A white-hat hacker has returned 322 Ethereum (around $900,000) after an exploit drained Multichain users of more than $3 million worth of crypto this week.
Up to $1.5 million worth of Ethereum is still at large, however.
Multichain is a cross-chain router protocol that bridges users between thirty different blockchains, including Bitcoin, Ethereum, and Terra.
This week’s critical vulnerability appears to have affected six tokens on the protocol: Wrapped ETH (WETH), Peri Finance Token (PERI), Official Mars Token (OMT), Wrapped BNB (WBNB), Polygon (MATIC), and Avalanche (AVAX).
On Monday, Multichain announced on Twitter that the problem had been “reported and fixed.”
However, more attackers swooped in after the announcement and were still able to exploit the protocol through the same vulnerability, with one hacker stealing as much as $1.43 million.
1/A critical vulnerability that affected 6 tokens (WETH, PERI, OMT, WBNB, MATIC, AVAX) has been reported and fixed.
All assets on both V2 Bridge and V3 Router are safe, and cross-chain transactions can be done safely.
— Multichain (Previously Anyswap) (@MultichainOrg) January 17, 2022
The White Hat Multichain hacker
In the badlands of crypto, critical vulnerabilities aren’t just exploited by criminals for self-interested motives, they also draw the attention of blockchain vigilantes called “white hat” hackers, who exploit vulnerabilities to report them and collect a bounty.
One of the attackers that attacked Multichain after Monday’s announcement was a white hat.
The hacker returned 322 ETH (around $900,000) to an affected user and kept 62 ETH ($173k) as a bounty for themselves.
The hacker also returned 52 ETH ($139,000) to Multichain and kept around 12 ETH as a bounty.
Around 527 ETH, or just under $1.5 million, is still missing, however.
On Thursday, Multichain CEO and co-founder Zhaojun took to Twitter and confirmed ZenGo wallet co-founder Tal Be’ery’s theory that the vulnerability was due to the fact that Multichain’s bridge contracts need a pause function to prevent loss of funds in the future.
Elon Musk’s favorite cryptocurrency made a comeback at the end of last year as retail investors flooded back into the market to snap up Dogecoin. The coin was launched as a joke in 2013, but has persisted over the years and remained prominent.
But just how serious is the business of mining the O.G. meme coin? People are actively buying the machines to do so, according to vendors at this year’s Mining Disrupt conference in Fort Lauderdale, Florida.
Though the conference was heavily focused on th...
Banks can engage in cryptocurrency and other legally permitted activities without seeking prior regulatory approval, so long as they manage risks appropriately, The Federal Deposit Insurance Corporation announced Friday.
The policy change rescinds a 2022 requirement that mandated FDIC-supervised institutions notify the agency before engaging in crypto-related activities. Under the new guidance, banks can offer services involving digital assets without the agency's advance permission.
"With today...
The NASDAQ exchange has applied to the U.S. Securities and Exchange Commission to list shares of an Avalanche exchange-traded fund issued by crypto asset manager Grayscale.
The 19b-4 form for Grayscale's AVAX ETF follows its registration as a Delaware Trust entity more than two weeks ago.
If approved, the AVAX ETF would use Coinbase Custody as its custodian, the 19b-4 shows.
The issuer must still file an S-1 registration statement describing the product, however.
AVAX, the utility token of L...