Top

Suspected Malicious Activity Drains AnySwap Tokens via Multichain Executor

Web3 & Enterprise·July 13, 2023, 12:06 AM

According to an on-chain sleuth known as Spreek, a person is using the Multichain Executor to drain tokens associated with the AnySwap bridging protocol.

Multichain is a cross-chain routing network, established and maintained by a Chinese developer team. It supports in excess of 25 blockchains and more than 1,100 tokens.

Photo by Marek Piwnicki on Unsplash

 

$100 million outflow

This revelation comes after abnormal outflows of over $100 million from Multichain bridges on July 7, which were flagged by the Multichain team. Spreek’s report via Twitter on July 10 states that the Multichain Executor address has been draining anyToken addresses across multiple chains and transferring them to a new externally owned account (EOA).

Evidence provided in the report includes an Ethereum transaction, 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe, which called the “anySwapFeeTo” method on the Multichain Router: V4 contract. This transaction resulted in approximately $15,275.90 worth of anyDAI being minted on Ethereum, sent to the Multichain Executor, burned, and exchanged for the underlying DAI backing the asset.

The funds from these transactions were sent to the following address:0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Similarly, on the BNB Smart Chain (BSC), the Multichain Executor used the anySwapFeeTo function to convert $208,997 worth of anyUSDC into Binance-pegged USDC and sent them to the same address. Additionally, 50.80 anyBTC, equivalent to $39,251.43 at the time, was converted into Binance-pegged Bitcoin and sent to the address.

In total, approximately $263,524.33 worth of tokens were sent to this address through the anySwapFeeTo method. Spreek suggests that this behavior could be part of the protocol’s normal functioning. However, a different account engaged in similar activity the day before and ultimately sold the drained tokens, indicating malicious intent.

 

Potential exploit

Spreek theorizes that the attacker may be exploiting the anySwapFeeTo function by setting fees to an arbitrarily large amount, allowing them to drain users’ funds. The function apparently permits setting any value, enabling the address to choose the total value of the token held in that anyToken.

The Multichain incident has puzzled blockchain analysts, as it remains unclear whether it resulted from an exploit or if it was simply large token-holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s bridges and transferred to wallet addresses with no prior transactions. This represented the majority of funds held on each bridge.

 

Hack or rug pull

The Multichain team labeled these withdrawals as “abnormal” and advised users to stop using the protocol. However, they have not disclosed the source or nature of the anomaly. In response to the incident, stablecoin issuers Circle and Tether froze some of the addresses involved in the suspicious transactions. Chainanalysis, a blockchain analytics firm, has commented that the incident appears more like a hack or rug pull rather than a migration.

Adding to the complexity, the Multichain team has reported that their CEO is missing, and they have shut down certain bridges due to losing access to some of the network’s multi-party computation network servers. There have been various concerns relative to Multichain since May. The situation continues to evolve, with ongoing investigations and efforts to mitigate any potential damage caused by the suspected malicious activity.

More to Read
View All
Web3 & Enterprise·

May 04, 2023

Korean Crypto Firms Organize Consortium for Real-World Asset Tokens

Korean Crypto Firms Organize Consortium for Real-World Asset TokensElysia, a Korean decentralized autonomous organization (DAO) project, announced today that it organized a consortium to promote an ecosystem for real-world asset (RWA) tokens.Tangible assetsRWA tokens are virtual assets underpinned by tangible assets such as real estate properties and cars.The consortium comprises Neopin, a blockchain platform of Korean online game publisher Neowiz; Galaxia Metaverse, a blockchain subsidiary of Korean industrial conglomerate Hyosung Group; and BKEX Labs, a British Virgin Islands-based crypto investment firm. The companies will collaboratively research and develop a decentralized finance (DeFi) lending protocol supported by RWA tokens.Photo by Jessica Bryant on PexelsLending protocolsLending protocols based on physical assets offer better security and higher profitability compared to those based on unbacked virtual assets, which often experience high price volatility. As a DAO LLC approved by the state of Wyoming in the US, Elysia will leverage its RWA tokenization system to bolster security within the protocol and provide legal safeguards to investors.In addition, tokenized tangible assets are expected to offer small investors a chance to invest in markets that were previously out of reach due to the requirement of a significant amount of capital.According to Aju Business Daily, an Elysia official said that an RWA-based lending protocol would not only appeal to retail investors but also to institutions and projects. These entities are expected to park their excess funds and introduce RWA liquidity pools into their DeFi, the official added.Better liquidity of physical assetsElysia’s RWA tokens can be liquidated on its DeFi platform Elyfi. Users can create RWA tokens based on their tangible assets and visit Elyfi to sell those tokens or borrow virtual assets against them. Elysia aims to facilitate the liquidity of physical assets and offer a diverse range of financial services based on this model.

news
Markets·

Mar 06, 2024

Crypto boom drives $17.5B surge in demand deposit at Korean banks

Among various accounts within a bank, a demand deposit account is considered a “station” where people can temporarily store their money and easily withdraw it for future investments. These accounts are highly liquid, since users can deposit or withdraw funds at any time without having to pay a penalty to a bank.  Following the recent cryptocurrency boom, the five major banks in Korea – KB Kookmin Bank, Shinhan Bank, Hana Bank, Woori Bank and NH Nonghyup Bank – are seeing a significant influx of funds into their demand deposit accounts, according to local media outlet Money Today. This is partly attributed to an increasing number of youths who are seeking to invest in crypto assets, parking their money in these banks’ demand deposit accounts. Shinhan Bank and Nonghyup Bank have seen the highest increase in their deposits, owing to their affiliation with local crypto exchanges that have access to real-name accounts from these banks. Photo by André François McKenzie on UnsplashBTC’s surge attracting young investors to cryptoExperts say that these deposits could be potentially transferred to the crypto market by owners as Bitcoin’s value continues to climb. An insider from a crypto exchange noted that the bullish crypto market, spurred by the U.S. approval of spot bitcoin ETFs, is driving a number of young investors to turn to crypto investments, encouraging them to channel their deposits into buying crypto tokens.  Data from these five major banks shows their total demand deposits by the end of February exceeded KRW 614 trillion ($460 billion), seeing a month-over-month increase of about KRW 23.5 trillion. During the same period, the banks’ combined regular savings grew by KRW 23.6 trillion, while their combined installment savings saw a decrease of KRW 13.3 trillion. This came after the government-led savings product “Youth Hope Installment Savings” reached its maturity, which returns users their principal with relatively large interest gains.  Banks scrambling to attract crypto investors with new savings productsIn response to the potential decline in interest rates in the second half of this year, an increasing number of customers are seeking to put their money into savings products with an interest rate of as low as 3%, according to a banker. In a bid to attract more users, local banks are busy introducing new savings products.  KB Kookmin Bank launched a savings product offering a relatively high annual interest rate of up to 4%, and Shinhan Bank rolled out a savings product targeting youths with an annual interest rate of up to 3.85%.  Meanwhile, Kbank, an online-only bank, is deemed among the largest beneficiaries of the crypto boom, as the bank saw its average daily new customers triple compared to last year. Since 2020, Kbank has served as the provider of real-name accounts to Upbit, the leading crypto exchange in Korea.  Ha Joon-kyung, a professor at the Department of Economics at Hanyang University, said the sudden surge in demand deposits means that a significant portion of these funds will be invested in high-yielding but risky assets, including cryptocurrencies, stocks and real estate.  

news
Markets·

Dec 14, 2023

WEMIX comes in 9th in CoinMarketCap’s TVL chain ranking

WEMIX comes in 9th in CoinMarketCap’s TVL chain rankingSouth Korean gaming publisher Wemade’s layer 1 blockchain network WEMIX has ranked 9th in CoinMarketCap’s list of largest blockchains in crypto ranked by total value locked (TVL). TVL refers to the U.S. dollar value of assets locked or staked on a blockchain. It is a key indicator of liquidity as well as investor and developer participation in a blockchain ecosystem.Photo by GuerrillaBuzz on UnsplashWEMIX’s statsAs of this writing, WEMIX’s TVL is $555.4 million, outpacing 10th place-holder Cardano by over $100 million. Its market capitalization is $1.27 billion. Staking accounts for the largest share of WEMIX’s TVL, which implies a high level of on-chain activity and trust among users in the blockchain’s stability and potential for growth.Expansive ecosystemWEMIX is building a large-scale ecosystem centered on the WEMIX3.0 mainnet, which features popular platforms like the blockchain gaming platform WEMIX PLAY; decentralized autonomous organization (DAO) and NFT platform NILE; and decentralized finance (DeFi) platform WEMIX.Fi.The firm’s more recently developed platform is its joint omnichain network with Chainlink Labs dubbed the Unbound Networking & Accelerating Growth Initiative, or “unagi,” which will serve as an interoperable Web3 gaming platform linking multiple blockchains. It is expected to boost WEMIX’s growth into an even larger mega-ecosystem.

news
Loading