Top

Singapore’s UniPass Plays Role in ERC-4337 Vulnerability Fix

Policy & Regulation·October 28, 2023, 1:31 AM

Smart contract wallet provider UniPass and crypto infrastructure firm Fireblocks have successfully addressed a significant vulnerability in the Ethereum ecosystem.

Photo by Nenad Novaković on Unsplash

 

Account abstraction vulnerability

This vulnerability, identified as the ERC-4337 account abstraction vulnerability, posed a critical security risk to hundreds of mainnet wallets. The joint effort between Fireblocks and UniPass was detailed in a blog post published to the Fireblocks website on Thursday.

This vulnerability, if exploited, could have enabled a malicious actor to execute a complete takeover of the UniPass Wallet by manipulating Ethereum’s account abstraction process. The vulnerability represented a substantial threat to the security of smart contract wallets, as it could lead to unauthorized access and fund drainage.

 

Improving user experience

Account abstraction, as dealt with via ERC-4337, is a mechanism that introduces a novel way of processing transactions and interacting with smart contracts on the Ethereum blockchain. It allows for a more flexible and efficient handling of transactions, transcending the traditional distinction between externally owned accounts (EOAs) and contract accounts.

EOAs are controlled by private keys and can initiate transactions, while contract accounts are governed by the code of a smart contract. When an EOA initiates a transaction with a contract account, it triggers the execution of the contract’s code. Account abstraction introduces the notion of abstracted accounts, which are not tied to a specific private key and can initiate transactions and interact with smart contracts, similar to EOAs.

In the context of ERC-4337, an account executing an action relies on the EntryPoint contract to ensure that only signed transactions are executed. Typically, these accounts trust a single audited EntryPoint contract to validate user operations before executing commands. However, the vulnerability resided in the fact that a malicious or buggy EntryPoint contract could potentially skip the validation step and directly call the execution function, bypassing essential security measures.

This vulnerability, identified by the two firms, had allowed attackers to seize control of UniPass wallets by replacing the trusted EntryPoint of the wallet. Once this takeover was completed, the attacker could access the wallet and drain its funds.

It’s worth noting that the vulnerability posed a threat to several hundred users who had activated the ERC-4337 module in their wallets, making them susceptible to exploitation by any actor on the blockchain. Fortunately, the wallets affected by this vulnerability contained only small amounts of funds, and swift mitigation efforts were successful in preventing further harm.

 

Company merger

Earlier this year, Singapore’s UniPass merged with Chinese wallet provider Keystone to form Account Labs, a company which has been incorporated in Singapore. At the time, Keystone founder Liu Lixin outlined that further developing account abstraction-derived products was the objective of the creation of Account Labs. He stated:

“We are on the cusp of a Web3 Account Abstraction revolution. Together, we’ll drive rapid transformation, making the transition from Web2 to Web3 effortless for users. Our goal is to ensure everyone can securely and smoothly manage a decentralized account. We welcome partners to join us in advancing the Web3 account domain.”

In furthering that objective, Account Labs announced on Thursday that it had raised $7.7 million in a funding round led by Amber Group, MixMarvel DAO Ventures, and Qiming Ventures.

More to Read
View All
Web3 & Enterprise·

Oct 02, 2023

Coinbase Acquires License to Enhance Crypto Operations in Singapore

Coinbase Acquires License to Enhance Crypto Operations in SingaporeUS crypto exchange business Coinbase has reached a significant milestone in its Singapore operations by obtaining a Major Payment Institution (MPI) license from the Monetary Authority of Singapore (MAS).The achievement, announced by the firm via a blog post published on Sunday, represents a pivotal moment for Coinbase as it expands its digital payment token services in Singapore to serve both individuals and institutions. The issuance of the full MPI license comes approximately one year after Coinbase initially received in-principle approval from MAS.Photo by Duy Nguyen on UnsplashEnabling broader service offeringThe importance of this development lies in Coinbase’s ability to provide advanced services, not only to individual traders but also to institutional investors. Hassan Ahmed, the country director of Coinbase Singapore, stressed the significance of this full license, stating that it will play a crucial role in strengthening relationships with stakeholders, especially regulated entities like banks. The regulatory milestone is anticipated to further cement Coinbase’s presence in the institutional finance sector in the region.Coinbase’s commitment to the Singaporean market has been evident in its continuous expansion initiatives. The company established a technology hub in Singapore last year, actively recruiting and training product managers and engineers specializing in Web3 technologies.In May the firm extended its product offering to Singaporean customers, introducing fee-less purchases of the USDC stablecoin and introducing digital asset staking. Meanwhile Coinbase Ventures, the firm’s investment arm, has also demonstrated confidence in the region by investing in more than 15 Web3 startups within Singapore over the past three years.Singapore earmarked for growthSingapore has emerged as the focal point for Coinbase’s Asia-Pacific institutional business, owing to its progressive stance on cryptocurrencies and a robust Web3 ecosystem boasting over 700 Web3 companies. According to Coinbase’s surveys, 25% of Singaporeans perceive cryptocurrencies as the future of finance, and 32% have had some form of crypto asset ownership. These statistics underscore Singapore’s growing importance in the global cryptocurrency landscape.Coinbase’s interest in meeting the demands of the local market is evident with the introduction of funding options like PayNow and the banks’ Fast And Secure Transfers (FAST) service, in addition to the integration of the Singpass onboarding system earlier this year.Despite facing regulatory challenges, including a lawsuit from the US Securities and Exchange Commission (SEC) accusing Coinbase of operating illegally, the exchange continues to explore avenues to grow and expand the business further. In August, Coinbase reported a significant improvement in its financials, with a narrower net loss and higher-than-expected revenue. This performance is reflected in its appreciating stock prices, which have more than doubled in 2023.This move places Coinbase among a select group of just over a dozen firms licensed to offer digital payment token services in Singapore. Last month, institutional investor-focused AsiaNext was officially designated as a Recognized Market Operator (RMO) by MAS. The firm was building on previous success in Singapore, having acquired a Capital Markets Services (CMS) license from MAS in June.That same month USDC stablecoin issuer Circle was awarded a full trading license. Other crypto firms to achieve licensing success in the city-state include Crypto.com and Blockchain.com.

news
Policy & Regulation·

Jan 12, 2024

South Korean FSC prohibits domestic securities firms from brokering spot bitcoin ETF

The South Korean Financial Services Commission (FSC) made an official announcement on Friday (KST) stating that "domestic securities firms brokering spot bitcoin ETFs that are listed on overseas markets may be considered a violation of the government's stance on virtual assets and the Financial Investment Services and Capital Markets Act." This stance refers to a press release published on Dec. 13, 2017 that outlined the government’s conclusion that virtual assets must be dealt with carefully.Photo by Lauren Seo on UnsplashFuture possibilityHowever, this statement is not to be interpreted as a complete dismissal of the possibility that South Korea could adopt the ETF. The agency added that it would look into the issue thanks to a more stable regulatory landscape sweeping the country following the implementation of regulations on virtual assets like the Virtual Asset User Protection Act. Authorities are also taking into consideration the fact that other countries like the U.S. are adopting a more open stance. Market downturnFollowing the announcement, stocks related to the ETF in the South Korean market – which had surged on the news of a spot bitcoin ETF listing on the U.S. stock market a day ago – saw share prices drop within a day. As of 10:04 a.m. on Friday, Woori Technology Investment was trading at KRW 7,650 ($5.82), down 4.61 percent from the day before, and Hanwha Investment & Securities was down 9.09 percent to KRW 4,000. Both of these firms hold stakes in Dunamu, the operator of South Korea's largest cryptocurrency exchange Upbit.

news
Web3 & Enterprise·

Jan 24, 2024

OKX and HashKey plan partnership to promote industry development

HashKey Group, the Hong Kong-based regulated cryptocurrency exchange, is planning a partnership with crypto derivatives platform OKX.Photo by Ivan Lau on UnsplashAdvancing innovation and growthThe duo announced their plans via a press release which was published on Tuesday. The objective of the partnership is aimed at advancing compliant virtual asset innovation and industry growth in Hong Kong. The collaboration between HashKey Group and OKX capitalizes on the strengths and resources of both entities to elevate services and experiences. Harnessing these strengths the pair intend to contribute towards Hong Kong's emergence as a hub for the regulated virtual asset industry. The partnership will encompass various industry initiatives, including blockchain infrastructure development, product diversification and virtual asset investment education within the region. First regulated exchangeNotably, HashKey Group achieved a significant milestone last year by becoming the first Hong Kong Securities and Futures Commission (SFC)-regulated crypto exchange authorized to serve retail users. The firm secured Type 1 and Type 7 licenses from the SFC, in line with the  "compliance first” approach the company is taking. Founded in 2018 and headquartered in Hong Kong, with operations in Singapore and Tokyo, HashKey Group caters to a diverse clientele, including retail investors, institutions, family offices, funds and professional investors. The services offered by the company encompass a Hong Kong SFC-regulated virtual asset exchange, global asset management and wealth management, with a focus on blockchain and digital assets, blockchain node validation, tokenization and Web3 incubation and community operations. Its Singaporean subsidiary, digital asset fund manager HashKey Capital, secured a regulatory license from the Monetary Authority of Singapore (MAS) in December. Unicorn statusOKX Ventures, the investment division of OKX, played a crucial role in supporting HashKey's Series A financing. That Series A funding round saw HashKey achieve unicorn status with a $1.2 billion valuation earlier this month. OKX Ventures focuses on investing in projects that nurture sustainable growth within the global virtual asset ecosystem. OKX, already serving over 50 million users worldwide, has a notable presence with sponsorships that include Manchester City FC in the English Premier League (EPL) and the McLaren Formula 1 racing team. Earlier this month, the company expanded its sponsorship with McLaren. The digital asset exchange began onboarding customers in Hong Kong a month before officially launching operations there, aligning with the city's new virtual asset service providers (VASPs) regime implemented on June 1 of last year. In March 2023, OKX established a Hong Kong entity to launch virtual asset services, with plans to apply for the virtual asset service provider (VASP) license and Type 1 & 7 licenses under the Securities and Futures Ordinance. Approval is anticipated by early 2024. The collaborative effort between HashKey Group and OKX marks a significant stride in advancing compliant virtual asset innovations in Hong Kong. This partnership aims to enhance service offerings and customer experiences, further solidifying Hong Kong's position as a regulated virtual asset industry hub. By leveraging their respective strengths, these industry leaders are well placed to assist in elevating Hong Kong's standing in the global virtual asset landscape, fostering growth and compliance in this rapidly evolving sector.  

news
Loading