Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

May 23, 2023

TON Foundation $250M Accelerator Fund Launch

TON Foundation $250M Accelerator Fund LaunchThe team behind The Open Network (TON) layer one blockchain has launched a $250 million fund to promote and incentivize development on the network.The Dubai-headquartered TON Foundation, the community managing the TON/Open Network blockchain project, provided details of the program via social media on Monday.Photo by Ibrahim Boran on UnsplashBoosting ecosystem projectsThe $250 million fund is aiming to boost key TON ecosystem projects, with a particular focus on DeFi. The TON Foundation is already canvassing projects to participate and apply for funding.Successful applicants will be offered between $50,000 and $250,000. The scheme goes beyond funding. Projects will also get to avail of mentorship from partners like GotBit, a consulting service targeted at blockchain start-ups. Growth advisory firm Web3Port will also be available to successful candidates in that mentorship role.UAE-based multi-strategy crypto investment firm Cypher Capital will also be at the disposal of the TON-based start-ups, while they will also have the ability to access the Tonstarter launchpad. Additionally, the scheme features participation from East Asia, with South Korea-based Boom Labs, an incubator for Web3 developers, lending its support.Justin Hyun, Head of Incubation and Growth at the TON Foundation, had this to say about the development:“This is the beginning of many different incubators which will be supported in the future. Funding forms part of our local hubs rollout strategy and our ecosystem will work to attract new developers as well as successful repeat founders, based across a variety of key global locations.”$25M funding in first yearFunding will be allocated from the TONcoin.Fund, a $250 million TON syndicate which invests in teams and projects that build on The Open Network. In the first year of the program, $25 million will be allocated.Bill Qian, Chairman of Cypher Capital, said that the program “is unique within the Web3 universe today.” “TON Accelerator Program is taking the well-known incubator principle from the Web2 ecosystem, refining it, and evolving it by incorporating the best practices of Web3 protocols and methodologies,” he added.DoraHacks Hack-a-TONxIn its announcement the TON Foundation outlined its intention to select the first successful projects from those who took part in the DoraHacks Hack-a-TONx. Hack-a-TONx was a two-month-long hackathon, put together by the TON Foundation in coordination with global hackathon organizer and multi-chain Web3 developer community, DoraHacks.Submissions are being accepted by the TON Foundation from projects that have built on TON, who already have a minimum viable product (MVP). Although originally promoted by the makers of the Telegram messaging app, since 2020, TON has harnessed the TON Foundation to develop the project as a community-run and community-led open source initiative.The African nations of Cameroon, the Democratic Republic of the Congo, and the Republic of Congo have all expressed an interest in adopting the TON blockchain. Earlier this month, the TON Foundation entered into a partnership with the Seychelles-based BIT crypto exchange. That collaboration will see BIT accepting TON tokens from its users for the payment of trading fees, with discounts offered to the exchange users who opt to pay using TON.

news
Web3 & Enterprise·

Sep 05, 2023

Bybit Leans on Innovative Tech by Launching AI-Powered Trading Assistant

Bybit Leans on Innovative Tech by Launching AI-Powered Trading AssistantDubai-headquartered cryptocurrency exchange Bybit has introduced TradeGPT, an AI-powered educational tool aimed at changing the way in which traders interact with the cryptocurrency market.A ToolsGPT follow-upThe move follows on from the firm’s launch of ToolsGPT in June, an AI-based tool that aids platform users to generate technical analysis and takes a ChatGPT-like approach in providing responses to user queries. Vivien Fang, Head of Financial Products at Bybit, explained: “Our analysts and tech team created ToolsGPT to provide the financial education and mentorship that is sorely needed in our hyper-financialized world. Essentially, we built the tool that we all wished we had when we began our careers in financial engineering and trading.”Photo by Wance Paleri on UnsplashAI mentor and guideFor Bybit users, TradeGPT offers a multitude of benefits, including real-time market analysis, multilingual support, and personalized guidance. It functions as a mentor and guide, empowering users to comprehend market trends, formulate strategies, and select the most suitable investment products to achieve their financial goals.This offering addresses the limitations of traditional AI systems and provides real-time market data. TradeGPT leverages Bybit’s extensive market data, trading analytics, and technical analysis tools, making it a resource for traders navigating the complexities of the cryptocurrency landscape.Following industry trendBybit’s TradeGPT follows in the footsteps of Singapore-based platform Crypto.com, which unveiled its AI-enabled platform, Amy, in May. Amy leverages the technology of OpenAI’s ChatGPT to deliver real-time information about specific tokens, projects, price listings, and historical events to Crypto.com platform users.At the time Kris Marszalek, CEO of Crypto.com, highlighted the platform’s significance, stating: “Amy is the latest example of our incredible momentum.” The company added that it followed a series of notable product launches, including CFTC-regulated options trading, on-chain staking solutions, and the GEN 3.0 Crypto.com Exchange.Binance, the world’s largest cryptocurrency exchange by trading volume, introduced Binance Sensei in April. The company has integrated the AI-powered learning tool into Binance Academy and offers users of all skill levels an interactive chat window for guidance.As an increasing number of cryptocurrency companies launch AI-enabled platforms, the synergy between AI and the industry becomes more apparent. AI’s data processing capabilities could address scalability issues and expedite transaction processing for cryptocurrencies.Conversely, cryptocurrencies could incentivize research and development in the field of AI. Tokenized economies may reward contributors to AI projects, fostering collaboration and innovation. Furthermore, cryptocurrency-enabled decentralized networks could provide secure and transparent platforms for exchanging AI-generated insights without the need for intermediaries.Digital assets are developing in real-time alongside other technologies. The introduction of Bybit’s TradeGPT, alongside Crypto.com’s Amy and Binance’s Sensei, offers a step forward in harnessing the power of AI to empower cryptocurrency traders. As these AI-driven tools continue to evolve and gain traction, they’re likely to reshape how individuals and institutions engage with the cryptocurrency market.

news
Policy & Regulation·

Aug 17, 2023

Dubai Regulator Hits OPNX With $2.7M Penalty

Dubai Regulator Hits OPNX With $2.7M PenaltyCrypto bankruptcy claims trading platform OPNX and its founders have been hit with a hefty fine, imposed by Dubai’s Virtual Assets Regulatory Authority (VARA). The penalty, amounting to AED 10 million ($2.7 million), was levied on the newly established exchange in accordance with a notice published by the regulator on Wednesday.Photo by Agnieszka Stankiewicz on UnsplashPayment outstandingVARA’s recent announcement highlighted that the fine had been imposed in May and remains outstanding. The regulatory body disclosed that individual fines of AED 200,000 ($54,451) each were imposed on Su Zhu and Kyle Davies, the controversial founders of failed Singapore-based crypto hedge fund, Three Arrows Capital (3AC). Additionally, fines were also imposed on two other co-founders of OPNX. The penalties were attributed to failures in adhering to regulations governing marketing, advertising, and promotions.OPNX, established earlier this year by Su Zhu and Kyle Davies in collaboration with Mark Lamb and Sudhu Arumugam, positioned itself as a trading platform for crypto claims following the collapse of their Three Arrows Capital (3AC) fund last summer. The duo has since made Dubai their primary operational base.Further action“In light of the company’s unpaid fine, VARA shall determine consequential actions warranted against OPNX, which may include further fines, penalties, and/or taking any actions necessary to recover payment and definitively remedy the behavior,” stated VARA in an official statement.Dubai is making a concerted effort to nurture the development of crypto-related business, implementing various initiatives in order to bring that about. However, as part of that strategy, Dubai’s regulatory landscape for cryptocurrencies has taken a more stringent turn this year, with the introduction of a new regulatory framework mandating that companies catering to retail investors must secure full licensing from VARA.Concerns arose in February when regulatory authorities discovered that OPNX was actively seeking customers for its platform and collecting personal data without proper authorization.Formal reprimandsIn April VARA issued an investor alert, outlining that OPNX was not a regulated entity although it was operating from Dubai. Shortly afterwards, formal reprimands followed for the two 3AC founders, alongside Mark Lamb, Sudhu Arumugam, and OPNX’s CEO Leslie Lamb.Leslie Lamb, in a previous interview with Bloomberg, emphasized that OPNX had not actively marketed itself toward Dubai or the broader UAE market. She stressed the company’s full cooperation with VARA’s ongoing investigation, asserting that no regulatory guidelines had been breached.“While Kyle and I contributed the initial ideas for OPNX, Leslie is very much the CEO, and we aren’t involved in day-to-day operations,” stated Su Zhu, clarifying their roles.Despite the regulatory setback, both Su Zhu and Kyle Davies continued to promote OPNX on the X platform (formerly known as Twitter).It emerged recently that the claims trading platform has been eyeing the acquisition of failed crypto lender Hodlnaut, which is currently undergoing court-supervised restructuring in Singapore. Zhu and Davies have come in for a lot of criticism within the crypto sector, having left a long list of unpaid creditors as a consequence of the failure of 3AC. The duo recently suggested that they would contribute profits from OPNX to 3AC creditors despite the fact that they have been uncooperative with the 3AC bankruptcy process.

news
Loading