Multichain Executor has been ‘draining’ AnySwap tokens: Report

Share This Post

The contract has used an “anySwapFeeTo” function to transfer hundreds of thousands of dollars worth of tokens to itself, which on-chain sleuth Spreek suspected may have been malicious.

A person is using the Multichain Executor to “drain” tokens associated with the AnySwap bridging protocol, according to a July 10 report from on-chain sleuth and Twitter user Spreek. The report follows previous outflows of over $100 million from Multichain bridges that occurred on July 7, which were reported by the Multichain team as “abnormal.”

According to Spreek’s July 10 report, “The Multichain Executor address has been draining anyToken addresses across many chains today and moving them all to a new EOA [externally owned account].”

An image attached to the post shows Ethereum transaction 0x53ede4462d90978b992b0a88727de19afe4e96f0374aa1a221b8ff65fda5a6fe. Blockchain data reveals that this transaction called the “anySwapFeeTo” method on the Multichain Router: V4 contract, causing approximately $15,275.90 worth of anyDAI to be minted on Ethereum and sent to the Multichain Executor, who then burned it and exchanged it for the underlying DAI stablecoin backing the asset. 

DAI conversion by Multichain Executor. Source: Blockchain data

In a separate comment, Spreek said the funds are being sent to the following address: 0x1eed63efba5f81d95bfe37d82c8e736b974f477b. Ethereum blockchain data shows that this address received the redeemed DAI from the Multichain Executor on July 10, about five minutes after the previous transaction.

Data for BNB Smart Chain (BSC) shows that the Multichain Executor also called the anySwapFeeTo function on its network for $208,997 worth of anySwap US Dollar Coin (USDC). This resulted in $208,997 worth of the tokens being converted into their underlying Binance-Pegged USDC, which were subsequently sent to this same address. In other BSC transactions, the contract used this process to convert 50.80 anyBTC, worth $39,251.43 at the time, to equivalent Binance-Pegged Bitcoin (BTCB) and send it to this address.

The transactions add up to approximately $263,524.33 worth of tokens sent to this address through the anySwapFeeTo method.

Spreek said this behavior could be part of the normal functioning of the protocol. On the other hand, a different account had engaged in similar behavior the day before, they stated. The other account eventually sold the drained tokens, providing evidence that it was malicious:

“It is unclear whether this is authorized behavior. Previously the same method was used yesterday by a different MPC address on the anyUSDT token on mainnet. The tokens were then immediately sold to ETH, suggesting that that similar address was the actions of a malicious actor.”

The on-chain sleuth theorized that the attacker may be using the anySwapFeeTo function to set fees to an arbitrarily large amount, allowing them to drain users’ funds. This function “Apparently allows ANY value to be set, so the address is simply choosing the total value of the token held in that anyToken,” Spreek stated.

The Multichain incident has baffled blockchain analysts, as no one has been able to prove whether it resulted from an exploit or is simply the result of large token holders moving their funds between networks. The mystery began on July 7 when over $100 million worth of tokens were withdrawn from the Ethereum side of Multichain’s Fantom, Moonriver, and Dogechain bridges and sent to wallet addresses with no previous transactions. These withdrawals represented the majority of funds held on each bridge.

The Multichain team declared that the withdrawals were “abnormal” and told users to stop using the protocol. However, they did not declare what the source of the anomaly was or could be.

On July 8, stablecoin issuers Circle and Tether froze some of the addresses that received funds tied to the strange transactions. On July 11, blockchain analytics firm Chainanalysis said the incident “looks more like a hack or rugpull and less like a migration.”

The Multichain team says their CEO is missing and that they’ve shut down some bridges due to no longer having access to some of the network’s multi-party computation network servers.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Retail Surge Sparks Bearish Outlook As Bitcoin Dominance Declines

The cryptocurrency market’s recent dominance by Bitcoin has decreased below 50%, indicating a potential adverse trend as retail activity increases This change prompts inquiries regarding market

Kraken Set to Launch Its Own Blockchain ‘Ink’ in 2025

The post Kraken Set to Launch Its Own Blockchain ‘Ink’ in 2025 appeared first on Coinpedia Fintech News Being an industry giant for the past 14 years, Kraken, one of the oldest

BOB Project: Can Bitcoin Take Over DeFi with Ethereum Bridge?

The post BOB Project: Can Bitcoin Take Over DeFi with Ethereum Bridge appeared first on Coinpedia Fintech News BOB, a project built on Bitcoin, is s making headlines with its bold plan to make

Kraken eyes DeFi expansion with launch of Ink, its new Ethereum layer-2 network

Crypto exchange Kraken announced the upcoming launch of Ink, an Ethereum layer-2 network based on the Optimism Superchain, in an Oct 24 statement Ink aims to empower users to trade, borrow, and lend

Could Trump’s 2024 Victory Send Bitcoin Soaring to $92K? This Bitwise Exec Thinks So

Bitwise’s head of alpha strategies, Jeff Park, projects that a Trump win in the 2024 US election could push BTC prices toward the $92,000 mark Park isn’t alone in this prediction; a

Crypto Alert: $13 Million of Investor Funds Frozen in South Korea!

The post Crypto Alert: $13 Million of Investor Funds Frozen in South Korea! appeared first on Coinpedia Fintech News In South Korea, over 33,000 crypto investors are locked out of approximately $13