Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Nov 15, 2023

Bitget withdraws from Hong Kong crypto market

Bitget withdraws from Hong Kong crypto marketSeychelles-incorporated cryptocurrency derivatives platform Bitget has made a decision to permanently exit the Hong Kong market, discontinuing its efforts to obtain a virtual asset trading platform (VATP) license.Photo by SHUJA OFFICIAL on UnsplashBitgetX platform shutdownThe decision comes only months after it had introduced its BitgetX platform to comply with local regulations. The company, which bases its operations out of Singapore, is a well-known entity in the crypto space, renowned as the operator of the 12th-largest cryptocurrency exchange globally in terms of 24-hour trading volume. It made this revelation on Monday, citing what it referred to as “business and market-related considerations.”In a published statement, the company said:”With a heavy heart, we regret to inform you that due to business and market related considerations, we have decided not to pursue a Virtual Asset Trading Platform (VATP) license in Hong Kong. As a result of this decision, the BitgetX website (www.BitgetX.hk) will cease its operations effective December 13, 2023. At the same time, Bitgetx.hk will permanently exit the Hong Kong market.”While outlining that BitgetX will close its doors, the firm urged users to withdraw their assets beforehand. Bitget is among a handful of exchanges that had publicly expressed their intent to secure a license following Hong Kong’s proactive push over the course of the past year to embrace the virtual asset sector.Broader challengesThe decision to abandon the pursuit of a VATP license echoes the broader challenges faced by the cryptocurrency industry in Hong Kong. Despite the city’s recent enthusiastic regulatory embrace of the virtual asset sector, a number of stumbling blocks remain.High compliance costs and the lingering aftermath of the JPEX financial scandal have hindered Hong Kong’s aspirations to establish itself as a leading crypto hub. A report back in June identified the major cost implications of acquiring a license in Hong Kong. At the time, it was estimated that the required spend to obtain a VATP license could range from $2.55 million to $25.5 million.Banking crypto companies has also become a major bottleneck. In June, the Hong Kong Monetary Authority (HKMA) urged banks such as HSBC, Standard Chartered and the Bank of China to bank the crypto sector, having identified a reluctance amongst them to do so.Limited interestThe forthcoming closure of BitgetX adds to a growing trend of limited interest in Hong Kong’s new licensing scheme. Only five companies, all local, have submitted applications for virtual asset licenses to the Securities and Futures Commission (SFC). This list began publication in response to the JPEX scandal, which significantly damaged public trust in virtual assets.The challenges faced by the industry go beyond regulatory hurdles. The damaged public trust, coupled with the high-profile exit of JPEX, has contributed to the hesitancy of international crypto platforms in pursuing licenses in Hong Kong. The abrupt withdrawal of Bitget raises questions about the viability of Hong Kong as a central player in the cryptocurrency industry and underscores the complexities faced by exchanges navigating the evolving landscape of the digital asset sector.

news
Policy & Regulation·

Sep 05, 2023

Chinese Central Bank Official Emphasizes Need for Digital Yuan Retail Payments

Chinese Central Bank Official Emphasizes Need for Digital Yuan Retail PaymentsA senior official from the People’s Bank of China (PBOC) has underscored the importance of making China’s digital yuan, commonly referred to as the e-CNY, accessible in all retail payment scenarios within China.Photo by Eric Prouzet on UnsplashStreamlining retail e-CNY paymentsThe remarks were delivered by Changchun Mu, Head of the Digital Currency Research Institute, during a trade forum in Beijing. Mu emphasized the need for standardizing QR codes in payment systems, particularly those dominated by giants like WeChat Pay and Alipay.Local media reported on Sunday that the central bank official highlighted that various wallet providers, including WeChat, Alipay, commercial banks with mobile banking apps, and other payment apps associated with e-CNY operations, must remain vigilant about complying with relevant financial regulations and obtaining the necessary licenses. He stressed that the initial step in this process should involve the adoption of the digital yuan as the preferred payment method for all retail transactions.Standardizing QR code paymentsMu explained that in the short term, authorities can start by unifying QR code standards on a technical level to achieve barcode interoperability. In the long run, he suggested that they will steadily implement the upgrade of payment tools.The move towards standardizing QR code payments aligns with the central bank’s commitment from the previous year to promote universal QR payment codes. This initiative aims to allow consumers to make payments by scanning a unified barcode. Currently, QR code payment systems are widely prevalent in China, with WeChat Pay and Alipay being dominant players.The PBOC has been actively testing the e-CNY, having introduced a pilot app in January 2022. The digital yuan pilot programs, initiated in late 2019, have expanded to encompass at least 26 locations across 17 provincial-level cities and regions, including major cities like Beijing, Shanghai, Shenzhen, and Suzhou, according to state media Xinhua.The extent of China’s promotion of its digital yuan has been unmatched despite the fact that most central banks globally have had ongoing central bank digital currency-related (CBDC) projects open for a number of years already.Recent months have seen the launch of a whole host of initiatives to further the use of the CBDC. These initiatives have included integration of the currency into the education system in Jiangsu province, the installation of digital yuan ATMs in Hainan, among many other such projects, and paying state employees with the currency in Changshu. That said, despite these efforts, widespread adoption of the e-CNY remains a work in progress.Bringing about e-CNY integrationMu also emphasized that the existing interbank payment and settlement systems function effectively, indicating that there is no immediate need to replace them with the CBDC system. Instead, he suggested that seamless integration could be achieved by ensuring comprehensive interoperability between the e-CNY and existing electronic payment tools and commercial bank deposit systems.Moreover, at a wholesale level, Mu proposed the use of the digital yuan for settlement within the financial market infrastructure. Smart contracts could also be leveraged for such activities, thereby enhancing efficiency in wholesale payments.Mu’s remarks underscore the Chinese central bank’s determination in advancing the development and adoption of the digital yuan while ensuring it remains integrated into the existing financial ecosystem.

news
Web3 & Enterprise·

Nov 06, 2023

DeFi investment platform Allbit.com adds portfolio and analytics services

DeFi investment platform Allbit.com adds portfolio and analytics servicesBlockchain firm Ozys, announced on Nov. 3 (local time) that it has added portfolio and analytics services to its comprehensive Web3 financial investment platform Allbit.com.Photo by rc.xyz NFT gallery on UnsplashIntegration with KlaytnThe beta version of Allbit.com was launched in March, with a trading view chart displaying real-time prices of cryptocurrencies based on trades that are made on KLAYswap, a major decentralized finance (DeFi) protocol launched by Ozys. KLAYswap is built on Korean tech juggernaut Kakao’s open-source public blockchain called Klaytn.Newest features“Users of KLAYSwap and KLAYSTATION can now easily check the status of their on-chain activities without having to track them separately,” explained Ozys CEO Roi Choi.The “My Portfolio” feature on the recently updated platform gives users a convenient way to monitor their asset balances, the liquidity on KLAYswap, and the staking status of KLAYSTATION, a staking tool based on the Klaytn network. For better risk management, the “Net Asset Trend” graphically displays daily changes in the user’s net asset value. Additionally, the “PNL (ROI) Dashboard” provides insights into profit and loss by showing real-time and periodic performance data. Whether tokens are held in a personal wallet or deposited into a particular service, the dashboard tracks token price movements to present users with an up-to-date view of their investment returns.Allbit.com customers can also keep up with activities on various wallets and market trends through their personalized watchlists and share their portfolios with others.Choi added that Ozys plans to add more functions to Allbit.com in the future to enhance the user experience and optimize convenience.

news
Loading