTaking to the company’s Discord, Socket team hospitality lead Taylor Melvin clarified that it had “experienced a security incident which affected wallets with infinite approvals to Socket contracts.” The incident, which occurred on Tuesday, involved an unknown attacker draining millions worth of stablecoins and other tokens from the Bungee bridging aggregator. The attackers targeted wallets with infinite approvals to Socket contracts, exploiting authorizations for blockchain-based tools that allow applications to access tokens in a user's wallet. Security researcher "@speekaway" was the first to flag the exploit on Tuesday. The attacker's wallet, connected to the exploit, held nearly $3 million in ether (ETH) and $300,000 worth of other tokens. By 2:47 p.m. ET, the attack seemed to have ceased, with the researcher recommending users to revoke approvals for Socket to safeguard their assets. Pausing contractsIn response to the security breach, Socket announced the pause of affected contracts on Tuesday at 3:15 p.m. ET. The project's team promptly identified and addressed the issue, taking swift action to mitigate the exploit's impact. @speekaway chimed back in once contracts had been paused, writing:”Think this pause fixed it, very likely no more attacks are possible. So if you are currently freaking out about revoking you can probably relax.” Normal service returnsAs Socket paused activity during the incident, preventing further propagation of the attack, developers worked to fix the issue. Early Wednesday, Socket developers announced that the problem had been resolved, and normal activities had resumed. The team also stated that plans for compensation were in progress. Cross-chain bridges, like Socket's Bungee, facilitate token transfers between different blockchains but remain susceptible to exploitation. Blockchain security and data analytics company PeckShield confirmed that at least $3.3 million had been lost, highlighting the need for enhanced security measures in the rapidly evolving blockchain ecosystem. The exploit involved the exploitation of a recently added route, which has since been disabled. The attacker targeted users who had over-approved Socket, draining funds up to the limit of their approval. This incident follows the $81 million hack of Orbit Chain, a cross-chain bridge connecting Ethereum to other networks, earlier in January. Cross-chain tools' complexity contributes to the frequency of such attacks, emphasizing the importance of understanding the security measures in place when utilizing these bridges. In a message to CoinDesk, Sergey Nazarov, co-founder of Chainlink, emphasized the need for users to scrutinize the security of their chosen bridge, considering the various levels of cross-chain security. With the complexities involved, users are encouraged to be vigilant and informed about the security spectrum of the bridges they employ. Socket was founded by Indian duo Rishabh Khurana and Vaibhav Chellani. In September, the company raised $5 million, with funding coming from Framework Ventures and Coinbase Ventures. 

news
Policy & Regulation·

Oct 28, 2023

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability FixSmart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.Photo by Nenad Novaković on UnsplashAccount abstraction vulnerabilityThis vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.Improving user experienceAccount abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.Company mergerEarlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

news
Policy & Regulation·

Sep 05, 2023

South Korea Reveals Guidelines for Public Officials’ Virtual Asset Disclosure

South Korea Reveals Guidelines for Public Officials’ Virtual Asset DisclosureSouth Korea’s high-ranking government officials will soon be obliged to divulge specific information regarding their virtual asset holdings, including types and quantities, as part of their wealth declaration process. The Ministry of Personnel Management (MPM) issued a press release yesterday, announcing revisions to the Enforcement Decree of the Public Service Ethics Act. These amendments are slated to come into effect on December 14.Photo by Chris Boland on UnsplashIn addition, officials holding positions of rank one or higher will be required to disclose the methods through which they acquired their virtual assets. They must also furnish documentation of transaction records for a period of one year.These amendments to the decree come in the wake of the revised Public Service Ethics Act, which was passed in May. The primary aim of this act is to make it obligatory for government employees to declare their virtual asset holdings. The changes to the decree can be summarized into five main points.Types and amountsFirst, officials obligated to disclose their wealth must report the types and amounts of virtual assets. The prices of virtual assets traded on Upbit, Bithumb, Coinone, and Korbit — all virtual asset service providers (VASPs) designated by the Commissioner of the National Tax Service — are required to be reported using the average daily price observed on the reporting day. As for other assets, their values should align with their most recent market prices. In cases where determining these prices is not feasible, they should be reported at reasonable values that reflect transaction prices.Acquisition methodsSecond, high-level public officials must explain how they acquired virtual assets. Under the existing regulation, officials are obligated to reveal both the date and method of acquisition, along with the source of funds. However, following the adoption of the updated decree, they will also be required to provide analogous information for virtual assets.Year-long transaction historyThird, comprehensive guidelines will be established to outline the process of reporting virtual asset transaction history records. Officials subject to the disclosure requirement must divulge all virtual asset transactions conducted within the past year, even if they do not possess such assets on the day of reporting. They are obligated to furnish documentation prepared by VASPs.Officials and their family membersFourth, officials are required to permit VASPs and other relevant institutions to provide the Government Ethics Committee with information on virtual asset holdings owned by both themselves and their family members. This will be facilitated through the inclusion of virtual assets in the existing information provision agreement, similar to the approach applied to other types of assets such as real estate.Addressing conflict of interestLastly, the revised decree could potentially impose restrictions on certain public officials with regard to possessing virtual assets, especially when their responsibilities encompass tasks like formulating relevant policies, granting approval for virtual assets, and overseeing taxation matters related to them. The outcomes of these restrictions will be reported on an annual basis to the Government Ethics Committee.In a briefing regarding this development, MPM Vice Minister Lee In-ho underscored the significance of the amended decree as the regulatory framework for enforcing the requirement of public officials to declare their virtual assets. He highlighted the Korean government’s commitment to ensuring that public servants adhere to accurate reporting practices concerning virtual assets, thereby preventing unlawful accumulation of wealth.

news
Loading