On July 7, 2023, according to Secure3, a blockchain security audit contest platform, Fantom Bridge from Multichain was attacked. Multichain has announced through its official Twitter that it has suspended all bridge services and has no estimated resume time yet. The Secure3 security team analyzed and found that there is no evidence showing this is caused by smart contract vulnerability, suspecting that the attack may have been caused by the comproise of the MPC wallet multi-signature private key, causing a loss of about $126 million.
Among them, assets worth about $118 million have been transferred out from Multichain’s Fantom Bridge. Including:
0x9d57..
0x027F..
and 0xefeef..
respectively0x622e5..
0x418e..
In addition, various tokens worth about $7.5 million (USDC, USDT, DAI, WBTC) were transferred out from Multichain’s Moonriver Bridge and transferred to address 0x48Be..
In response to this security incident, the Secure3 security team summarizes the MPC wallet security considerations here.
MPC wallet is a digital asset wallet that uses multi-party computation (MPC) technology to protect private keys. MPC wallet can split private keys into multiple shards and store them on different devices or in the cloud to avoid the risk of single point failure and leakage of private keys.
Secure3 security team recommends:
Headquartered in Silicon Valley, Secure3 is an intelligent audit contest platform, aiming to reshape Web3 safety by providing efficient, affordable, and secure smart contract auditing services for all Web3 projects.
Secure3’s audit contest organizes decentralized certified auditors in the form of an audit competition. With 3–10x more auditors (compared to centralized auditing firms) working on the project independently, anonymously, and simultaneously, Secure3 has proven successful in providing cost-efficient and high-quality auditing services. In the past year, Secure3 has done over 100 projects including industry leaders, such as zkSync, Mantle, Manta Network, IoTeX, ParaSpace, MirrorWorld, etc.
Secure3 was incubated by Stanford StartX in 2022, and closed $5M seed funding from Mirana, GGV, Alumni Ventures, Hashkeys, etc.
安全铸基,创新无界
直击深度洞察
On August 14, 2023, according to Secure3, a blockchain security audit contest company, the decentralized yield aggregator ZunamiProtocol was attacked, resulting in a loss of more than 2 million US dollars. The Secure3 security team analyzed that the root cause of this attack was that the LP asset price calculation logic in ZunamiProtocol had defects, and the attacker used it to manipulate the price. The Secure3 security team summarized the reasons for this incident.
On July 31, 2023, according to Secure3, a blockchain security audit contest platform, multiple protocols including Curve were attacked. Further analysis revealed that the root cause was vulnerabilities in the underlying Vyper compiler for the Ethereum smart contract programming language. Versions 0.2.15, 0.2.16 and 0.3.0 contained serious flaws, resulting in multiple attacks on projects like Curve Finance, Alchemix and JPEG’d, inflicting losses totaling around $70 million. The Secure3 security team determined that the fundamental reason behind the attacks was the failure of reentrancy locks in the vulnerable Vyper versions. Secure3’s security team analyzed the factors behind this incident.
Team Secure3 recently discovered a malicious attack on the OMNI Protocol, with the hacker stealing almost 2000 ETH (~2.4M USD) from OMNI.
联系我们
audit@secure3.io