Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the rank-math domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/coinmiller/public_html/wp-includes/functions.php on line 6114

Warning: Cannot modify header information - headers already sent by (output started at /home/coinmiller/public_html/wp-includes/functions.php:6114) in /home/coinmiller/public_html/wp-content/plugins/post-views-counter/includes/class-counter.php on line 913
Multichain under fire from users as hacking losses grow to $3M - Coin Miller
Home Crypto Multichain under fire from users as hacking losses grow to $3M

Multichain under fire from users as hacking losses grow to $3M

by Michael Nicholas
0 comment
Multichain under fire from users as hacking losses grow to $3M

Hackers have continued to exploit a critical vulnerability in the cross-chain router protocol (CRP) Multichain that first appeared on Jan 17.

Earlier this week, Multichain urged users to revoke approvals for six tokens to protect their assets from being exploited by malicious individuals.

However Multichain’s announcement on Jan. 17 encouraged more hackers to try the exploit. One stole $1.43 million, another offered to return 80% while keeping the rest as a tip. According to Tal Be’ery, the co-founder of the ZenGo wallet, the stolen amount has now risen to $3 million.

Six supported tokens are still subject to the security vulnerability including WETH, PERI, OMT, WBNB, MATIC, and AVAX.

Users have accused the company on social media of not providing them with clear enough information or support regarding the situation. One user who lost $960k offered 50 ETH to the hacker’s address in return for the remaining funds.

The company claimed on Jan.17 that the critical vulnerability affecting the six tokens had been reported and fixed on Jan. 17, but on Jan. 19 it again reminded users to revoke approvals of the tokens. Multichain has since turned off the comments on its recent tweets.

Crypto Twitter figure “ChainLinkGod” said that he was “incredibly confused” by the platform’s message, while “drarreg17” asked Multichain what it was going to do to “compensate users like myself who were affected by the exploits?”

Related: Multichain asks users to revoke approvals amid ‘critical vulnerability’

Unhappy users posting in the company’s Telegram group today complain  Multichain has not been able to resolve the security vulnerability yet, nor has it been able to provide its users with the support they seek.

According to Be’ery, the company reached out to the original address that has been holding over 450 ETH ($1.43 million) in stolen funds since Jan. 18 and offered the hacker or hackers a bug “bounty for exploits.”

Multichain (formerly Anyswap) envisions being the ultimate router for Web 3.0. The ecosystem supports 30 chains, including Bitcoin (BTC), Avalanche (AVAX), Ethereum (ETH), Fantom (FTM), Litecoin (LTC), and Terra (LUNA), and offers no-slippage swapping.

With nearly $9 billion in TVL, it is unclear when and how Multichain will sort the situation. Cointelegraph has contacted the project for comment.