Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Oct 11, 2023

State-Owned Newspaper to Launch NFT Platform in China

State-Owned Newspaper to Launch NFT Platform in ChinaChinese government-owned media outlet China Daily, under the guidance of the Publicity Department of the Chinese Communist Party, has allocated a substantial budget of 2.813 million yuan (equivalent to $390,000) for the development of an NFT platform.Photo by Hanson Lu on UnsplashInviting bids from home and abroadThe move will open the door to both domestic and international blockchain technology firms, inviting them to spearhead the creation of the platform. According to a public tendering announcement published last month, the chosen firm must operate on a blockchain mainnet capable of handling over 10,000 transactions per second, ensuring top-notch performance and reliability.One of the platform’s key features will be its user-friendly interface, allowing users to effortlessly upload, display, and manage their digital collections. It will support a wide range of multimedia formats and diverse collection types, making it a versatile hub for creative expression. Additionally, the platform will offer advanced functionalities like pricing, bidding, limited-time offers, and multi-currency settlement to ensure a comprehensive and satisfying user experience.Extending the reach of Chinese cultureThe core objective of the China Daily NFT Platform is to amplify the global influence of Chinese culture by seamlessly blending technology and culture in the metaverse. This ambitious strategy integrates cutting-edge technologies such as virtual reality (VR), augmented reality (AR), mixed reality, blockchain, non-fungible tokens (NFTs), big data, and cloud computing.In an effort to expand the global reach of their digital collections, China Daily intends to collaborate with both domestic and international mainstream NFT platforms. This ambitious plan includes partnerships with well-known foreign platforms such as OpenSea, Rarible, SuperRare, and Foundation. Despite the rigorous regulatory landscape and scrutiny that blockchain entities face in China, this approach aims to make Chinese digital collections more accessible to a global audience.The urgency and importance attached to this project are evident in the tight timeline set by China Daily. The chosen contractor must submit their application by October 17 and complete the development of the platform within three months, highlighting the publication’s commitment to this venture.NFT platform development despite crypto banHowever, it’s important to acknowledge that this initiative unfolds within the backdrop of stringent cryptocurrency regulations in China. Since 2021, although NFTs have not been banned, all forms of cryptocurrency transactions have been prohibited in the country, and blockchain entities operating within China face intense regulatory oversight.In May the Supreme People’s Procuratorate of China issued a warning relative to NFTs on the basis that they have crypto-like properties. However, the agency also acknowledged that NFTs do present a novel application of blockchain technology.Recent events, including the detention of former China Evergrande executives Xia Haijun and Pan Darong for alleged involvement in fraudulent activities, underscore the strict regulatory environment prevailing in China.Within the Chinese autonomous territory of Hong Kong, the South China Morning Post (SCMP) spun out Artifact Labs, an NFT company, following an initial decision in 2021 to launch an NFT standard called artifact.China Daily’s foray into the NFT space demonstrates that some facets of blockchain innovation are being leveraged within China, in this instance with a view towards cultural promotion and global engagement.

news
Web3 & Enterprise·

Aug 28, 2023

Kiwoom Securities and Koscom Partner to Pilot Security Token Platform Amid Regulatory Changes

Kiwoom Securities and Koscom Partner to Pilot Security Token Platform Amid Regulatory ChangesKiwoom Securities, a securities firm based in South Korea, has recently taken a step forward by announcing its collaboration through a memorandum of understanding (MOU) with fintech company Koscom. This partnership aims to carry out a pilot program for a security token platform.Photo by Shubham’s Web3 on UnsplashPreparing for regulatory shiftIn light of the expected enactment of a revised bill that will establish a legal framework for security tokens, the two companies have joined forces to work towards creating standardized practices for security tokens. Once this regulatory act comes into effect, fractional investment companies — the entities responsible for issuing security tokens — will have the opportunity to kick-start their operations promptly. This will be possible by utilizing the systems developed by securities firms, also known as account management institutions. The primary objective of this MOU is to define the essential industry standards that will facilitate this process.Combining strengthsWhile Kiwoom Securities benefits from a substantial retail customer base, Koscom brings technological expertise to the table thanks to its four-decade-long track record of constructing the data infrastructure for capital markets. Together, they will work to verify the seamless integration of distributed ledger technology into the operational system of the securities firm.Kiwoom Securities has been making strides in this direction through its partnerships with diverse companies, including music copyright trading platform Musicow and fine arts fractional investment platform Tessa. These collaborations have provided Kiwoom Securities with practical experience and technological insights relevant to security tokens.Hwang Hyun-soon, CEO of Kiwoom Securities, expressed Kiwoom’s commitment to collaborating to ensure that the security token platform developed by both companies evolves into a benchmark platform for the future security token market.Hong Woo-sun, CEO of Koscom, remarked that they expect the agreement to play a role in advancing their security token businesses and developing the Korean security token market.

news
Policy & Regulation·

Sep 19, 2023

Rising Cryptocurrency Arbitrage Transactions Raise Concerns in South Korea

Rising Cryptocurrency Arbitrage Transactions Raise Concerns in South KoreaThe number of arbitrage transactions between South Korean and foreign cryptocurrency exchanges has been experiencing a notable uptick, according to a report by local media outlet Maeil Business Newspaper.In recent developments, foreign actors engaging in price manipulation have been transferring substantial amounts of cryptocurrency assets to Korean exchanges, driving up prices. Subsequently, they transfer these tokens from Korean exchanges back to overseas platforms, capitalizing on the price discrepancies to generate profits.Photo by Maxim Hopman on UnsplashBithumb’s case in H1According to documents submitted to Kim Hee-gon, a member of the ruling political party People Power Party, on Monday, KRW 3.4 trillion ($2.6 billion) worth of tokens were moved from Bithumb, a leading Korean cryptocurrency exchange, to foreign trading platforms during the first half of this year. Although this figure marks a 40% decrease compared to H1 2022’s KRW 5.7 trillion, primarily due to the significant decline in token prices across the cryptocurrency market, it’s noteworthy that the number of transactions has seen a significant increase.Other exchangesGopax, another major exchange in the nation, recorded token outflows totaling KRW 12.3 billion. On the other hand, Upbit, Coinone, and Korbit, which are also prominent exchanges, declined to provide data due to reasons like confidentiality concerns. However, given that Upbit holds an 82.0% share of the Korean crypto market, nearly four times larger than Bithumb’s share (14.2%), it is suspected that the volume of tokens transferred from Upbit to foreign platforms would likely have followed a similar proportion.While the value of tokens sent from Bithumb to overseas operators saw a year-over-year decrease, the number of transactions surged to 231,302, nearly doubling the figure of H1 2022’s 124,048 transactions. The average transaction size was KRW 14.7 million.Even though the overall enthusiasm for cryptocurrencies might have cooled off since last year, the spike in the number of transactions suggests that there’s been a surge in arbitrage trading between Korea and foreign markets.Kimchi premiumEarlier this month, a significant transaction caught the eye of cryptocurrency market observers in South Korea. On September 1, crypto data analytics firm Arkham identified that 170,000 CyberConnect (CYBER) tokens were transferred to Bithumb from a crypto wallet thought to be owned by DWF Labs, a firm specializing in cryptocurrency trading and investment. The timing of the transaction coincides with a period during which the Kimchi premium for CYBER exceeded 100%. The Kimchi premium refers to the crypto price gap between Korean exchanges and their foreign counterparts.The complicating factor here is that DWF Labs is a foreign entity that is managed by a foreign team.The use of corporate accounts is virtually prohibited in the Korean crypto market. The Travel Rule mandates that any transfers of tokens between Korean and international exchanges must go through accounts that have been verified under Know Your Customer (KYC) guidelines. Given these regulations, there are growing suspicions within the crypto community that foreign venture capitalists may have used accounts in borrowed names to conduct sales on Korean exchanges, which are restricted to Korean citizens. However, it’s worth noting that there is currently no legal basis for taking punitive action even if borrowed-name accounts were indeed used.Lawmaker Kim commented on the limitations of current financial regulations aimed at preventing money laundering in the cryptocurrency market. Despite efforts by financial authorities, including the introduction of the Travel Rule, Kim stated that these measures have not been very effective. He emphasized the urgency of enhancing the regulatory framework to curb potential illicit activities involving cryptocurrencies, such as those exploiting market arbitrage opportunities.

news
Loading