zkSync DEX Merlin Exploited for Over $1.8M
Crypto News

zkSync DEX Merlin Exploited for Over $1.8M

3m
1yr ago

Merlin’s liquidity pool has been drained of $1.8 million not long after blockchain security firm CertiK audited its code. 

zkSync DEX Merlin Exploited for Over $1.8M

Table of Contents

Ethereum-based decentralized exchange (DEX) Merlin, which uses zero-knowledge sync (zkSync), has lost more than $1.8 million in a liquidity pool exploit hours after smart contract security firm CertiK audited its code.
The hack occurred on Wednesday morning during the public sale of Merlin’s native token, MAGE, with the attacker siphoning several assets, including USD Coin (USDC), Ether (ETH), and other illiquid tokens.

Merlin’s LP Drained After Code Audit

A few hours after the exploit, CertiK tweeted that it was investigating the incident and working to understand its impact on the community. The security firm disclosed that its initial findings suggested that a private key management issue may have led to the hack and not an exploit, as widely believed.
CertiK said it pointed out the centralization risk in the recent audit report for Merlin under the “Decentralization Efforts” section. The firm insisted that while audits could not prevent private key issues, they always ensured to highlight better practices for projects.
As claimed in the audit dated April 24, 2023, CertiK recommended that Merlin improve its centralized roles to a decentralized mechanism like multi-signature wallets to enhance security practices. The firm also asked the protocol to implement a timelock feature with a latency of at least 48 hours to avoid a single point of key management failure. CertiK has also promised to work with appropriate authorities if any foul play is discovered.

“We encourage all community members to review this information and all audits fully. As we navigate this challenging situation, we want to assure you that we are taking all necessary measures to protect our community’s interests,” CertiK said.

Malicious Code Detected

Interestingly, eZKalibur, another zkSync DEX and launchpad, revealed it had identified the malicious code that enabled the hackers to drain Merlin’s funds. The DEX said it found two lines of code in the initialize function that gave the feeTo address approval to transfer an unlimited amount of tokens from the contract’s address.

Meanwhile, the Merlin team has asked users to revoke access to the connected site on their wallets as they analyze the cause of the exploit.
0 people liked this article

Related Articles

Crypto News
Bitcoin soars past $30,000 amid First Republic Bank crisis and Argentina inflation
Bitcoin’s price is experiencing a strong rebound, heading toward $30,000 on April 26 with a 6.5% increase compared to its local lows. The surge appears to be fueled by renewed concerns over t...
1yr ago
4m
Crypto News
Bitcoin mempool faces congestion amid price fluctuations
As bitcoin’s price experiences increased volatility, the mempool is becoming congested with a high volume of unconfirmed transactions. At the time of writing, 134,986 unconfirmed transactions...
1yr ago
3m
Marketing
@StakeHighRoller Joins Best Sports Betting Twitter Accounts to Follow with $1 Billion Bets Posted...
Stake High Roller is rapidly gaining popularity as one of the sports betting accounts on Twitter worth following.
1yr ago
2m
Crypto News
Cardano price analysis: ADA breaks past $0.4000 as bullish momentum restores
The recent Cardano price analysis shows that the ADA/USD pair has been on a bullish trend in the past 24 hours. ADA has been trading on a downtrend pattern for the past week and it is currently on ...
1yr ago
4m
Crypto News
The Sandbox and Ledger partner to make Metaverse more secure
The Sandbox, a decentralized metaverse platform, is partnering with security solution provider Ledger Enterprise to enhance security integration for its partners. The collaboration will allow partn...
1yr ago
3m
Blog
BTC and ETH Recover as SOL and RNDR Dominate Today’s Session
BTC and ETH are showing recovery signs in today's market session as SOL dominates with RNDR, which just completed its RNP voting process.
1yr ago
2m