Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Policy & Regulation·

Sep 19, 2023

JPEX Exchange Scandal Sees Crypto Regulation Under Scrutiny in Hong Kong

JPEX Exchange Scandal Sees Crypto Regulation Under Scrutiny in Hong KongWhile Hong Kong has been developing steadily as a crypto sector hub, the focus in the Chinese autonomous territory has turned towards regulation after a recent scandal involving an unlicensed cryptocurrency exchange.Photo by Ihor Saveliev on UnsplashOngoing investigationYesterday we reported on some arrests relative to problems experienced at crypto exchange JPEX. The fallout continues on Tuesday, with the Hong Kong police now understood to have arrested eight individuals, including social media influencers who promoted the exchange and JPEX employees, on allegations of fraud. This illicit activity in and around the JPEX exchange has affected over 1,600 investors, implicating more than $150 million in assets.JPEX, in response to mounting pressure, announced the suspension of trading on its platform. In a statement, the exchange mentioned ongoing negotiations with third-party market makers to address liquidity shortages. However, JPEX also accused an unidentified third-party market maker of maliciously freezing funds, further complicating the situation.Politicians and regulators speak outResponding to the incident via a press conference on Tuesday, Hong Kong’s Chief Executive, John Lee, emphasized the significance of investing in virtual assets through licensed platforms. Lee stated:“This incident highlights the importance that when investors want to invest in virtual assets, then they must invest on platforms that are licensed.” He also pledged that the Securities and Futures Commission (SFC) would closely monitor the situation to ensure investor protection.Elizabeth Wong, the Head of the SFC’s fintech unit, revealed that an investigation was underway to determine whether JPEX had violated anti-money laundering laws. The SFC had already declared JPEX unlicensed, prompting numerous complaints from investors who were unable to withdraw their virtual assets or experienced unexplained reductions in their balances.Assets frozenHong Kong authorities have taken decisive action against those involved in the scandal. They have frozen bank accounts valued at 15 million Hong Kong dollars ($1 million) and seized three properties valued at 44 million Hong Kong dollars. The police have reported receiving 1,641 complaints related to JPEX, involving a staggering $1.2 billion Hong Kong dollars. By last Wednesday, the SFC had received in excess of 1,000 complaints and at that point, they notified the general public.The JPEX scandal has drawn attention to the need for stronger cryptocurrency regulations in Hong Kong, a region that has become attractive to cryptocurrency firms since mainland China banned cryptocurrency transactions in 2021. In mainland China, trading cryptocurrencies on foreign exchanges from within the country remains illegal.Hong Kong’s response to cryptocurrency regulation has evolved. Beginning on June 1, the SFC started accepting applications from cryptocurrency exchanges, allowing licensed operators to serve retail investors, provided they understand the associated risks. Previously, only professional investors had access to such exchanges. Currently, only two exchanges in Hong Kong, OSL Exchange and Hashkey Exchange, have received approval to operate.As Hong Kong reevaluates its approach to cryptocurrency regulation, the crypto sector will hope that it strikes a balance between fostering innovation and protecting investors from fraud and market manipulation.

news
Web3 & Enterprise·

Apr 22, 2025

XRP primed for institutional adoption in Asia via tracker fund launch

XRP, the native asset of the XRP Ledger (XRPL), a blockchain network developed by Ripple Labs, is destined for further institutional adoption in Asia due to the launch of the region’s first XRP tracker fund. Crypto-focused institutional asset manager HashKey Capital recently announced the launch of its HashKey XRP Tracker Fund, which has been devised to track the performance of what is the world’s fourth-largest crypto asset by market cap, after Bitcoin (BTC), Ether (ETH) and U.S. dollar stablecoin Tether (USDT).Photo by Kanchanara on UnsplashEnabling institutional accessThe fund enables investors to gain exposure to XRP without having to take direct ownership and custody of the digital asset. Bitcoin and Ethereum exchange-traded funds (ETFs) have become popular in a number of markets, including the United States, as they allow institutional investors to gain exposure to these digital assets where they may have been uncomfortable with direct ownership due to concerns around custody and counterparty risk or regulatory concerns. According to HashKey’s press release, investors can buy into the fund through cash or in-kind subscription and subscribe or redeem shares monthly. The fund will be measured and compared against a benchmark index provided by CF Benchmarks, a provider of crypto-related indices. HashKey Partner Vivien Wong acknowledged the potential that XRP has in the market, stating:“XRP stands out as one of the most innovative cryptocurrencies in today’s market, attracting global enterprises who use it to transact, tokenize, and store value.”She added that the new fund simplifies access to XRP within the region, while catering to a growing demand for investment opportunities related to digital assets.Potential ETF fund conversionThis marks HashKey’s third product that tracks digital asset pricing, with the company having launched both Bitcoin and Ethereum exchange-traded funds (ETFs) previously. On X, HashKey Capital outlined that the XRP Tracker Fund could potentially evolve into a fully fledged ETF, subject to regulatory approval, within the next 1-2 years. The new fund, which was launched on April 18, also incorporates a strategic partnership with XRP developer Ripple Labs. In what is understood to be the first of a number of collaborations, Ripple will fulfill the role of being the fund’s anchor investor. Ripple’s Managing Director for the Asia-Pacific (APAC) region, Fiona Murray, cited the development as proof that institutional adoption of digital assets continues to go from strength to strength.  Ripple CEO Brad Garlinghouse stated last month that he expects a number of spot XRP ETFs to be approved in the United States later this year. Earlier in March, analysts at American investment bank JPMorgan had estimated that spot XRP ETF approval in the U.S. could result in net inflows of $8 billion into such products.At the time of writing, XRP was trading at $2.09. The asset has increased in price by 300% over the course of the past 12 months, largely due to a changing regulatory environment in the United States and optimism that a settlement can be reached to end its multi-year legal battle with the Securities and Exchange Commission (SEC).

news
Policy & Regulation·

Jun 19, 2023

Korea’s Busan City to Develop Blockchain-Based Carbon Neutrality Platform

Korea’s Busan City to Develop Blockchain-Based Carbon Neutrality PlatformBusan Metropolitan City, known for being home to South Korea’s largest port, announced today that its consortium won the bid for the 2023 new local energy facilitation project offered by the Korea Energy Agency, an organization under the Ministry of Trade, Industry, and Energy (MOTIE). The consortium consists of five entities, including Busan City, tech solution provider Nuri Flex, and gas distributor Busan City Gas. As the winning bidder, Busan City and its collaborators will proceed with the development of a blockchain-based platform that promotes carbon neutrality.Photo by BERK OZDEMIR on PexelsCarbon neutralityThe primary aim of this project is to create a system that leverages surplus renewable energy to achieve carbon neutrality in the city’s port and industrial infrastructure. The initiative includes providing eco-friendly renewable energy to port and industrial facilities, establishing a blockchain-based carbon credit system to support businesses in joining the global corporate renewable energy initiative RE100, and facilitating the trading of surplus electricity. These measures are intended to save energy, enhance power system stability, and create greater value.Boosting green energy proportionThe project is set to take place from June 2023 to December 2024, with an estimated cost of 3 billion KRW ($2.3 million). The national and local governments will each finance 25% of the project, while the private sector will cover the remaining 50%. Upon completion of the project, Busan aims to increase the proportion of renewable energy within the city. Leveraging surplus energy and engaging in carbon credit trading, Busan expects to gain a competitive edge in the carbon-neutral sector.

news
Loading