Back to all stories
Blogs
Incident Analysis
Multichain Collapse: The Private Key Leak That Drained $125M+
1/8/2024
Multichain Collapse: The Private Key Leak That Drained $125M+

Project name: Multichain

Project type: Bridge

Date of exploit: July 6, 2023

Asset loss: More than $125M

Vulnerability: Private Key Issue

Date of audit report publishing:

  • Nov 11, 2022: MultiChain Foundation - Cardano (Golang)
  • Nov 21, 2022: MultiChain Foundation - Aptos (Move)

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Multichain is a centralized cross-chain bridge protocol that allows users to bridge tokens between chains.

Nature of the Vulnerability

  • The private key of Multichain is compromised, allowing the attacker to drain assets from the bridge protocol

CertiK Audit Overview

Screenshot 2024-01-08 at 6.04.37 AM

Conclusion

On July 6, 2023, the cross-chain bridge protocol Multichain experienced large unauthorized withdrawals, suggesting a likely Private Key issue.

It is identified as an out-of-scope issue since it is not an implementation bug.

;