Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

Sep 08, 2023

Saudi Arabia Looks to Diversify Through Web3

Saudi Arabia Looks to Diversify Through Web3Saudi Arabia is intensifying its efforts to diversify its economy as part of its ambitious Vision 2030 initiative. In a move away from its traditional reliance on oil, the kingdom is embracing cutting-edge technologies like blockchain and artificial intelligence (AI) and is delving into the burgeoning gaming industry.That’s the view of Animoca Brands Co-Founder Yat Siu, who, in a recent interview with Cointelegraph, highlighted Saudi Arabia’s keen interest in Web3, emphasizing the country’s partnerships with entities like The Sandbox and Animoca itself.Photo by Hala AlGhanim on UnsplashDriving gaming growthSiu believes that Saudi Arabia is making a concerted effort to explore the possibilities of the new iteration of the internet, particularly in the realm of Web3 gaming and blockchain gaming, where asset ownership is verified on the blockchain. He stated:“I think Saudi [Arabia] understands the principle that Web3 gaming or blockchain gaming — the one that we actually prove the owner assets — is going to be the future of gaming.”While Saudi Arabia has yet to make a significant global impact in game and AI development, experts in the emerging field of Web3 believe that the kingdom’s investments in gaming could have far-reaching implications.The Boston Consulting Group reported that Saudi Arabia accounts for 45% of the region’s gaming sector, with a total value exceeding $1.8 billion. It also boasts one of the highest game revenues in the area, according to Ireland-based gaming content creator, Allcorrect.$38 billion gaming fundSiu is not the only one to believe in the efficacy of Saudi’s Web3 efforts. Poland-based Web3 gaming platform GameSwift also articulated a similar view recently. In a tweet thread published last month, the firm acknowledged the $38 billion gaming fund launched by the Saudi royal family.That initiative involves a Gaming Hub, the first incubator for esports in the world. The objective of the hub is to empower early-stage studios and provide an accelerator program for their growth, with direct investment going to top ten studios.Cryptocurrency uncertaintyDespite its understanding of the high-level concept of Web3, Saudi Arabia faces uncertainties regarding the integration of cryptocurrencies and virtual assets into gaming due to the absence of clear regulations. Siu explained that while Saudi Arabia is proactive in investigating cryptocurrencies, other regions like Hong Kong, Japan, and the United Arab Emirates (UAE) offer more clarity on what can be done with crypto and Web3.Siu noted that Saudi Arabia is actively seeking information on best practices and strategies from experts like Animoca. To encourage Web3 adoption, financial literacy is key, according to Siu.He emphasized that users must have a certain level of financial literacy to fully embrace Web3, as it goes beyond traditional banking. Understanding the potential value of digital assets and their network effects is crucial for Web3 users.Saudi Arabia is not the only Gulf nation to pivot to Web3. Oman is looking to do likewise based on similar rationale — to diversify away from an oil-based economy. The UAE is also actively working towards creating the right conditions to nurture Web3 startup businesses.

news
Web3 & Enterprise·

Nov 08, 2023

Lotte’s NFT marketplace partners with upcycling brand NiUl for membership NFTs

Lotte’s NFT marketplace partners with upcycling brand NiUl for membership NFTsLotte Data Communication, an affiliate of South Korean retail conglomerate Lotte Group, issued a press release on Wednesday (local time) to reveal that its NFT marketplace, Kottonseed, has issued new non-fungible tokens (NFTs) in partnership with upcycling brand NiUl whose name stands for “Nothing is Useless.”Photo by MSA-90 on PixabayPlastic lids to stylish keychainsNiUl recycles discarded plastic lids, transforming them into vibrant, stylish key ring pendants known as NiUl rings. NiUl has successfully sold over 2,000 pendants across a mix of online and offline platforms, with 300 kilograms of plastic lids donated by supporters. In a strategic move to broaden its reach, the company has been partnering with diverse firms and ramping up its donation initiatives, targeting environment and fashion-conscious millennials and Generation Z consumers.In their latest venture with Kottonseed, these pendants have been digitized into membership NFTs, which come with a suite of benefits like a special edition rope strap and discounts on products. Some lucky members may even get the opportunity to be involved in creating a NiUl ring. These membership NFTs are being released in limited numbers and are up for grabs starting today on NiUl’s page on Smart Store, an e-commerce platform of popular search engine Naver.NFTs in five colorsThe NFTs are offered in five distinct colors, each named after the sky’s varying appearances: “Post-rain Clear,” “Blue Sky,” “Sunset,” “Aurora” and “Night Sky.”A spokesperson for Lotte Data Communication expressed that the company sees great value in participating in upcycling initiatives with NiUl through their NFT marketplace, Kottonseed. They are keen on pursuing enjoyable and varied collaborations to support NiUl’s socially beneficial endeavors. Moreover, Lotte is actively exploring ways in which NFTs can contribute to environmental, social and governance (ESG) objectives.

news
Web3 & Enterprise·

Mar 08, 2024

Silicon Valley blockchain firm Gluwa becomes partner in Nigeria’s CBDC project

Gluwa, a San Francisco-based blockchain firm, has become a key partner in Nigeria’s central bank digital currency (CBDC) project, the eNaira, Korean media outlet Seoul Economic Daily reported.   Tapping into Nigeria’s 226M populationGluwa, the issuer of Creditcoin (CTC), announced yesterday that its Nigerian branch Gluwa Nigeria signed a memorandum of understanding (MOU) with the Central Bank of Nigeria (CBN). Through the MOU, Gluwa Nigeria aims to facilitate the adoption of digital currency in Africa’s largest economy with a 226 million population, by connecting eNaira to Credal, the native API for Gluwa’s Creditcoin network. This integration is expected to enhance Nigeria’s financial ecosystem by recording loan and payment transactions on the Creditcoin network.Photo by Emmanuel Ikwuegbu on UnsplashMaking the financial system more inclusive and efficient The partnership is anticipated to boost financial inclusiveness among many Nigerians who are financially isolated due to their lack of access to traditional financial services. Moreover, the CBN expects that the adoption will improve the eNaira’s functionality and spur innovation in the country’s financial system. Among other objectives of the project is to create an efficient financial infrastructure in the country so that Western fintech firms can easily enter the Nigerian financial market.   Oh Tae-lim, CEO of Gluwa, said the company plans to lay out the project’s blueprint by the end of this year and eventually broaden the acceptance of the eNaira, taking the potential of the digital currency to a new level.  Meanwhile, Gluwa’s native token, CTC, is a real-world asset (RWA) network with a loan transaction volume of KRW 106.8 billion ($80 million) and a user base of 337,000.  

news
Loading