Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

Nov 27, 2023

Metabora Singapore officially launches blockchain-based app for golf fans

Metabora Singapore officially launches blockchain-based app for golf fansMetabora Singapore, a subsidiary of South Korean blockchain game developer Metabora formerly known as Kakao Friends Games, has officially launched BirdieSquad, a blockchain-based community platform for fans of professional golfers in the Korea Ladies Professional Golf Association (KLPGA). This comes after the beta version that was launched in August quickly gained popularity, topping the ranks of sports-related apps.Photo by Splash Pic on UnsplashRevolutionizing the golf fandomBirdieSquad was developed by Kakao VX, the digital sports arm of Korean internet juggernaut Kakao, with the goal of creating an innovative and fun playground for golf fans to interact and create a fandom-based community. Users can own NFTs of their favorite golfers — which come in six tiers: Uncommon, Rare, Super Rare, Epic and Legendary — which are stored in personal wallets, and earn various rewards based on players’ actual performance results. They can also interact with other users and compete in “cheer-offs”. During off-seasons, Metabora plans to host various events such as AI-based championship tournaments.The platform is currently working with 46 professional golfers, including Han Jin-seon, Park Hyun-kyung, Lee Ye-won and Kim Min-byul. The platform said that it would bring more athletes in the future.“As we strive to create a new fandom culture where pro golfers and fans can interact, we will expand our ecosystem by onboarding various entertainment content revolving around gaming and sports,” said Lim Young-joon, Chief Business Officer of Metabora Singapore.Expanding partnershipsMeanwhile, the company has been expanding its partnerships with various global blockchain networks such as Polygon, NEAR Protocol, Ethereum and BNB Chain to expand its global ecosystem.

news
Web3 & Enterprise·

Aug 04, 2023

Dunamu Helps Adolescents Tell the Difference between Blockchain and Bitcoin

Dunamu Helps Adolescents Tell the Difference between Blockchain and BitcoinDunamu, the fintech company operating South Korea’s leading crypto exchange Upbit, announced on Thursday that its digital finance education program designed to help foster talent in digital finance amidst the current era of digitization and fintech has come to an end.Photo by Element5 Digital on UnsplashEmpowering digital finance literacy for the future generationDubbed “Duniverse” — a portmanteau of Dunamu and universe — the program was held from May to July for 4,100 middle school students throughout Seoul, Gyeonggi Province, and Incheon. The curriculum proved to enhance their understanding and literacy in digital finance.“Digital finance education for adolescents is essential in addressing various social issues, such as preventing financial accidents and income polarization,” said Lee Sirgoo, CEO of Dunamu.The first Duniverse program was held last year, hosting some 4,800 middle school students in vulnerable areas of Gyeonggi Province. Owing to the positive response, this year’s pool has been expanded to over 7,000 first-year middle school students in Seoul, Gyeonggi Province, and Incheon. In the first half of this year alone, a total of 4,120 students from 17 middle schools participated.The program featured lessons on the technologies of the Fourth Industrial Revolution, such as blockchain, NFTs, and metaverse, as well as basic financial knowledge. A total of eight sessions were led by a team of qualified instructors with years of experience in economic education. Dunamu employees also directly contributed to the review process of educational materials, the company said.Success recognized by students and teachers alikeIn a survey conducted by Dunamu targeting 435 participants, 93.1 percent of them expressed high satisfaction, stating that their understanding of digital finance improved. This portrays a meaningful upgrade from the answers of a previous survey conducted before the start of the program, where six out of ten respondents said that they had little knowledge about digital finance.They also reported that they now understand the difference between digital asset ownership and copyrights as well as blockchain and Bitcoin, and show interest when coming across digital finance-related content in the media.School teachers also praised the program for addressing blind spots in financial education and taking a proactive learning approach. “The students were able to learn about big data, ChatGPT, and more, which is especially valuable since such education for teenagers is still lacking. I believe it will help boost their competitiveness in the future job market,” said a teacher from Goam Middle School in Yangju, Gyeonggi Province.The teachers also approved of other topics that were covered, such as financial fraud prevention, to help teenagers avoid falling victim to financial scams. Suggestions were also made to expand teacher training courses.Upcoming programThis year’s second Duniverse program will be held from August to December for 2,712 middle school students in Seoul, Gyeonggi Province, and Incheon.Dunamu has continually devoted efforts to boosting social welfare and nurturing young talent. This includes “Dunamu Next Steppers,” a hope fund for young people with multiple debts, along with supporting emerging talents and artists with developmental disabilities in their participation in NFT projects.

news
Policy & Regulation·

Apr 10, 2023

Korea’s Internet Agency Encourages More Blockchain Tech Adoption to Overcome Crypto Winter

Korea’s Internet Agency Encourages More Blockchain Tech Adoption to Overcome Crypto WinterVirtual asset and blockchain technology needs to be more broadly adopted to overcome crypto winter, an official from the Korea Internet and Security Agency (KISA) said at the 2023 Blockchain Meetup Conference on Wednesday.©Pexels/Helena LopesUser-friendly apps and regulatory supportPark Sang-hwan, the leader of the blockchain technology promotion group at KISA, encouraged the blockchain industry to develop user-friendly applications to give positive impressions, adding that blockchain-based apps should be faster and efficient to meet users’ expectations.He also said the blockchain industry needs regulatory support, explaining that regulatory issues can hinder the growth of the industry’s growth.KISA’s support for blockchain industryAccording to Park, the quasi-government internet agency introduced a business quality control system to offer advice on legal, technological, and business issues to companies, as well as to provide them with business problem-solving support. KISA will continue driving the development of key blockchain technologies, create new business plans for Web 3.0, and devise a mid- to long-term roadmap for research and development, he said.Blockchain projects in KoreaDuring his speech at the conference, Park presented several KISA-led public sector projects that will unfold this year, as reported by the Korean economics newspaper Hankyung. They include blockchain-based online voting systems, the establishment of digitally formed national licenses, and the verification of personal identification.Endeavors in the private sector were also revealed, including NFT-based concert tickets, oil waste disposal systems, and identification using soulbound tokens.

news
Loading