{"id":5291,"date":"2022-01-19T08:30:36","date_gmt":"2022-01-19T08:30:36","guid":{"rendered":"http:\/\/egrowonline.com\/?p=5291"},"modified":"2022-01-19T08:30:36","modified_gmt":"2022-01-19T08:30:36","slug":"one-of-the-largest-cryptocurrency-swapping-platforms-just-lost-1-3-million-as-users-failed-to-update-approvals","status":"publish","type":"post","link":"http:\/\/egrowonline.com\/?p=5291","title":{"rendered":"One of the largest cryptocurrency swapping platforms just lost $1.3 million as users failed to update approvals"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<ul class=\"summary-list\">\n<li>Around $1.34 million has been siphoned off from one of the largest crypto token swapping platforms in the world, Multichain \u2014 formerly known as Anyswap.<\/li>\n<li>The company had alerted users to the bug on January 17 but required them to manually revoke permissions for six tokens.<\/li>\n<li>Not everyone made the change and now over $1 million have been stolen by a single blockchain address.<\/li>\n<\/ul>\n<div class=\"amzn-offers-wdgt clearfix js-slider-wrap\">\n<div class=\"amzn-offers-slider\">\n<ul class=\"js-slider-body\">\n<li><a target=\"_blank\" rel=\"nofollow sponsored noopener\" class=\"amzn-offers-widget-col\" href=\"https:\/\/www.businessinsider.in\/affiliate_amazon.cms?pid=B00NFD0ETQ&amp;tag=bi_inarticle_widget_offers-21\">\n<p><span class=\"amzn-offers-p-disc\">35<span>% OFF<\/span><\/span><\/p>\n<div class=\"amzn-offers-w-details\">\n<div class=\"amzn-offers-w-thumb\"><img decoding=\"async\" src=\"https:\/\/m.media-amazon.com\/images\/I\/31nlfClYn7L._SL160_.jpg\" \/><\/div>\n<div class=\"amzn-offers-w-deal\">\n<p><h4>Logitech G402 Hyperion Fury Wired Gaming Mouse, 4,000 DPI, Lightweight, 8 Programmable Buttons, Compatible with PC\/Mac &#8211; Black<\/h4>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"amzn-offers-col2\">\n<div class=\"amzn-offers-buy-btn\"><span class=\"amzn-offers-get-this\">Buy On<\/span><img decoding=\"async\" src=\"https:\/\/www.businessinsider.in\/photo\/84612448\/84612448.jpg\" \/><\/div>\n<\/div>\n<p><\/a><\/li>\n<li><a target=\"_blank\" rel=\"nofollow sponsored noopener\" class=\"amzn-offers-widget-col\" href=\"https:\/\/www.businessinsider.in\/affiliate_amazon.cms?pid=B09KTZS3JP&amp;tag=bi_inarticle_widget_offers-21\">\n<p><span class=\"amzn-offers-p-disc\">18<span>% OFF<\/span><\/span><\/p>\n<div class=\"amzn-offers-w-details\">\n<div class=\"amzn-offers-w-thumb\"><img decoding=\"async\" src=\"https:\/\/m.media-amazon.com\/images\/I\/41GvjothOZL._SL160_.jpg\" \/><\/div>\n<div class=\"amzn-offers-w-deal\">\n<p><h4>HP Pavilion 15 11th Gen Intel Core i5-8GB RAM\/512GB SSD 15.6 inch(39.6 cm)Laptop, FHD Anti-Glare Display\/Iris Xe Graphics\/Backlit KB\/B&amp;O Audio\/Windows 11\/ 1.75kg, 15-eg1000TU<\/h4>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"amzn-offers-col2\">\n<div class=\"amzn-offers-buy-btn\"><span class=\"amzn-offers-get-this\">Buy On<\/span><img decoding=\"async\" src=\"https:\/\/www.businessinsider.in\/photo\/84612448\/84612448.jpg\" \/><\/div>\n<\/div>\n<p><\/a><\/li>\n<li><a target=\"_blank\" rel=\"nofollow sponsored noopener\" class=\"amzn-offers-widget-col\" href=\"https:\/\/www.businessinsider.in\/affiliate_amazon.cms?pid=B09GKWTGXK&amp;tag=bi_inarticle_widget_offers-21\">\n<p><span class=\"amzn-offers-p-disc\">37<span>% OFF<\/span><\/span><\/p>\n<div class=\"amzn-offers-w-details\">\n<div class=\"amzn-offers-w-thumb\"><img decoding=\"async\" src=\"https:\/\/m.media-amazon.com\/images\/I\/41iuyFaLWAS._SL160_.jpg\" \/><\/div>\n<div class=\"amzn-offers-w-deal\">\n<p><h4>Lenovo Tab M10 FHD Plus (2nd Gen) (10.3 inch\/26.6 cm, 4 GB, 128 GB, Wi-Fi Only), Platinum Grey with Active Pen<\/h4>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"amzn-offers-col2\">\n<div class=\"amzn-offers-buy-btn\"><span class=\"amzn-offers-get-this\">Buy On<\/span><img decoding=\"async\" src=\"https:\/\/www.businessinsider.in\/photo\/84612448\/84612448.jpg\" \/><\/div>\n<\/div>\n<p><\/a><\/li>\n<li><a target=\"_blank\" rel=\"nofollow sponsored noopener\" class=\"amzn-offers-widget-col\" href=\"https:\/\/www.businessinsider.in\/affiliate_amazon.cms?pid=B088HBRHYG&amp;tag=bi_inarticle_widget_offers-21\">\n<p><span class=\"amzn-offers-p-disc\">44<span>% OFF<\/span><\/span><\/p>\n<div class=\"amzn-offers-w-details\">\n<div class=\"amzn-offers-w-thumb\"><img decoding=\"async\" src=\"https:\/\/m.media-amazon.com\/images\/I\/41H2QuJITKL._SL160_.jpg\" \/><\/div>\n<div class=\"amzn-offers-w-deal\">\n<p><h4>Lenovo Yoga Smart Tablet with The Google Assistant 25.65 cm (10.1 inch, 4GB, 64GB, WiFi + 4G LTE), Iron Grey<\/h4>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"amzn-offers-col2\">\n<div class=\"amzn-offers-buy-btn\"><span class=\"amzn-offers-get-this\">Buy On<\/span><img decoding=\"async\" src=\"https:\/\/www.businessinsider.in\/photo\/84612448\/84612448.jpg\" \/><\/div>\n<\/div>\n<p><\/a><\/li>\n<li><a target=\"_blank\" rel=\"nofollow sponsored noopener\" class=\"amzn-offers-widget-col\" href=\"https:\/\/www.businessinsider.in\/affiliate_amazon.cms?pid=B08P2VQ5XV&amp;tag=bi_inarticle_widget_offers-21\">\n<p><span class=\"amzn-offers-p-disc\">19<span>% OFF<\/span><\/span><\/p>\n<div class=\"amzn-offers-w-details\">\n<div class=\"amzn-offers-w-thumb\"><img decoding=\"async\" src=\"https:\/\/m.media-amazon.com\/images\/I\/31f9e9HnJfS._SL160_.jpg\" \/><\/div>\n<div class=\"amzn-offers-w-deal\">\n<p><h4>Acer Predator X35 1800R Curved 35 Inch UltraWide QHD Gaming Monitor I G-SYNC Ultimate I Quantum Dot I 200Hz I VESA Display HDR 1000 I Adjustable Stand I Display Port, HDMI Port &amp; USB 3.0 HUB<\/h4>\n<\/p>\n<\/div>\n<\/div>\n<div class=\"amzn-offers-col2\">\n<div class=\"amzn-offers-buy-btn\"><span class=\"amzn-offers-get-this\">Buy On<\/span><img decoding=\"async\" src=\"https:\/\/www.businessinsider.in\/photo\/84612448\/84612448.jpg\" \/><\/div>\n<\/div>\n<p><\/a><\/li>\n<\/ul>\n<p><!--\/amazon_tas_as_widget.cms?widgetName=Amazing_Offers_In-article_Widget&amp;pl=fashion&amp;type=tashnkpotime:3--><\/div>\n<\/div>\n<p><!--\/amazon_offers_widget.cms?PartnerTag=bi_inarticle_widget_offers-21&amp;amsid=88992186potime:34-->At a time when the security ecosystem around decentralised finance (<br \/>\n<a target=\"_blank\" href=\"http:\/\/coindcx.com\" rel=\"nofollow noopener\">DeFi<\/a>) is being<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.businessinsider.in\/investment\/news\/bitmart-suspends-withdrawals-after-hackers-drained-almost-200-million-in-cryptocurrencies-using-a-stolen-private-key\/articleshow\/88125721.cms\" rel=\"noopener\">questioned<\/a>, cross-chain protocol Multichain \u2014 formerly known as Anyswap \u2014 is asking users to take matters into their own hands in the face of a $1.34 million exploit. <\/p>\n<p>If you have got a problem, you have to fix it on your own, according to the company. Multichain initially revealed that it noticed a critical vulnerability on its platform on January 17 and had subsequently \u2018fixed\u2019 it.\n<\/p>\n<div data-type=\"twitter\" data-handle=\"MultichainOrg\" data-handlename=\"Multichain (Previously Anyswap)\" data-image=\"http:\/\/pbs.twimg.com\/profile_images\/1471389661712973827\/EgXhZHRJ_normal.jpg\" data-favoritecount=\"757\" data-retweetcount=\"344\" data-status=\"1\/A critical vulnerability that affected 6 tokens (WETH, PERI, OMT, WBNB, MATIC, AVAX) has been reported and fixed.\u2026 https:\/\/t.co\/1FM8EXYy7R\" data-createdat=\"1642436047000\" data-id=\"1483110393543544832\">\n<div>\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p>1\/A critical vulnerability that affected 6 tokens (WETH, PERI, OMT, WBNB, MATIC, AVAX) has been reported and fixed.\u2026 https:\/\/t.co\/1FM8EXYy7R<\/p>\n<p>&amp;mdash; Multichain (Previously Anyswap) (@MultichainOrg) <a target=\"_blank\" href=\"https:\/\/twitter.com\/MultichainOrg\/status\/1483110393543544832\" rel=\"nofollow noopener\">1642436047000<\/a><\/p><\/blockquote>\n<\/div>\n<\/div>\n<p>However, by \u2018fixing\u2019 it, the company meant that users will have to manually login into their account and remove approvals of six tokens on its platform \u2014 Wrapped Ethereum (WETH), PERI Finance (PERI), Mars Token (OMT), Wrapped BNB (WBNB),<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.businessinsider.in\/cryptocurrency\/news\/cryptocurrency-polygon-founded-by-3-indians-has-touched-13-billion-in-market-cap\/articleshow\/82770196.cms\" rel=\"noopener\">Polygon<\/a> (MATIC), and Avalanche (AVAX).<br \/>\n<br class=\"article_breaks\" data-name=\"6\" data-nm1=\"br\" \/><br \/>\n<br \/>Unlike the message sent out on Twitter where Multichain wrote that the exploit has been \u2018reported and fixed\u2019, the company meant that it\u2019s been \u2018noticed\u2019 and \u2018now it\u2019s on you\u2019. The miscommunication meant that not everyone was able to revoke permissions before the bug started to get exploited. <\/p>\n<div data-type=\"twitter\" data-handle=\"samczsun\" data-handlename=\"samczsun\" data-image=\"http:\/\/pbs.twimg.com\/profile_images\/1483510261755650049\/2KFi3fM7_normal.jpg\" data-favoritecount=\"760\" data-retweetcount=\"282\" data-status=\"Someone is exploiting this literally *right now*. If you haven't revoked approvals yet you should probably do so be\u2026 https:\/\/t.co\/pKVkOdEkSy\" data-createdat=\"1642495707000\" data-id=\"1483360627229962246\">\n<div>\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p>Someone is exploiting this literally *right now*. If you haven&#8217;t revoked approvals yet you should probably do so be\u2026 https:\/\/t.co\/pKVkOdEkSy<\/p>\n<p>&amp;mdash; samczsun (@samczsun) <a target=\"_blank\" href=\"https:\/\/twitter.com\/samczsun\/status\/1483360627229962246\" rel=\"nofollow noopener\">1642495707000<\/a><\/p><\/blockquote>\n<\/div>\n<\/div>\n<p>Less than 24 hours later, blockchain security company PeckShield noticed that a single blockchain address had made off with more $1.34 million. <\/p>\n<div data-type=\"twitter\" data-handle=\"PeckShieldAlert\" data-handlename=\"PeckShieldAlert\" data-image=\"http:\/\/pbs.twimg.com\/profile_images\/1128620708135718912\/t1Igt1Ns_normal.png\" data-favoritecount=\"65\" data-retweetcount=\"22\" data-status=\"@peckshield @MultichainOrg Stolen funds are currently held at this address, more than 450 Ether (~$1.34m)https:\/\/t.co\/I8H6YXURBM\" data-createdat=\"1642496396000\" data-id=\"1483363515411099651\">\n<div>\n<blockquote class=\"twitter-tweet\" lang=\"en\">\n<p>@peckshield @MultichainOrg Stolen funds are currently held at this address, more than 450 Ether (~$1.34m)https:\/\/t.co\/I8H6YXURBM<\/p>\n<p>&amp;mdash; PeckShieldAlert (@PeckShieldAlert) <a target=\"_blank\" href=\"https:\/\/twitter.com\/PeckShieldAlert\/status\/1483363515411099651\" rel=\"nofollow noopener\">1642496396000<\/a><\/p><\/blockquote>\n<\/div>\n<\/div>\n<p>There has been no update as to whether another solution has been found or if the tokens of Multichain\u2019s users are no longer vulnerable, as of 11:00am on January 19 Indian Standard Time (IST).<\/p>\n<p><strong><\/p>\n<h2 class=\"subheading\">What is a cross-chain swap protocol?<\/h2>\n<p><\/strong>\n<\/p>\n<p>Multichain is one of the largest<br \/>\n<a target=\"_blank\" href=\"https:\/\/www.businessinsider.in\/cryptocurrency\/news\/ethereum-vs-solana-vs-cardano-who-is-defis-darling\/articleshow\/86608461.cms\" rel=\"noopener\">cross-chain swap<\/a> protocols in the world right now. It runs across 10 different blockchains and supports 1,366 different tokens. Overall, it looks after over $8.3 billion in smart contracts.<br \/>\n<br class=\"article_breaks\" data-mod=\"6\" data-nm1=\"a\" \/><\/p>\n<p>Simply put, a cross-chain swap lets users exchange a token on one blockchain for a different token on another blockchain. According to Multichain\u2019s own company statement, the Singapore-based enterprise is aiming to become a router for Web3, touted to be the next generation of the internet. The news of the exploit has come in less than a month after Multichain raised $60 million at a $12 billion valuation led by Binance Labs.<\/p>\n<p><strong>SEE ALSO:<br \/><a target=\"_blank\" href=\"https:\/\/www.businessinsider.in\/investment\/news\/coindcx-hiring-2000-plus-people-this-year-crypto-coders-developers-product-development-and-other-roles\/articleshow\/88972086.cms\" rel=\"noopener\">EXCLUSIVE: CoinDCX plans to hire more than 2,000 people this year \u2014 and they are not just looking at coders<\/a><br \/><\/strong><br \/>\n<a target=\"_blank\" href=\"https:\/\/www.businessinsider.in\/investment\/news\/coinbase-users-can-buy-nfts-with-mastercard-as-the-crypto-exchange-partners-with-the-card-giant-to-ease-the-digital-art-buying-experience\/articleshow\/88980984.cms\" rel=\"noopener\">Coinbase users can buy NFTs with Mastercard as the crypto exchange partners with the card giant to ease the digital art-buying experience<\/a><br \/>\n<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.businessinsider.in\/investment\/news\/one-of-the-largest-cryptocurrency-swapping-platforms-just-lost-1-3-million-as-users-failed-to-update-approvals\/articleshow\/88992186.cms\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Around $1.34 million has been siphoned off from one of the largest crypto token swapping platforms in the world, Multichain \u2014 formerly known as Anyswap. The company had alerted users to the bug on January 17 but required them to manually revoke permissions for six tokens. Not everyone made the change and now over $1 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5292,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[36],"tags":[3859,52,3858,1170,1687,545,1208,3857,886,399],"class_list":["post-5291","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-approvals","tag-cryptocurrency","tag-failed","tag-largest","tag-lost","tag-million","tag-platforms","tag-swapping","tag-update","tag-users"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"http:\/\/egrowonline.com\/wp-content\/uploads\/2022\/01\/one-of-the-largest-cryptocurrency-swapping-platforms-just-lost-1-3-million-as-users-failed-to-update-approvals.jpg","_links":{"self":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/5291","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5291"}],"version-history":[{"count":1,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/5291\/revisions"}],"predecessor-version":[{"id":5293,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/posts\/5291\/revisions\/5293"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=\/wp\/v2\/media\/5292"}],"wp:attachment":[{"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5291"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5291"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/egrowonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5291"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}