CertiK Helping Merlin DEX With Compensation Plan
Crypto News

CertiK Helping Merlin DEX With Compensation Plan

3ในการอ่าน
1 year ago

The security firm CertiK is planning to launch a compensation plan to return the funds stolen in the $2 million Merlin DEX exploit.  CertiK Working To Recover Stolen Funds The blockchain security company has jumped in to help the Merlin decentralized exchange in its dire sit...

CertiK Helping Merlin DEX With Compensation Plan

The security firm CertiK is planning to launch a compensation plan to return the funds stolen in the $2 million Merlin DEX exploit. 

CertiK Working To Recover Stolen Funds

The blockchain security company has jumped in to help the Merlin decentralized exchange in its dire situation. The latter lost around $2 million during a public sale of its MAGE token, despite being audited by the smart-contract auditor, CertiK. To help recover a portion of the lost funds, CertiK is launching a compensation plan. 

The security firm has revealed that it is investigating the scam and has even worked with some members of the Merlin team to launch the compensation program. 

On April 26th, CertiK said, 

“Initial investigations indicate that the rogue developers are based in Europe, and CertiK will collaborate with law enforcement authorities to track them down if direct negotiation is unsuccessful.”

USDC Stolen During Public Sale

The decentralized exchange was conducting a three-day public sale of its MAGE token when it was targeted by a rogue developer. The latter made away with around $850,000 of USD Coin and other relatively illiquid tokens. To sum it up, a total of $1.8 million worth of tokens were stolen in the attack. CertiK has dived into the blockchain data available on the attack and surmised that the culprit behind the attack must be someone who had control over the liquidity pool and could easily remove the funds. 

CertiK’s Audit Under Question

The root of the hack was uncovered by the eZKalibur team, which is a community-driven decentralized exchange. Their initial investigations helped them identify the malicious code responsible for the depletion of funds. Specifically, the initialize function contains two lines of code that grant approval to the feeTo address, allowing it to transfer an unlimited amount of token0 and token1 from the contract's address. This enables the feeTo address to call the transferFrom function and transfer tokens from the contract's address to itself.

The eZKalibur team had also questioned CertiK’s auditing, which had given the Merlin DEX a high ranking before the attack happened. 

CertiK’s Plan Offers 20% Bounty

The CertiK team is trying to appeal to the rogue developer with a compensation plan, where they would get to keep a white hat bounty of 20% of the stolen funds after returning 80% to the exchange platform. According to CertiK's preliminary findings, the developers of the project are located in Europe, and the company is collaborating with law enforcement agencies to locate them.

The security firm also said, 

“Although we raised the private key privilege issues in the audit report, we want to assist impacted users. We are determined to track down those behind this rug pull.”

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. 

0 people liked this article

Related Articles

Marketing
AIGameToEarn - The Web3 Gaming Platform That Rewards Players with $100000 Guaranteed Prize Pool
AIGameToEarn is a blockchain-based project seeking to become the go-to platform for Web3 gaming where everyone, regardless of skill and experience, can play, learn, earn, and have fun.
1 year ago
7ในการอ่าน
Crypto News
What happened to the Bitcoin price?
Bitcoin was sailing higher on Wednesday when suddenly there was a strong pullback. News of Mt Gox and the US Government moving their BTC caused panic selling. A topsy-turvy day The day had gone wel...
1 year ago
3ในการอ่าน
Crypto News
The road to L2's - OpenOcean brings Dex aggregation to zkSync Era
OpenOcean has integrated on zkSync Era to provide traders the best swap rate.
1 year ago
3ในการอ่าน
Crypto News
FBI Raids $4M Washington Home of Former FTX Executive
The FBI reportedly raided the house of the former co-CEO of FTX Digital Markets, Ryan Salame. The post FBI Raids $4M Washington Home of Former FTX Executive appeared first on Tokenist.
1 year ago
5ในการอ่าน
Crypto News
Veax Labs Officially Launches Advanced NEAR-Based DEX on Mainnet, Introduces Major LP Incentive P...
Schwarzenbach, Switzerland, April 27th, 2023, ChainwireVeax Labs has officially launched its advanced decentralized exchange (DEX) on mainnet. Built on NEAR Protocol, the platform aims to seamlessl...
1 year ago
3ในการอ่าน
Crypto News
NEAR Protocol (NEAR) Price Prediction And A Year Of Growth For Uwerx (WERX)
The dollar has weakened, and risk assets trade inversely to the dollar. As the dollar loses strength, it becomes less appealing to investors, and this capital quickly finds its way into the digital...
1 year ago
3ในการอ่าน