CertiK and zk-Sync DEX Merlin Explore $2M Reimbursement Plan for Rugpull Victims
Crypto News

CertiK and zk-Sync DEX Merlin Explore $2M Reimbursement Plan for Rugpull Victims

3m
1 year ago

Merlin’s exploit was carried out by its bank-end developer team after they manipulated the protocol’s contracts and web host.

CertiK and zk-Sync DEX Merlin Explore $2M Reimbursement Plan for Rugpull Victims

Índice

Blockchain security firm CertiK and zk-Sync decentralized exchange (DEX) Merlin are working towards a plan to reimburse users affected by a recent exploit that drained almost $2 million from the latter.

Merlin revealed on Thursday that the incident, which was widely believed to be an exploit, was, in fact, a rug pull by several rogue members of its back-end developer team, who manipulated the protocol’s code to achieve their goal.

CertiK and Merlin to Compensate Victims

Recall that Merlin’s liquidity pool was drained on Wednesday, hours after CertiK audited the protocol’s code. The DEX was conducting the public sale of its native token, MAGE, when an attacker executed the hack.

As CryptoPotato reported, CertiK said an analysis of the event suggested a private key management issue may have led to the incident. The security firm disclosed that it had pointed out a centralization risk in the audit conducted on Monday and recommended that Merlin switches to decentralized mechanisms to avoid single points of key failure.

Upon further analysis, Merlin and CertiK discovered that the hack was an insider job from the protocol’s team. The back-end team implemented a call-action function that gave them power over the contracts and all trading pairs in the liquidity pools.

The developers were also able to manipulate Merlin’s front-end contracts and web host, allowing them to execute several on-chain transactions that drained the public sale.

A 20% White Hat Bounty

While Merlin and CertiK are working out a compensation plan, they have also informed relevant authorities about the incident and the whereabouts of the rogue technical team. The back-end team has been traced to Serbia, Europe, and local authorities have been notified.

The protocol has also recruited on-chain analysts to monitor the movement of the funds. The stolen assets have been tracked to two wallets and were still there at the time of writing.
Meanwhile, CertiK has offered the developers a 20% white hat bounty, urging them to accept it to avoid the wrath of the law.
0 people liked this article

Related Articles

Crypto News
The Number One Asset Bitcoin Jumps Over 10% in a Day
Bitcoin (BTC) started the day at a higher price of $30,000 due to the banking crisis, which triggered unrest in the US.
1 year ago
1m
Crypto News
US Senator Ted Cruz Endorses Bitcoin, Sparking Renewed Interest in the Cryptocurrency Market
The world of cryptocurrencies has received a significant boost as US Senator Ted Cruz publicly vouched for Bitcoin, saying he recently bought the dip. The move is a positive indication of how mains...
1 year ago
3m
Trading
BTC and ETH Recover as RNDR and EGLD Dominate Today’s Session
BTC and ETH record significant gains as they recover from the recent correction as RNDR and EGLD dominate with impressive gains.
1 year ago
2m
Crypto News
Bitcoin leverage ratio declines, signaling reduced price volatility
A crucial metric assessing the leverage usage in the bitcoin (BTC) market has been dropping, indicating a potential decrease in future price volatility. The estimated leverage ratio, computed by di...
1 year ago
2m
Crypto News
Kraken seeks court intervention against IRS demands
Crypto exchange Kraken is contesting the United States Internal Revenue Service (IRS) and its request for crucial user information, and has asked a federal court in San Francisco to intervene. Krak...
1 year ago
2m
Crypto News
Arkham Denies Buggy Mt. Gox Alerts to Blame for 7% Bitcoin Price Crash.
On April 26, the price of Bitcoin $29,176 plummeted by about 7% in a single hour, dropping from $29,850 to $27,789. According to media reports, this was because blockchain analytics company Arkham ...
1 year ago
3m