CCT - Crypto Currency Tracker logo CCT - Crypto Currency Tracker logo
NewsBTC 2023-07-12 00:00:28

Insider Job? Chainalysis Report Suggests Multichain Attacker Had Inside Connections

On July 6, 2023, the Multichain Protocol was hit by a massive hack, resulting in the loss of over $125 million worth of cryptocurrency. The attack targeted the protocol’s Fantom bridge, resulting in the theft of valuable crypto assets like WBTC, USDC, DAI, wETH, and Link. The stolen funds amounted to a staggering $126 million, with WBTC accounting for $30.9 million, wETH for $13.6 million, and USDC for $57 million. This exploit is one of the biggest crypto hacks on record. Multichain Attack And Insider Threats According to a recent report by the analysis and data company Chainalysis, the attack is suspected to be an inside job since Multichain has recently experienced some notable issues unrelated to its protocol design, prompting public suspicions that insiders may have carried out this recent exploit. The disappearance of Multichain’s CEO, who is known by the alias Zhaojun, and the subsequent suspension of services for more than 10 chains, including DynoChain, Redlight Chain, and Public Mint has added fuel to this suspicion. Related Reading: ConsenSys To Launch Linea, Its ZK-Rollup Network, On Main Ethereum Network Multichain’s smart contracts are secured by a multi-party computation (MPC) system, which functions similarly to a multi-signature wallet system. However, like multi-signature wallets, these systems are still vulnerable if an attacker possesses sufficient MPC keys. It is possible that the attacker gained control of Multichain’s MPC keys to pull off this exploit. Interestingly, the attacker did not swap out centrally controlled assets like USDC, which can be frozen by the issuing company (Circle, in the case of USDC), along with the addresses holding those assets. Most hackers typically seek to quickly swap funds for those not vulnerable to those security measures. In total, addresses frozen by Circle and Tether hold approximately $65 million in assets stolen from Multichain. What’s Next For The Protocol? After the attack, the Multichain team tweeted that they were beginning an investigation and urged users to pause transactions. A day later, on July 7, the team tweeted that the protocol would be stopping service indefinitely. Unfortunately, scammers also went on Twitter to spread a “phishing” link and impersonate the Fantom Foundation to trick affected users into claiming an “emergency FTM distribution.” Cross-chain bridge protocols have proven lucrative targets for hackers due to their experimental designs and the fact that they generally have large, centralized repositories of assets bridged by users to other blockchains. However, there may be several methods to mitigate risk and prevent similar exploits from occurring. According to Chainalysis, one way is through rigorous code audits to help developers standardize projects and investors evaluate protocol viability. While the Multichain hack appears to have resulted from compromised keys rather than faulty code, reputable audit reports often explicitly identify which parts of protocols are vulnerable to private key theft, which may help users better assess risk. Additionally, users of any protocol can research before they transact. Related Reading: Bitcoin And Crypto Investors Must Monitor The DXY: 6x Rally Ahead? The exploit suffered has left the blockchain community on edge, with many waiting for an official statement from the Multichain team. The team has not made any public pronouncements on the matter, leaving users and investors in the dark about the protocol’s future. Multichain’s native token, MULTI, has experienced a significant decline over the past 7 days, with a drop of over 27% in this timeframe. Currently, the token is trading at $2.387, representing a further decline of 3% in the last 24 hours. Featured image from Unsplash, chart from TradingView.com

면책 조항 읽기 : 본 웹 사이트, 하이퍼 링크 사이트, 관련 응용 프로그램, 포럼, 블로그, 소셜 미디어 계정 및 기타 플랫폼 (이하 "사이트")에 제공된 모든 콘텐츠는 제 3 자 출처에서 구입 한 일반적인 정보 용입니다. 우리는 정확성과 업데이트 성을 포함하여 우리의 콘텐츠와 관련하여 어떠한 종류의 보증도하지 않습니다. 우리가 제공하는 컨텐츠의 어떤 부분도 금융 조언, 법률 자문 또는 기타 용도에 대한 귀하의 특정 신뢰를위한 다른 형태의 조언을 구성하지 않습니다. 당사 콘텐츠의 사용 또는 의존은 전적으로 귀하의 책임과 재량에 달려 있습니다. 당신은 그들에게 의존하기 전에 우리 자신의 연구를 수행하고, 검토하고, 분석하고, 검증해야합니다. 거래는 큰 손실로 이어질 수있는 매우 위험한 활동이므로 결정을 내리기 전에 재무 고문에게 문의하십시오. 본 사이트의 어떠한 콘텐츠도 모집 또는 제공을 목적으로하지 않습니다.