zkSync DEX Merlin Exploited for Over $1.8M After Code Audit
Crypto News

zkSync DEX Merlin Exploited for Over $1.8M After Code Audit

3ในการอ่าน
1 year ago

Merlin’s liquidity pool has been drained of $1.8 million not long after blockchain security firm CertiK audited its code. 

zkSync DEX Merlin Exploited for Over $1.8M After Code Audit

สารบัญ

Ethereum-based decentralized exchange (DEX) Merlin, which uses zero-knowledge sync (zkSync), has lost more than $1.8 million in a liquidity pool exploit hours after smart contract security firm CertiK audited its code.

The hack occurred on Wednesday morning during the public sale of Merlin’s native token, MAGE, with the attacker siphoning several assets, including USD Coin (USDC), Ether (ETH), and other illiquid tokens.

Merlin’s LP Drained After Code Audit

A few hours after the exploit, CertiK tweeted that it was investigating the incident and working to understand its impact on the community. The security firm disclosed that its initial findings suggested that a private key management issue may have led to the hack and not an exploit, as widely believed.

CertiK said it pointed out the centralization risk in the recent audit report for Merlin under the “Decentralization Efforts” section. The firm insisted that while audits could not prevent private key issues, they always ensured to highlight better practices for projects.

As claimed in the audit dated April 24, 2023, CertiK recommended that Merlin improve its centralized roles to a decentralized mechanism like multi-signature wallets to enhance security practices. The firm also asked the protocol to implement a timelock feature with a latency of at least 48 hours to avoid a single point of key management failure. CertiK has also promised to work with appropriate authorities if any foul play is discovered.

“We encourage all community members to review this information and all audits fully. As we navigate this challenging situation, we want to assure you that we are taking all necessary measures to protect our community’s interests,” CertiK said.

Malicious Code Detected

Interestingly, eZKalibur, another zkSync DEX and launchpad, revealed it had identified the malicious code that enabled the hackers to drain Merlin’s funds. The DEX said it found two lines of code in the initialize function that gave the feeTo address approval to transfer an unlimited amount of tokens from the contract’s address.

Meanwhile, the Merlin team has asked users to revoke access to the connected site on their wallets as they analyze the cause of the exploit.
0 people liked this article

Related Articles

Crypto News
Microsoft Up 8.2% Premarket On Strong Earnings, Will Continue AI Push
Microsoft believes artificial intelligence products will boost sales. The post Microsoft Up 8.2% Premarket On Strong Earnings, Will Continue AI Push appeared first on Tokenist.
1 year ago
6ในการอ่าน
Crypto News
Bahamas-based firm GEM Digital increases investment in UAE Everdome metaverse project
GEM Digital, a digital asset investment firm based in the Bahamas, has increased its investment in the United Arab Emirates-based Everdome metaverse project by $50 million. This follows an initial ...
1 year ago
2ในการอ่าน
Crypto News
Bitcoin makes play for $30k, leading to $145M liquidations
Bitcoin’s (BTC) rally toward $30,000 led to more than $70 million in liquidations for short traders in the last 24 hours, according to Coinglass data. The overall crypto market saw roughly $145 mil...
1 year ago
2ในการอ่าน
Blog
EMG Has Formed A Collaboration With Polygon Studios
The 1st E-commerce Telecom platform that will enable payment, and peer-to-peer money transfer using its own cryptocurrency, EMG Coin.
1 year ago
2ในการอ่าน
Metaverse
YachtingVerse: The First IDO Project on the DaoSpace LaunchPad Platform.
An Initial DEX Offering (IDO) is a crowdfunding technique where crypto projects raise funds by offering their tokens on decentralized exchanges (DEX).
1 year ago
2ในการอ่าน
Crypto News
South Korea Court Rules LUNC Is Not a Security
A Seoul Southern District Court recently found that LUNA, now renamed LUNC, is not a financial investment product. The US SEC called LUNC a security earlier this year. Terra Classic (LUNC), the na...
1 year ago
3ในการอ่าน