Telegram (AI) YouTube Facebook X
Ру
The amount stolen from Multichain users has reached $3 million

The amount stolen from Multichain users has reached $3 million

Unknown actors continue to exploit a vulnerability in the Multichain cross-chain protocol, which developers disclosed earlier in the week. According to Tal Be’ery, the chief technology officer of the ZenGo crypto wallet, hackers have already withdrawn around $3 million in digital assets.

On Monday, January 17, the Multichain team reported a vulnerability affecting six tokens: WETH, PERI, OMT, WBNB, MATIC and AVAX. The next day PeckShield analysts said that unknown actors exploited the exploit and withdrew more than 450 ETH (about $1.4 million at the price at the time).

Later the protocol developers said the incident affected 445 users. Representatives of the project urged following the published instructions to keep funds safe.

Be’ery noted that one of the attackers’ victims lost about $960,000. The victim left an Ethereum blockchain entry requesting the return of the cryptocurrency for a reward.

The hacker accepted the offer and returned the assets in exchange for 50 ETH (about $157,200).

«Прежде всего, спасибо, что вы получили WETH. Я не знал о взломе и осознал ситуацию только потому, что WETH так и не поступили в мой кошелек после транзакции на CowSwap. Учитывая стоящую на кону сумму, приняли бы вы 50 ETH в качестве справедливых чаевых?», — написал пользователь в обращении к хакеру.

Be’ery noted that the Multichain developers also contacted the attackers. He pointed out that they contacted the адресом, on which 445 ETH of the stolen funds were stored, and offered a bounty for the discovered exploit.

Meanwhile PeckShield reported another Multichain vulnerability affecting cross-chain bridge liquidity providers. The firm noted that the developers used an administrator key to move funds out of the affected contracts.

The project’s community criticized the team for providing ambiguous information about the incident and for insufficient user support. The Multichain Twitter account disabled the ability to comment on posts.

In a discussion with Vice, the Multichain Telegram channel administrator going by the nickname Marcel said the team is taking certain steps, though not publicly announcing them.

Back in December 2021, Multichain attracted $60 million from Binance Labs, Circle Ventures and the Tron Foundation.

Subscribe to ForkLog news on VK.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK