Cointime

Download App
iOS & Android

Internal Rug Pull Confirmed in Merlin DEX Incident, CertiK Recovers $160K of Stolen Funds

May 5 (Cointime) - Blockchain cybersecurity firm, CertiK, has provided an update on the Merlin DEX incident that occurred on April 25th. The incident involved an internal rugpull by Merlin insiders, who took $1.8M of their users' funds by abusing the owner wallet's privileges.  

Last week, Cointime reported that Merlin, the DEX built on ZkSync, has experienced a liquidity drain. Merlin had recently undergone a CertiK audit and launched a public sale on April 24.

So far, $160K of the stolen funds have been frozen with the help of partners, and the company will continue to monitor the movement of all stolen funds in an attempt to freeze and recover the remaining amount.    

According to the tweet thread,  CertiK initially tried to collaborate with the remaining members of the Merlin team to aid victims, but encountered difficulties due to several core members' unwillingness to verify their true identities. As a result, CertiK is now focusing on working with law enforcement and has submitted information to relevant US and UK agencies. The firm is also exploring all possibilities to fight exit scams with the $2M they have committed. 

CertiK has admitted that although the centralization risks were called out in the report, the impact of these findings was not made clear enough. The firm stated:

"The centralized privileges should have been distinctly highlighted so users were aware of the risks. Going forward, CertiK will prioritize centralization risks in audit summaries to ensure users have a complete picture of potential risks."

Read the full thread:

This lack of cooperation has complicated our efforts to validate and aid victims. We are focusing on working with law enforcement and have submitted information to relevant US & UK agencies.

We are exploring all possibilities to fight exit scams with the $2M we’ve committed.

We have successfully frozen $160K of the stolen funds with the help of partners. We will continue to monitor the movement of all stolen funds in an attempt to freeze and recover the remaining amount.

Although the centralization risks were called out in the report, we didn’t make the impact of these findings as clear as they needed to be.

The centralized privileges should have been distinctly highlighted so users were aware of the risks.

Going forward, CertiK will prioritize centralization risks in audit summaries to ensure users have a complete picture of potential risks.

We recognize that audit reports can be highly technical documents, and it’s our job to communicate the risks clearly and transparently.

To clarify: the $2 million we have pledged will be used to fight exit scams as well as help scam victims

Comments

All Comments

Recommended for you

  • Bitpanda receives broker-dealer license from Dubai Virtual Assets Authority

    Bitpanda, headquartered in Vienna, has obtained a broker-dealer license from the Dubai Virtual Asset Regulatory Authority (VARA).

  • US artificial intelligence startup Yutori raises $15 million

    Yutori, a startup based in San Francisco, has raised $15 million for the development of an artificial intelligence personal assistant.

  • Meme incubation platform Coresky completes $15 million Series A financing

    Meme incubation platform Coresky announced the completion of a $15 million Series A financing round, led by Tido Capital, with WAGMi Ventures, Copilot Venture Studio, Web3 Vision Fund, and Parallel Ventures participating. The valuation information has not been disclosed, and the company's total financing to date has reached $21 million.

  • Vest Labs Completes $5 Million Seed Round of Financing, with Amber Group, QCP Capital and Other Investors

    Vest Labs, a financial infrastructure company based on real-time risk pricing, has announced the completion of a $5 million seed round financing, with participation from Jane Street, Amber Group, Selini Capital, QCP Capital, and Big Brain Holdings. The new funds will be used to support its construction of a real-time, verifiable risk pricing model based on zero-knowledge proofs to enhance financial market transparency and efficiency, and will also launch a perpetual futures trading platform supporting Arbitrum, Solana, Base, and other L2 solutions.

  • Digital asset high-frequency trading company ABEX completes new round of financing of US$6 million

    ABEX, a digital asset high-frequency trading company based in London, United Kingdom, announced the completion of a $6 million financing round, led by MMC Ventures. The new funds are intended to be used for the launch of derivative trading and algorithmic execution solutions to improve the transaction execution efficiency of centralized and decentralized financial venues. It is reported that the company is registered with the Financial Conduct Authority (FCA) in the United Kingdom, allowing it to engage in cryptocurrency trading activities.

  • The market value of BSC ecosystem meme coin BUBB hit a record high of US$35 million, with a 24-hour increase of 516%.

    On March 21st, according to GMGN market information, the BSC ecosystem meme token BUBB reached a market value of 35 million USD in a short time, hitting a historic high, and is currently at 31.3 million USD, with a 24-hour increase of 516% and a 24-hour trading volume of 41.7 million USD.

  • Decentralized identity management platform Via Science completes $28 million Series B financing, led by Bosch Ventures

    decentralized identity management platform Via Science has completed a $28 million Series B financing round, led by Bosch Ventures, with participation from BMW i Ventures, MassMutual Ventures, Sentinel Global, and Westly Group. It is reported that Via Science's decentralized, zero-trust architecture has been tested by the US Department of Defense and, unlike any other Web3 technology, its combination of end-to-end post-quantum encryption can ensure access and privacy for the authorizer.

  • A certain whale's 5x MELANIA long position has not changed for the time being, and the position of 3.86 million MELANIA has now suffered a floating loss of nearly $100,000

    according to on-chain analyst @ai_9684xtpa monitoring, the 5x MELANIA long position of the Hyperliquid 50x leverage profit of 16 million US dollars whale has not changed, with a position of 3.86 million tokens now floating a loss of nearly 100,000 US dollars

  • Multi-engine Web3 gaming platform PlaysOut completes $700 million seed round of financing, led by Kenetic Capital

    the multi-engine Web3 gaming platform PlaysOut has announced the completion of a $7 million seed round of financing, led by Kenetic Capital, KBW Ventures, Gam3Girl Ventures, Oak Grove Ventures, Aptos, Yugana Labs, Sentor Investments, and Longling Capital, with a valuation of $70 million. The new funds are intended to drive its efforts to bridge the gap between Web2 and Web3, enabling developers to unlock monetization models by building assets on-chain and exploring token-based incentives, NFT integration, and blockchain-driven economies.

  • CertiK Chief Security Officer: The number of security incidents as of September 2023 has exceeded the total in 2022

    On October 23, at the ETH HK Side Event, a Web3 ecosystem security forum jointly held by CertiK and OKLink in Causeway Bay, Hong Kong, Professor Li Kang, Chief Security Officer of CertiK, shared his views on digital asset security construction. He pointed out that according to CertiK's statistics, the number of security incidents as of September 2023 has exceeded the total number in 2022. Hacking attacks and fraudulent behavior are still important threats, seriously hindering the development of the Web3 industry. Li Kang also mentioned the revolutionary feature of transparency in the Web3 field. The entire ecosystem can reduce security risks through public and transparent measures, such as asset management solutions. At the event, leaders from the Hong Kong Investment Promotion Agency, OKLink, and BlockSec shared their related work and latest developments in Web3 security construction. For example, CertiK and OKLink have received responses from multiple exchanges in asset tracking locking and data labeling. Finally, Li Kang hopes to further strengthen Hong Kong's position as a Web3 innovation gateway in the rapidly growing Asia-Pacific region through this sharing, and jointly promote the safe application and landing of Web3 technology.