简体中文
繁體中文
English
Pусский
日本語
ภาษาไทย
Tiếng Việt
Bahasa Indonesia
Español
हिन्दी
Filippiiniläinen
Français
Deutsch
Português
Türkçe
한국어
العربية
Abstract:Owing to a security vulnerability in six tokens, Multichain users lost more than $3M over the week. A white hat hacker returned 322 ETH, but in excess of 527 ETH is still exploited.
Owing to a security vulnerability in six tokens, Multichain users lost more than $3M over the week. A white hat hacker returned 322 ETH, but in excess of 527 ETH is still exploited.
In a dramatic twist, one of this weeks Multichain hackers has returned 322 ETH ($974,000 at the time of writing) to the cross-chain router protocol and one of the affected users.
However the hacker kept 62 ETH ($187,000) as a “bug bounty”, and a total of 528 ETH (worth $1.6M) remains outstanding after the exploits.
Earlier this week, news emerged of a security vulnerability with Multichain relating to the tokens WETH, PERI, OMT, WBNB, MATIC, and AVAX, and $1.43 million was stolen. Multichain announced on Jan. 17 the critical vulnerability had been “reported and fixed.”
However, publicity about the vulnerability reportedly encouraged a number of different attackers to swoop in, and more than $3 million in funds were stolen. The critical vulnerability in the six tokens still exists, but Multichain has drained around $44.5m of funds from multiple chain bridges to protect them.
One of the hackers, calling himself a “white hat” has been in communication with both Multichain and a user who lost $960,000 in the past day or so, to negotiate returning 80% of the money in return for a hefty finders fee.
According to a Jan. 20 tweet from ZenGo wallet co-founder Tal Beery, the hacker claimed they hadbeen “saving the rest” of the Multichain users who were being targeted by bots, in an act of defensive hacking.
The funds were returned across four transactions. On Jan. 20 the hacker returned 269 ETH ($813,000) in two transactions directly to the user he stole it from and kept a bug bounty of 50 ETH ($150,000).
The relieved user responded to the hacker:
Well received, thank you for your honesty.
Overnight, the hacker also returned 50 ETH ($150,000) across two transactions to the official Multichain address, and kept a bug bounty of 12 ETH ($36,000).
Multichain (formerly Anyswap) aims to be the “ultimate router for Web3.” The platform supports 30 chains at the moment, including Bitcoin (BTC), Ethereum (ETH), Avalanche (AVAX), Litecoin (LTC), Terra (LUNA), and Fantom (FTM).
In a tweet on Jan. 20, the Co-Founder and CEO of Multichain Zhaojun conceded that Multichain bridge contracts need a pause function to deal with similar incidents in future.
Cointelegraph has contacted the project for comment.
Disclaimer:
The views in this article only represent the author's personal views, and do not constitute investment advice on this platform. This platform does not guarantee the accuracy, completeness and timeliness of the information in the article, and will not be liable for any loss caused by the use of or reliance on the information in the article.
This article outlines the history of Ponzi schemes, highlighting the infamous Charles Ponzi, Bernie Madoff, and beyond.
The forex market presents both opportunities and challenges, with technical analysis being crucial for successful trading. This article outlines the five essential steps for mastering Forex MT4 technical analysis: identifying trends, utilizing technical indicators, determining entry and stop-loss points, analyzing price charts, and performing real-time monitoring and adjustments. By following these steps, traders can enhance their understanding and application of technical analysis, ultimately improving their trading accuracy and success rate.
Wednesday's major data releases and macroeconomic events are expected to cause volatility to increase after another day of erratic trading in the financial markets. The Spring Budget for the UK will be released, and January Retail Sales figures for January will be made available by Eurostat. ADP Employment Change for February and January JOLTS Job Openings will be discussed later in the session on the US economic docket.
Major currency pairings are still trading in familiar ranges early on Tuesday after the erratic trading on Monday. The US economic docket for the American session will include the factory orders data for January and the ISM Services PMI survey for February. Final updates to the February PMI for the US, Germany, the UK, and the EU will also be released by S&P.