CertiK and zk-Sync DEX Merlin Explore $2M Reimbursement Plan for Rugpull Victims
Crypto News

CertiK and zk-Sync DEX Merlin Explore $2M Reimbursement Plan for Rugpull Victims

3 хв
1 year ago

Merlin’s exploit was carried out by its bank-end developer team after they manipulated the protocol’s contracts and web host.

CertiK and zk-Sync DEX Merlin Explore $2M Reimbursement Plan for Rugpull Victims

Зміст

Blockchain security firm CertiK and zk-Sync decentralized exchange (DEX) Merlin are working towards a plan to reimburse users affected by a recent exploit that drained almost $2 million from the latter.

Merlin revealed on Thursday that the incident, which was widely believed to be an exploit, was, in fact, a rug pull by several rogue members of its back-end developer team, who manipulated the protocol’s code to achieve their goal.

CertiK and Merlin to Compensate Victims

Recall that Merlin’s liquidity pool was drained on Wednesday, hours after CertiK audited the protocol’s code. The DEX was conducting the public sale of its native token, MAGE, when an attacker executed the hack.

As CryptoPotato reported, CertiK said an analysis of the event suggested a private key management issue may have led to the incident. The security firm disclosed that it had pointed out a centralization risk in the audit conducted on Monday and recommended that Merlin switches to decentralized mechanisms to avoid single points of key failure.

Upon further analysis, Merlin and CertiK discovered that the hack was an insider job from the protocol’s team. The back-end team implemented a call-action function that gave them power over the contracts and all trading pairs in the liquidity pools.

The developers were also able to manipulate Merlin’s front-end contracts and web host, allowing them to execute several on-chain transactions that drained the public sale.

A 20% White Hat Bounty

While Merlin and CertiK are working out a compensation plan, they have also informed relevant authorities about the incident and the whereabouts of the rogue technical team. The back-end team has been traced to Serbia, Europe, and local authorities have been notified.

The protocol has also recruited on-chain analysts to monitor the movement of the funds. The stolen assets have been tracked to two wallets and were still there at the time of writing.
Meanwhile, CertiK has offered the developers a 20% white hat bounty, urging them to accept it to avoid the wrath of the law.
0 people liked this article

Related Articles

Crypto News
SEC’s Crypto Compliance Tactics Called Out by High-Ranking Official
SEC Commissioner slams the agency for a lack of guidance on crypto compliance. Is the regulator losing its way? Read more here.
1 year ago
1 хв
Crypto News
Plant the Seeds of Change: Invest in Mooky for a Greener Future
 Background on the Mooky token and its focus on environmental sustainability The Mooky token is a cryptocurrency created to promote environmental sustainability. Mooky token’s ownership is sh...
1 year ago
4 хв
Crypto News
Fidelity Doubles Down on Metaverse With Financial Literacy Experience
Fidelity Investments is trying to expand its footprint in the metaverse with digital experiences meant to improve financial education for investors.  The firm said Thursday that it will launch Panc...
1 year ago
3 хв
Crypto News
Polkadot price analysis: Bullish momentum intensifies as DOT enters $6 range
The latest Polkadot price analysis shows that the bulls have been ruling the price charts today. The progress has been commendable, as a constant uptrend has been observed. Due to the increase in p...
1 year ago
3 хв
Crypto News
NEAR Protocol (NEAR) Price Prediction And A Year Of Growth For Uwerx (WERX)
The dollar has weakened, and risk assets trade inversely to the dollar. As the dollar loses strength, it becomes less appealing to investors, and this capital quickly finds its way into the digital...
1 year ago
3 хв
Crypto News
NY Investment Bank says ‘Crypto winter is over,’ Bullish Outlook for Coinbase.
H.C. Wainwright, a famous New York-based investment bank, has announced the end of “crypto winter.” The bank has launched coverage of US crypto exchange Coinbase with a “buy&#8221...
1 year ago
3 хв