CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

zkSync DEX Merlin Exploited for Over $1.8M After Code Audit

April 26, 2023
in Crypto News
Reading Time: 3 mins read
A A
0
Uptober Turns to Hacktober as Crypto Exploits Skyrocket
0
SHARES
6
VIEWS
ShareShareShareShareShare

RELATED POSTS

European Authorities Bust $815M Crypto Fraud Ring, Arrest Nine Across Border

Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala

Polish PM Claims Russia Influence Blocked Crypto Bill

Ethereum-based decentralized exchange (DEX) Merlin, which uses zero-knowledge sync (zkSync), has lost more than $1.8 million in a liquidity pool exploit hours after smart contract security firm CertiK audited its code.

The hack occurred on Wednesday morning during the public sale of Merlin’s native token, MAGE, with the attacker siphoning several assets, including USD Coin (USDC), Ether (ETH), and other illiquid tokens.

Merlin’s LP Drained After Code Audit

A few hours after the exploit, CertiK tweeted that it was investigating the incident and working to understand its impact on the community. The security firm disclosed that its initial findings suggested that a private key management issue may have led to the hack and not an exploit, as widely believed.

CertiK said it pointed out the centralization risk in the recent audit report for Merlin under the “Decentralization Efforts” section. The firm insisted that while audits could not prevent private key issues, they always ensured to highlight better practices for projects.

As claimed in the audit dated April 24, 2023, CertiK recommended that Merlin improve its centralized roles to a decentralized mechanism like multi-signature wallets to enhance security practices. The firm also asked the protocol to implement a timelock feature with a latency of at least 48 hours to avoid a single point of key management failure. CertiK has also promised to work with appropriate authorities if any foul play is discovered.

“We encourage all community members to review this information and all audits fully. As we navigate this challenging situation, we want to assure you that we are taking all necessary measures to protect our community’s interests,” CertiK said.

Malicious Code Detected

Interestingly, eZKalibur, another zkSync DEX and launchpad, revealed it had identified the malicious code that enabled the hackers to drain Merlin’s funds. The DEX said it found two lines of code in the initialize function that gave the feeTo address approval to transfer an unlimited amount of tokens from the contract’s address.

📢 We did some research on Merlin smart contracts and we identified the malicious code responsible for the draining of funds.

These two lines of code in the initialize function are essentially granting approval for the feeTo address to transfer an unlimited (type(uint256).max)… pic.twitter.com/mIksh4HkhB

— eZKalibur ∎ (@zkaliburDEX) April 26, 2023

Meanwhile, the Merlin team has asked users to revoke access to the connected site on their wallets as they analyze the cause of the exploit.

SPECIAL OFFER (Sponsored)

Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.


Credit: Source link

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

Chainlink partners GMX DAO to revolutionize $487 trillion market

Next Post

Merkle Trade Launches First Trading Contest with a $3,000 Prize Pool

Related Posts

62 People Arrested in Turkey, Allegedly Connected to the Thodex Exchange Heist
Crypto News

European Authorities Bust $815M Crypto Fraud Ring, Arrest Nine Across Border

December 8, 2025
Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala
Crypto News

Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala

December 8, 2025
Polish PM Claims Russia Influence Blocked Crypto Bill
Crypto News

Polish PM Claims Russia Influence Blocked Crypto Bill

December 8, 2025
Next Post
Merkle Trade Launches First Trading Contest with a $3,000 Prize Pool

Merkle Trade Launches First Trading Contest with a $3,000 Prize Pool

Top US Crypto Exchange Coinbase Adds Little-Known Web3 Altcoin to Its Listing Roadmap

Cronos (CRO) Rallies After Revealing Partnership With Amazon Web Services

Recommended Stories

No Content Available

Popular Stories

  • Ethereum’s Highly Awaited “London Hard Fork” Is Now Alive

    Ethereum.org (ETH) Celebrates Success with 2024 Translatathon

    0 shares
    Share 0 Tweet 0
  • XRP Bulls Battle To Defend 2020 Highs, These Are The Levels to Watch

    0 shares
    Share 0 Tweet 0
  • Cardano (ADA) Metaverse Launches With Thousands Investing in Its Digital Real Estate

    0 shares
    Share 0 Tweet 0
  • Turkey Names Blockchain Expert to Central Bank Committee

    0 shares
    Share 0 Tweet 0
  • El Salvador buys 420 Bitcoin as asset regains $60,000

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • How crypto derivatives liquidation drove Bitcoin’s 2025 crash
  • Robinhood Charges Into Indonesia as Next Explosive Crypto Market
  • Exploring Chainlink’s Role Beyond Price Feeds in the Blockchain Ecosystem

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.