Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Policy & Regulation·

May 25, 2023

Korean Assembly Mandates Crypto Disclosure Amidst Lawmaker’s Scandal

Korean Assembly Mandates Crypto Disclosure Amidst Lawmaker’s ScandalThe Korean National Assembly’s plenary session passed amendments to a couple of acts today that mandate lawmakers and senior government officials to report their cryptocurrency assets, according to news agency News1.Photo by Tingey Injury Law Firm on UnsplashAmendments to two actsIn an afternoon session, the National Assembly passed two amendments: one to the National Assembly Act and another to the Public Service Ethics Act.The amendment to the National Assembly Act, which had been approved by the Special Committee on Political Reform on Monday, specifically addresses the issue of cryptocurrencies and their potential conflict of interest for lawmakers. Likewise, the amendment to the Public Service Ethics Act, which had been approved by the Public Administration and Security Committee on Monday, imposes a requirement on lawmakers and high-level civil servants to disclose their cryptocurrency holdings.Mandatory crypto disclosureConsequently, starting from the 22nd National Assembly, lawmakers will be obligated to disclose their cryptocurrency assets. Additionally, the current 21st National Assembly will be required to disclose the cryptocurrencies they held and traded between the beginning of their term and May 31 of this year, with the disclosure deadline set for the end of June.A lawmaker’s crypto scandalThese legislative actions were prompted by allegations surrounding lawmaker Kim Nam-kuk, who was purportedly in possession of 800,000 WEMIX tokens from January to February of last year, potentially valued at up to 6 billion KRW (around $4.5 million). Concerns were raised regarding possible insider trading and conflicts of interest due to Kim’s ownership of these tokens.

news
Web3 & Enterprise·

Nov 29, 2023

Seoul Auction Blue seeks to register security tokens with the FSS for Andy Warhol’s artwork

Seoul Auction Blue seeks to register security tokens with the FSS for Andy Warhol’s artworkSeoul Auction Blue, the operator of fractional artwork investment platform Sotwo, recently submitted an application to the South Korean Financial Supervisory Service (FSS), local news outlet Seoul Economic Daily reported on Wednesday (local time). Its aim is to register security tokens linked to artworks with the financial authority, marking it the third entity in the country to pursue this innovative financial venture.Photo by Guido Coppa on UnsplashAndy Warhol’s ‘Dollar Sign’The artwork investment app plans to issue security tokens based on Andy Warhol’s “Dollar Sign,” a piece measuring 51.0 cm in height and 40.5 cm in length. This artwork was purchased by Seoul Auction Blue at an auction for KRW 626.2 million (approximately $485,000). The total value of the security tokens, inclusive of issuance costs, is approximately KRW 700 million. The firm will issue a total of 7,000 tokens, each valued at KRW 100,000. Upon receiving regulatory approval, Seoul Auction Blue is set to open for subscription requests from Dec. 20 to 26.In its endeavor to issue digital investment contract securities, Seoul Auction Blue has meticulously prepared its documentation in line with the FSS’s guidelines. The selection of the artwork of Andy Warhol, the renowned and iconic 20th-century artist, aligns with the FSS’s recommendation to choose a significant piece by an internationally acclaimed artist. This strategic choice reflects the company’s commitment to compliance and the recognition of Warhol’s global stature in the art world.Preventing conflicts of interestThe registration application submitted by Seoul Auction Blue includes specific restrictions aimed at preventing conflicts of interest with its affiliates related to security tokens. As per these rules, the company is barred from buying idle assets of affiliates to back its security tokens. Instead, Seoul Auction Blue is permitted to acquire them only through public methods like participating in an open bid or a post-sale bid process. Notably, the token issuer is in principle prohibited from purchasing these assets via intermediaries in private sales or any other non-transparent settings.The acquisition of underlying assets requires approval from the compliance monitoring committee. Furthermore, this regulation strips Seoul Auction Blue of the capacity to determine the final trading prices or conditions for these transactions.In addition, the company is collaborating with a couple of securities firms to safeguard investors’ funds, creating a buffer against any potential bankruptcy of the issuer. The funds raised from subscriptions for the security tokens will be managed in accounts overseen by KB Securities. Additionally, an investor protection fund is being set up, which will be handled as a trust fund by Shinhan Securities. This fund acts as an extra layer of security, offering investors enhanced protection for their investments.

news
Policy & Regulation·

Jun 07, 2023

Lawsuit Sees Further Chinese Crypto TV Coverage

Lawsuit Sees Further Chinese Crypto TV CoverageChina’s state broadcaster, CCTV, rarely covers the topic of crypto but in the space of the past three weeks, it has covered the subject twice, with the latest segment covering the news of the United States Securities and Exchange Commission (SEC) filing a lawsuit against global crypto exchange, Binance.Photo by Paolo Chiabrando on UnsplashBad pressThe segment, which aired on CCTV, provided a brief overview of the lawsuit, stating that the SEC accused Binance, its Co-Founder Changpeng Zhao (CZ), and its American affiliate Binance.US of violating US securities laws. The report also noted that the prices of Bitcoin and Binance’s native BNB coin experienced a decline following the news.The lawsuit filed by the SEC received significant media attention due to Binance’s position as the world’s largest crypto exchange. The crypto industry in the US has been under increased scrutiny following the recent troubles faced by FTX, another major player in the market. Prosecutors have alleged that FTX engaged in fraudulent activities that harmed its users.Many blame US regulators who spent hundreds of hours with FTX executives working on projects, and US Capitol Hill politicians, 33% of whom received money from FTX, as being culpable for the FTX collapse. Despite this, it’s clear that the collapse is being leveraged to effect a clampdown on the digital assets sector.It is worth noting that the CCTV broadcast also made mention of a lawsuit filed by the US Commodity Futures Trading Commission (CFTC) against Binance and CZ in March. This lawsuit, similar to the SEC’s, focused on the sale of crypto derivatives. It is unclear whether CCTV covered the CFTC lawsuit when it was initially filed.CCTV’s coverage of crypto-related news is rare, making this particular broadcast significant and garnering wider attention. The outcome of legal action taken by the SEC against Binance is being watched carefully as it will likely have implications for digital asset regulation going forward.Previous coverageIn a previous broadcast last month, CCTV aired a segment that featured cryptocurrencies, including the Bitcoin logo. Ironically, given the nature of this latest reporting, Binance’s CZ regarded that previous coverage as a noteworthy event. Historically, such coverage has often preceded bull runs in the crypto market. The segment showcased what appeared to be a Bitcoin ATM in Hong Kong, displaying a prominent blue Bitcoin logo and an option to “Buy Bitcoins.”NFTs were also highlighted in the segment. Many speculated that the coverage signified a softening of the stance of the Chinese authorities in relation to crypto. However, the video of the initial crypto segment was taken down from the broadcaster’s website shortly after CZ tweeted about it.Despite it not being the most positive of news, CCTV’s coverage of the Binance lawsuit and its previous segment on cryptocurrencies indicates a growing interest in the industry from mainstream media outlets. The attention from a state broadcaster like CCTV suggests that regulators and authorities in China are closely monitoring developments in the crypto space and considering their potential impact on the broader financial landscape.

news
Loading