• Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
  • Disclaimer
Wednesday, December 17, 2025
CryptoBangs.com
Advertisement
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Altcoin
    • NFT News
  • DeFi
  • Blockchain
  • Regulation
  • Shop
  • Blog
  • Calculator
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Altcoin
    • NFT News
  • DeFi
  • Blockchain
  • Regulation
  • Shop
  • Blog
  • Calculator
No Result
View All Result
CryptoBangs.com
No Result
View All Result

CertiK-audited DEX Merlin Exploited For $1.8m

April 26, 2023
in Crypto News
Reading Time: 3 mins read
A A
CertiK-audited DEX Merlin Exploited For $1.8m
ShareShareShareShareShare

Merlin, an Ethereum-based decentralized exchange (DEX) utilizing zkSync layer-2 protocol, suffered an exploit in which roughly $1.8 million in funds were lost.

This occurred despite having received an audit from smart-contract auditor CertiK. Since the disclosure, the Merlin team has advised users to revoke wallet permissions connected to its site and has announced that it is currently analyzing possible methodologies for the exploit.

Developer announcement

Can everyone revoke connected site access on your wallets/sign permission https://t.co/YRxH7IUU4T

We are analysing the exploit of our protocol and would stress that everyone carries out this step as a precaution.

More updates will be provided

— Merlin (@TheMerlinDEX) April 26, 2023

CertiK, the firm which issued the audit, claimed in its preliminary investigation that the incident may have originated from a private key management issue, rather than an exploit. The firm highlighted the “centralization risk” in its audit while also emphasizing that audits, on their own, are not designed to prevent private key issues. CertiK has assured that it will share relevant information with authorities if foul play can be suspected, or if insider information was possibly leaked.

Blockchain security firm Peckshield has also issued disclosures on the threat actor, who has started moving some of the stolen funds to exchanges, with $133,800 USDC sent to MEXC Global and $31,000 USDC sent to Binance.

CertiK is a prominent brand in the blockchain security industry, and yet despite its defense on the matter, others have questioned the validity of the audit. eZKalibur, another zkSync DEX, claims to have identified the malicious code responsible for the fund drainage and raised questions on the quality of CertiK’s audit.

According to eZKalibur, the problematic code lies within the initialize function, where two lines of code grant approval for the feeTo address to transfer an unlimited amount (type(uint256).max) of token0 and token1 from the contract’s address. In this case, the feeTo address could potentially call the transferFrom function on the respective tokens, allowing the transfer of tokens from the contract’s address to itself.

This finding raises questions about the thoroughness of CertiK’s audit, as the risk of a rug pull, which is a significant concern, was not explicitly highlighted in the reporrt.

eZKalibur argues that this issue should have been marked as “major” or even “critical” rather than a simple decentralization concern. In the absence of a timelock, such a vulnerability could lead to the immediate draining of all deposited funds, which is what transpired in the Merlin DEX exploit.

We did some research on Merlin smart contracts and we identified the malicious code responsible for the draining of funds.

These two lines of code in the initialize function are essentially granting approval for the feeTo address to transfer an unlimited (type(uint256).max)… pic.twitter.com/mIksh4HkhB

— eZKalibur ∎ (@zkaliburDEX) April 26, 2023

As the debate over the auditing process and centralization risks continues, blockchain data indicates that two addresses were responsible for the exploit. An address starting with 0x2744 took $850,000 USDC and bridged it to Ethereum, while another address, 0x2744d62, stole $844,000 USDC.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.


Credit: Source link

Related articles

BC.GAME Announces UFC Welterweight Champion Colby Covington as New Brand Ambassador

BC.GAME Announces UFC Welterweight Champion Colby Covington as New Brand Ambassador

December 10, 2024
Experts Expect A BTC Decline In December, Arbitrum and Lunex Network Continue To Rally

Experts Expect A BTC Decline In December, Arbitrum and Lunex Network Continue To Rally

December 10, 2024
ShareTweetSendPinShare
Previous Post

3.1 Trillion Tokens at Risk as Binance-Voyager Deal Fails

Next Post

Yuga Labs Triumphs in BAYC NFT Trademark Tussle

Related Posts

BC.GAME Announces UFC Welterweight Champion Colby Covington as New Brand Ambassador

BC.GAME Announces UFC Welterweight Champion Colby Covington as New Brand Ambassador

December 10, 2024

UFC Welterweight Champion Colby Covington officially joins BC.GAME as a brand ambassador. Covington's first collaborative event, the BC.GAME Wager Race...

Experts Expect A BTC Decline In December, Arbitrum and Lunex Network Continue To Rally

Experts Expect A BTC Decline In December, Arbitrum and Lunex Network Continue To Rally

December 10, 2024

The bull run is well underway, mirroring previous cycles to uncanny effect thus far. Some experts anticipate a Bitcoin cool-off...

Binance Pool Launches Luckycoin (LKY) Mining with Zero Fees

Binance Pool Launches Luckycoin (LKY) Mining with Zero Fees

December 10, 2024

Binance Pool has officially launched Luckycoin (LKY) merged mining, which allows miners to mine Litecoin (LTC) while earning rewards in...

What’s Next After 17% Dip?

What’s Next After 17% Dip?

December 10, 2024

Cardano (ADA) has dipped below the $1 level and is down by more than 17 percent in the last 24...

The Best Cryptocurrencies to Invest in Now | High-Potential Cryptos to Watch Before They Surge

The Best Cryptocurrencies to Invest in Now | High-Potential Cryptos to Watch Before They Surge

December 9, 2024

The cryptocurrency market is teeming with innovative projects that cater to diverse needs, ranging from decentralised finance (DeFi) to blockchain-powered...

Load More
Next Post
Yuga Labs Triumphs in BAYC NFT Trademark Tussle

Yuga Labs Triumphs in BAYC NFT Trademark Tussle

No Content Available
CryptoBangs.com

CryptoBangs.com is an online news portal that aims to share the latest crypto news, bitcoin, altcoin, blockchain, nft news and much more stuff like that.

What’s New Here!

  • Tucker Carlson and Roger Ver Reveal Shocking Details About US Extradition Battle and Bitcoin in Exclusive TCN Interview
  • Goldman Sachs eyeing crypto market-making for Bitcoin, Ethereum if US regulations shift
  • BC.GAME Announces UFC Welterweight Champion Colby Covington as New Brand Ambassador
  • How High Will Dogecoin Rise If the Markets ‘Go Wild’?

Newsletter

Don't miss a beat and stay up to date with our Newsletter!
Loading

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA
  • Disclaimer

© 2023 - CryptoBangs.com - All Rights Reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Crypto News
    • Bitcoin
    • Ethereum
    • Ripple
    • Altcoin
    • NFT News
  • DeFi
  • Blockchain
  • Regulation
  • Shop
  • Blog
  • Calculator

© 2018 JNews by Jegtheme.

Please enter CoinGecko Free Api Key to get this plugin works.
WP Twitter Auto Publish Powered By : XYZScripts.com