CertiK, zkSync to launch compensation plan for $2M Merlin DEX exploit

Share This Post

The Web3 security firm urges the rogue developer to return 80% of the stolen funds and offers 20% as a white hat bounty.

Blockchain security firm CertiK is launching a compensation plan with Ethereum layer-2 scaling platform zkSync Era to cover the $2 million lost during a public sale of decentralized exchange Merlin’s MAGE tokens.

In a statement to Cointelegraph on April 26, CertiK reiterated it is investigating the exit scam and has also enlisted the remaining Merlin team to initiate the compensation plan. It said:

“Initial investigations indicate that the rogue developers are based in Europe, and CertiK will collaborate with law enforcement authorities to track them down if direct negotiation is unsuccessful.”

The blockchain security company is urging the rogue developer to return 80% of the stolen funds, conceding 20% as a white hat bounty.

The firm also pointed out that private key privileges are “committed to assisting impacted users” despite them being outside the scope of a smart contract audit.

Merlin lost about $850,000 worth of USD Coin (USDC) and some more relatively illiquid tokens on April 26 during its three-day MAGE tokens public sale without any hard cap. Blockchain data suggests that an exploiter with control over the liquidity pool was able to easily siphon the funds.

CertiK, which audited Merlin’s code, responded with its initial findings pointing to a “potential private key management issue.”

Crypto Twitter questioned the CertiK audit, implying that there might be a rug pull.

Verichains founder Thanh Nguyen alluded to a “backdoor” present in Merlin’s code, saying it is a “clear security risk as there is no use case that requires its approval.”

“While audits can identify potential risks and vulnerabilities, they cannot prevent malicious activities on the part of rogue developers such as rug pulls,” CertiK in a statement to Cointelegraph. “We encourage users to look for projects with a ‘KYC Badge’ as an added layer of security, signifying that the project has voluntarily gone through a KYC vetting process.”

Related: Ordinals Finance has conducted a $1M rug pull: CertiK

The firm explained that doing so can help reduce and mitigate the risk of insider threats such as rug pulls.

CertiK said it would continue providing updates on its compensation plan and ongoing investigation.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Trump-linked DeFi venture could double Aave’s treasury overnight with $100M boost

Former President Donald Trump‘s World Liberty Financial (WLF) DeFi project may add over $100 million in revenue to Aave DAO’s treasury if the lending protocol approves a pending proposal

DOGE Price Analysis: Double-Bottom Hints at Explosive Gains!

The post DOGE Price Analysis: Double-Bottom Hints at Explosive Gains! appeared first on Coinpedia Fintech News The crypto space turns volatile amid the US consumer price increase in September Amid

Uniswap Labs Introduces Scalability-Focused Ethereum L2

Uniswap Labs has announced Unichain, its Ethereum Layer-2 solution aimed at streamlining the user experience for those leveraging its services The organization specified that Unichain would be built

Dogecoin Targets $0.11 As Short-Term Traders Fuel DOGE Price – Details

Dogecoin is now at a crucial demand level after a 4% rise from local lows, stirring serious speculation in the market The meme coin has caught the attention of analysts and traders, with mixed

Bitcoin must again show resilience around recurring resistance at $61,000

Over the past week, Bitcoin’s price has exhibited a pattern of sharp upward moves followed by strong pullbacks, particularly in the higher white channels (above $63,000) and the red channels

Californian Investor Sues Olympus Peak Over FTX Deal, Alleges Millions Lost

The post Californian Investor Sues Olympus Peak Over FTX Deal, Alleges Millions Lost appeared first on Coinpedia Fintech News A lawsuit has been filed against popular hedge fund Olympus Peak by a