Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

Jul 08, 2023

KuCoin CEO: Privacy Not a Key Bitcoin Feature

KuCoin CEO: Privacy Not a Key Bitcoin FeatureJohnny Lyu, the CEO of Seychelles-headquartered cryptocurrency exchange KuCoin, recently shared his perspective on the role of privacy in Bitcoin, maintaining that privacy isn’t the primary feature of the leading digital asset that many believe it to be.Photo by Karolina Grabowska on PexelsUnit of exchange is coreIn an interview with Cointelegraph earlier this week, Lyu expressed his belief that privacy is not the core feature of Bitcoin. He argued that the primary benefit of Bitcoin lies in its function as a unit of exchange, enabling users to hedge against recessions.Lyu drew a connection between the creation of Bitcoin and the 2008 financial crisis, which was triggered by the subprime mortgage crisis in the United States. According to him, these events served as the catalyst for the birth of Bitcoin. However, he made it clear that privacy is just one of the features offered by the cryptocurrency.KYC safeguarding customer fundsAddressing concerns about the increasingly stringent Know Your Customer (KYC) checks being implemented by KuCoin, Lyu emphasized the importance of these measures in safeguarding user funds. While some individuals argue that stringent KYC practices compromise privacy, the CEO believes that they enhance security. He explained that KYC procedures protect users’ assets by establishing ownership and enabling asset tracking in the event of theft.As the cryptocurrency industry continues to expand and interact with the physical world, compliance becomes crucial. Lyu expressed his belief that KYC checks are an inevitable and healthy stage in the development cycle of cryptocurrencies. Compliance measures contribute to the industry’s long-term stability and promote user confidence.New restrictionsKuCoin recently announced that starting from July 15, 2023, mandatory KYC checks will be implemented for all new users. This means that without completing the KYC process, new users will be unable to access KuCoin’s products and services. Existing users who have not undergone KYC will still be able to trade but will face restrictions on depositing new funds.Lyu acknowledged that these new KYC restrictions may impact KuCoin’s trading volumes in the short term, as some customers may choose to leave. However, the exchange remains optimistic about the long-term benefits of compliance. The CEO expressed confidence that increased compliance will attract more secure funds and users to the industry, ultimately enhancing the overall security and integrity of the ecosystem.KuCoin currently boasts 27 million users, reflecting a 35% increase compared to the previous year. Following the announcement of the KYC upgrades, the exchange experienced a notable uptick in trading volumes, with figures rising from around $540 million to over $660 million at the time of writing, according to CoinGecko data.The introduction of mandatory KYC checks is seen as a necessary step to enhance user security and protect their assets. Although short-term effects on trading volumes are anticipated, the exchange remains optimistic about the long-term benefits of compliance measures for the entire industry.

news
Markets·

Jun 25, 2024

Nomura survey indicates shift towards crypto investment in Japan

Nomura Holdings, Japan's largest brokerage and investment banking company, along with its digital asset arm, Laser Digital, has unveiled a survey indicating a significant shift towards cryptocurrency investment among Japanese investment managers.  54% of investment managers favor cryptoThe survey, conducted in April with over 500 respondents, reveals that 54% of investment managers plan to invest in crypto assets within the next three years, aiming to stabilize their portfolios and mitigate risks through diversification and hedging against inflation. According to the survey, approximately 25% of respondents hold a positive impression of cryptocurrencies, particularly Bitcoin and Ether. Meanwhile, 62% view crypto assets as a viable diversification opportunity. Around half of those that responded indicated an interest in crypto exchange-traded funds (ETFs) while 31% are considering direct investment. This trend follows the Japanese cabinet's February approval of a proposal to include crypto in the list of assets that local investment limited partnerships can acquire or hold. Nomura anticipates a revision to the Limited Partnerships Act later this year to accommodate this change.Photo by Jezael Melgoza on UnsplashNew product development to drive demandThe survey also highlights the primary drivers for future investments in crypto assets. These include the development of a variety of financial products such as exchange-traded funds, investment trusts, staking, lending and other innovative offerings. These developments align with Japanese Prime Minister Fumio Kishida's "new capitalism" economic policy. Within that policy, Kishida outlined that fostering Web3 innovation is a key priority in a keynote address at the WebX conference in Tokyo in 2023. Metaplanet bond issuanceIn a related move, Tokyo-based investment and consulting firm Metaplanet plans to issue 1 billion yen ($6.26 million) worth of bonds to finance its Bitcoin acquisitions. The firm announced on June 24 that its board had approved the bond issuance, with the Bitcoin intended for long-term holding. A separate notice detailed that the bonds would offer an annual rate of 0.5%. Metaplanet appears to be following a business strategy first pioneered by MicroStrategy in the United States. The American business intelligence firm, now focused on Bitcoin development, holds the record for a public company with the most Bitcoin, possessing 226,331 BTC worth $15 billion. It provides an alternative means through which corporations can gain exposure to Bitcoin investment. Metaplanet is likely to fulfill a similar role within the Japanese market, meeting that developing investment need identified among Japanese investment managers in Nomura’s survey. While the Nomura survey findings are largely positive, there were a number of concerns expressed by investment managers also in relation to crypto. Among them were concerns about counterparty risk, regulatory requirements and high asset volatility. However, the report suggests that there is a path through which these concerns can be minimized. The report states: “These hurdles could soon be lowered, as Japan’s digital asset laws and regulations are rapidly being developed, enabling increased engagement from institutional investors in the future.” In December, the Japanese government approved a tax regime revision to exempt corporations from paying tax on unrealized crypto gains if they hold the assets long-term.

news
Policy & Regulation·

Nov 02, 2023

Turkey crafts new crypto regulations with FATF grey list removal objective

Turkey crafts new crypto regulations with FATF grey list removal objectiveIn an effort to secure removal from the Financial Action Task Force’s (FATF) “grey list,” Turkey is in the process of crafting new regulations governing crypto assets.The FATF, established by the Group of Seven (G7) advanced economies, serves as a guardian of the international financial system. It’s an international organization dedicated to combating financial crimes, which added Turkey to its “grey list” in 2021. In 2019, it cautioned Turkey about significant deficiencies in procedures for freezing assets linked to terrorism and the proliferation of weapons of mass destruction.Photo by Michael Jerrard on UnsplashCrypto compliance for FATF upgradeTurkish Finance Minister Mehmet Simsek recently discussed this matter with a parliamentary commission, according to a report published by Reuters. Simsek highlighted the FATF’s evaluation of Turkey’s adherence to 39 out of the 40 standards set by the organization. The single outstanding issue pertains to crypto assets, and Simsek revealed plans to introduce a crypto assets law in parliament to address this concern. However, he did not delve into specific legal changes.The Turkish government is taking action to align with international standards and remove the shadow of the “grey list.” The Turkish Presidential Annual Program for 2024, as published in the Official Gazette of the Republic of Turkey on October 25, outlines a commitment to establish comprehensive cryptocurrency regulations in the country by the end of 2024. Within the extensive 500-page document, Article 400.5 sets the goal of providing clear definitions for crypto assets, potentially subjecting them to taxation in the future.Additionally, the document seeks to establish legal definitions for crypto asset providers, including cryptocurrency exchanges. However, it refrains from specifying the finer details of the upcoming regulatory framework.Crypto popularityTurkey has been an outlier in terms of cryptocurrency use by comparison with many of its international peers. A report by KuCoin earlier this year validated that reality, indicating a significant increase in the number of crypto investors in Turkey over the course of the previous 18 months. In the aftermath of a devastating earthquake which hit the country on Feb. 6, crypto was reported to have been used as a means to get aid to those affected quickly and easily.However, developments in the crypto space have also included difficulties. It was reported in July that the use of crypto for the earthquake relief effort in Turkey was also being used as a cover by an affiliate of the terrorist group ISIS to launder money and receive funding. Turkish users of the Thodex crypto exchange platform were the victims of fraud in 2021, with the founders of that business having been sentenced for that fraud in September. In 2021 the country moved to ban crypto payments against a background that has seen the Turkish lira experience hyper-inflation.CBDC developmentTurkey’s central bank has been making strides in the digital currency arena, successfully conducting the initial trial of its central bank digital currency (CBDC), the digital lira, by December 2022. The central bank has expressed its intention to continue testing and exploring digital currency development throughout 2024.The move to enhance regulation and compliance in the crypto sector in Turkey aligns with global efforts to ensure transparency and accountability in financial systems.

news
Loading