{"id":16802,"date":"2022-01-20T09:15:02","date_gmt":"2022-01-20T08:15:02","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=16802"},"modified":"2022-01-20T10:09:43","modified_gmt":"2022-01-20T09:09:43","slug":"users-attack-multichain-over-security-vulnerability-leading-to-losses-of-over-3m","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/users-attack-multichain-over-security-vulnerability-leading-to-losses-of-over-3m\/","title":{"rendered":"Users attack Multichain over security vulnerability leading to  losses of over $3M"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\"><a href=\"https:\/\/coinscreed.com\/staging\/cross-chain-protocol-multichain-raises-60m-in-a-seed-funding-round-led-by-binance-labs.html\" data-type=\"post\" data-id=\"15435\">Cross-chain router protocol (CRP) Multichain<\/a>, on January 17th first discovered a security breach on its network. However, hackers have continued to take advantage of the weakness in the chain with users having lost over $3M. <\/h5>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"519\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145-1024x519.png\" alt=\"Users attack Multichain over security vulnerability leading to  losses of over $3M\" class=\"wp-image-16822\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145-1024x519.png 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145-300x152.png 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145-768x390.png 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145-750x380.png 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145.png 1029w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Multichain asked users to rescind permissions for six tokens earlier this week to protect their funds from <a href=\"https:\/\/www.google.com\/search?q=Users+attack+Multichain+over+security+vulnerability+leading+to+losses+of+over+%243M&rlz=1C1SQJL_enNG889NG889&oq=Users+attack+Multichain+over+security+vulnerability+leading+to++losses+of+over+%243M&aqs=chrome..69i57.1406j0j9&sourceid=chrome&ie=UTF-8\" data-type=\"URL\" data-id=\"https:\/\/www.google.com\/search?q=Users+attack+Multichain+over+security+vulnerability+leading+to+losses+of+over+%243M&rlz=1C1SQJL_enNG889NG889&oq=Users+attack+Multichain+over+security+vulnerability+leading+to++losses+of+over+%243M&aqs=chrome..69i57.1406j0j9&sourceid=chrome&ie=UTF-8\" target=\"_blank\" rel=\"noopener\">fraudulent persons<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>.<\/p>\n\n\n\n<p>However, after Multichain's announcement on January 17, other hackers attempted the attack. One stole $1.43 million, while the other offered to refund 80% and retain the remainder as a tip. The stolen amount has now increased to $3 million, according to Tal Be'ery, co-founder of the ZenGo wallet.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"505\" height=\"562\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-140.png\" alt=\"\" class=\"wp-image-16807\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-140.png 505w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-140-270x300.png 270w\" sizes=\"(max-width: 505px) 100vw, 505px\" \/><\/figure>\n\n\n\n<p>WETH, PERI, OMT, WBNB, MATIC, and AVAX are among the six <a href=\"https:\/\/coinscreed.com\/staging\/a-prominent-ethereum-whale-scoops-up-110-billion-shiba-inu-tokens-worth-3-62-million.html\" data-type=\"post\" data-id=\"15943\">supported tokens<\/a> remaining vulnerable to the security flaw.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Reaction of users to the hack <\/h2>\n\n\n\n<p>On social media, users have criticized the corporation for not giving customers enough information or support about the problem. In exchange for the remaining funds, one user who lost $960k offered 50 ETH to the hacker's address.<\/p>\n\n\n\n<p>On January 17, the firm claimed that the major<a href=\"https:\/\/coinscreed.com\/staging\/a-major-vulnerability-has-frozen-hundreds-of-millions-of-dollars-of-ethereum.html\" data-type=\"post\" data-id=\"11432\"> vulnerability<\/a> impacting the six tokens had been disclosed and rectified, yet on January 19, it advised customers to cancel token approvals once more. The comments on Multichain's latest tweets have since been disabled.<\/p>\n\n\n\n<p>Crypto &#8220;ChainLinkGod&#8221; on Twitter expressed his confusion by the platform's remark, while &#8220;drarreg17&#8221; inquired about what Multichain will do to &#8220;compensate people like myself who were affected by the exploits?&#8221;<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"507\" height=\"573\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-141.png\" alt=\"\" class=\"wp-image-16808\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-141.png 507w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-141-265x300.png 265w\" sizes=\"(max-width: 507px) 100vw, 507px\" \/><\/figure>\n\n\n\n<p>Unhappy users have expressed their dissatisfaction with the company's Telegram channel today, claiming that Multichain has yet to fix the<a href=\"https:\/\/coinscreed.com\/staging\/solana-sol-network-goes-down-as-a-result-of-another-ddos-attack.html\" data-type=\"post\" data-id=\"15925\"> security flaw<\/a> or give the help they require.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-142.png\" alt=\"\" class=\"wp-image-16809\" width=\"516\" height=\"747\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-142.png 428w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-142-207x300.png 207w\" sizes=\"(max-width: 516px) 100vw, 516px\" \/><\/figure>\n\n\n\n<p>Be'ery claims that the company contacted the original account, which has been holding approximately 450 ETH ($1.43 million) in stolen cash since Jan. 18, and promised the hacker or hackers a bug <a href=\"https:\/\/coinscreed.com\/staging\/cryptocom-reportedly-loses-15-million-due-to-the-recent-compromise.html\" data-type=\"post\" data-id=\"16679\">&#8220;bounty for exploits.&#8221;<\/a><\/p>\n\n\n\n<p>Multichain (previously Anyswap) aspires to be the ultimate Web 3.0 router. The ecosystem allows no-slippage exchanging and supports 30 chains, including Bitcoin (BTC), Avalanche (AVAX), <a href=\"https:\/\/coinscreed.com\/staging\/usdc-ranks-second-on-the-ethereum-network-for-the-first-time.html\" data-type=\"post\" data-id=\"16762\">Ethereum (ETH<\/a>), Fantom (FTM), Litecoin (LTC), and Terra (LUNA).<\/p>\n\n\n\n<p>With roughly $9 billion in TVL on the table, it's unclear when or how Multichain will resolve the matter.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cross-chain router protocol (CRP) Multichain, on January 17th first discovered a security breach on its network. However, hackers have continued to take advantage of the weakness in the chain with users having lost over $3M. Multichain asked users to rescind permissions for six tokens earlier this week to protect their funds from fraudulent persons . [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":16822,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[6111,6115,6108,6700],"class_list":["post-16802","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cross-chain-protocol","tag-hackers-2","tag-multichain","tag-vulnerability"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/01\/image-145.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/16802","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=16802"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/16802\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/16822"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=16802"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=16802"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=16802"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}