Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Policy & Regulation·

May 20, 2024

Hong Kong digital yuan pilot lacks P2P capabilities

Hong Kong has launched a pilot program for the digital yuan, marking the People’s Bank of China's (PBoC) central bank digital currency’s (CBDC) first major deployment outside mainland China.  This initiative, facilitated by the Hong Kong Monetary Authority (HKMA), represents another step forward in the integration of the digital yuan into Hong Kong's financial ecosystem.Photo by bady abbas on UnsplashCross-border transactions rather than P2PAccording to a press release, the HKMA and PBoC are working together to enable Hong Kong users to set up personal e-CNY wallets using just their Hong Kong mobile phone numbers. The faster payment system (FPS) will support these e-CNY wallets, allowing users to top up their wallets through 17 retail banks in the Chinese autonomous territory. However, the e-CNY wallets are primarily designed for cross-border payments between Hong Kong and the mainland, and currently do not support person-to-person transfers within Hong Kong. This pilot aims to facilitate transactions for Hong Kong residents using their digital yuan wallets, marking the first integration of a CBDC through a major central bank. The Digital Currency Institute (DCI) is managing the interoperability infrastructure between the FPS and the digital yuan, with a focus on enhancing cross-border payments, a key objective on the G20 countries' roadmap. More functionality promisedLike blockchain protocols, the digital yuan pilot offers 24/7 payment capabilities. Eddie Yue, the chief executive of the HKMA, stated that the e-CNY application and wallet would gradually gain more functionality as the HKMA and PBoC work to encourage more retail merchants to adopt the system. Yue stated: “By expanding the e-CNY pilot in Hong Kong and leveraging the 24x7 operating hours and real-time transfer advantages of the FPS, users may now top up their e-CNY wallets anytime, anywhere without having to open a Mainland bank account, thereby facilitating merchant payments in the Mainland by Hong Kong residents.” The HKMA and DCI are planning upgrades to the e-CNY wallets through real-name verification, aiming to enable corporate use cases for cross-border trade settlements in the future. Adoption strugglesWith at least 140 countries exploring CBDC pilots, China's digital yuan is among the most advanced. China has been actively promoting its CBDC, even paying monthly salaries in e-CNY to government workers and employees of state-owned enterprises. However, as reported by the South China Morning Post, many recipients are hesitant to use the digital yuan due to privacy concerns and other limitations. China's central bank aims to increase the use of the yuan in Hong Kong, especially in tourist areas. Last June, digital yuan ATMs were installed in the resort city of Sanya in an attempt to target use of the currency by tourists. Although the city of Jinan embarked upon an initiative last year to enable digital yuan payments on its bus system, the currency is not yet widely accepted for public transportation across China.  Meanwhile, Hong Kong is in the second phase of its own CBDC pilot, the e-HKD, and has launched a regulatory sandbox for stablecoins to foster communication between regulators and issuers of fiat-pegged stablecoins in the region. 

news
Web3 & Enterprise·

Dec 07, 2023

IEEE to deploy skill certificates on blockchain for Indian members

IEEE to deploy skill certificates on blockchain for Indian membersThe Institute of Electrical and Electronics Engineers (IEEE), a professional association boasting a membership of over 75,000 in India, has chosen the Avalanche blockchain as the primary settlement layer for issuing tamper-evident certificates.Photo by Vishnu Mohanan on UnsplashIntegrating Avalanche blockchainIndia holds the second-largest IEEE membership base globally outside the United States, making this move a significant development in secure credentialing.According to a report by Cointelegraph on Wednesday, Avalanche’s C-Chain will serve as the key settlement layer for IEEE’s certificate issuance due to its compatibility with the Ethereum Virtual Machine (EVM). The decision aims to provide an ecosystem that meets the requirements for tamper-proof, instant and secure verification processes for all trainees and users receiving IEEE credentials.Zupple Labs collaborationThe blockchain certificates will be issued through LegitDoc, a blockchain-based credential lifecycle management system developed by Zupple Labs. Neil Martis, Co-Founder of Zupple, noted that the Indian public sector has shown increased willingness to implement full-fledged blockchain projects over the past 12 months, moving beyond pilot initiatives.This is the latest project in recent weeks that has seen Zupple Labs play a key role in enabling the real-world use of blockchain. Through a collaboration with the Indian Web3 startup in October, the Hindustan Petroleum Corporation (HPCL) streamlined its purchase order process, issuing tamper-proof digital purchase orders via LegitDoc.Avalanche expands into IndiaDevika Mittal, Head of Avalanche’s India arm, emphasized the significance of Avalanche’s EVM compatibility in simplifying the deployment of widely used applications, including credential registries and identity management. She pointed out that reputable institutions like SK Planet and JP Morgan Onyx prefer Avalanche as their go-to blockchain.Mittal has been a key hire for Avalanche blockchain developer Ava Labs recently as part of its efforts to target significant expansion within India. Earlier this year, the company collaborated with China’s Alibaba Cloud, the cloud computing subsidiary of e-commerce behemoth Alibaba Group, assisting with the building of a launchpad that will enable the deployment of metaverses.The partnership between IEEE and Zupple Labs is poised to bring about the issuance of numerous tamper-proof engineering credentials in India. This collaboration underscores the growing acceptance of blockchain in education credentialing, setting a powerful precedent for broader participation in the Web3 landscape.In an interview, Martis expressed the flexibility of their approach, stating:“We would be experimenting with new platforms as additional parallel settlement layers as suitable new tech emerges.”This reflects an openness to exploring evolving blockchain technologies while maintaining a commitment to ensuring the immutability, longevity and security of the solutions.The IEEE-Zupple Labs collaboration aligns with the trend of blockchain integration in educational and professional spheres, offering a glimpse into the future of secure and efficient credentialing systems. As the second-largest membership base outside the United States, India plays a pivotal role in shaping the trajectory of blockchain adoption within professional associations like IEEE.

news
Policy & Regulation·

Jan 14, 2025

Indian Railways to issue NFT train tickets for world’s largest religious festival

Indian Railways (IR), the state-owned manager of India’s railway network, plans to issue non-fungible token (NFT)-based train tickets to transport pilgrims to Maha Kumbh Mela, the world’s largest religious festival. The Hindu festival is of particular significance given that it only occurs once every 144 years. ChainCode Consulting partnership According to a report published by Indian news outlet Pune.news on Jan. 13, IR has collaborated with ChainCode Consulting, a Bangalore-headquartered enterprise blockchain development and consulting firm, to provide the digital tickets. The Polygon blockchain has been chosen as the network upon which the NFT tickets will be minted. The tickets will then be made available to end users via NFTtrace, a real-world assets (RWA) tokenization and traceability platform run by ChainCode Consulting.Photo by Choong Deng Xiang on UnsplashLong-running collaborationService users and railway personnel will be free to check the validity of tickets on the public blockchain. This announcement is just the latest installment of a long-running collaboration between ChainCode Consulting and IR. In March 2024, a similar project was pursued by both parties. On that occasion, the collaboration involved the release of a series of NFT tickets for use on a train line running from Lucknow, the capital of the Indian state of Uttar Pradesh, to the Indian capital, New Delhi.  In that instance, NFTs were minted on the Hyperledger blockchain. A previous collaboration, earlier in 2024, saw NFTs minted on Polygon for digital tickets covering journeys to the sacred Hindu city of Ayodhya. Commenting on the choice of Polygon relative to this latest collaboration, Alok Gupta, CEO of ChainCode Consulting, stated: “By partnering with IRCTC and leveraging the Polygon blockchain, we are enabling a digital-first experience that complements the spiritual and traditional significance of the Mahakumbh while introducing a new level of engagement through NFTs.” Polygon is an Ethereum ecosystem scaling network. With that, it has fast throughput and low gas fees and it's on this basis that it’s understood that Polygon was chosen in this instance. Aishwary Gupta, global head of payment and fintech at Polygon Labs, the key developer behind the Polygon blockchain, told Cointelegraph that public blockchains are playing an important role in doing away with middlemen and intermediaries.  The Polygon Labs executive stated that at both state and central government levels in India, Polygon has been used on a number of projects. He added: ”With its low cost and high throughput, we are sure that the NFTs being issued around Maha Kumbh Mela would be yet another great success.” $94 billion market opportunityTicketing remains one of the proposed use cases for blockchain technology that has the potential to gain traction. That potential hasn’t gone unnoticed by ticketing industry leader Ticketmaster. In 2023 the company rolled out token-gated ticket sales. The feature enables artists to reward fans who hold NFTs with access to exclusive pre-sale events, prime concert seating and many other incentives and rewards. NFT technology offers a solution to a number of issues experienced within the events industry, including ticket scalping, fake tickets and security issues. The live events business is a $94 billion industry, underscoring the opportunity available to be exploited by innovative NFT-based ticketing startups. 

news
Loading