QUADRIGA INITIATIVE
CRYPTO WATCHDOG & FRAUD RECOVERY PLATFORM
A COMMUNITY-BASED, NOT-FOR-PROFIT
$257 000 USD
FEBRUARY 2021
GLOBAL
MULTI FINANCIAL
DESCRIPTION OF EVENTS
"Multi.Financial is an automated market maker (AMM) aggregator and yield farming project providing decentralised loans secured through MULTI on Binance Smart Chain (BSC). We created this project to improve the availability of credit on BSC, as we felt the options for decentralised loans were limited within the BSC ecosystem."
"Additionally, we will release a decentralised exchange (DEX) based on Ethereum’s Uniswap. This has been re-architected and designed around BSC, providing users with the benefits of the lower fees intrinsic to BSC and provide a valuable service to the wider DeFi ecosystem."
"It is said that Binance Smart Chain investors reported that on February 1, another "earth dog" project, Multi Financial, ran away on BSC, and it took about 5000 BNB in just one day. The compromised investor stated that it had reported that Binance had blocked the address of the project party and reported to the police."
"The `delegatecall()` function calls functions from other contracts as if they belong to the caller contract. Thus the callee may change the state of the calling address. This may be insecure." "The backdoor was in the getReward() function, this function was using delegatecall (Huge Red Flag) . DELEGATECALL basically says that I'm a contract and I'm allowing another contract to do whatever it wants to my storage. Here, it delegated this power to the loansFactory wich was not set in the beginning. The deployer sets it with this tx https://bscscan.com/tx/0x29e0cf21a42ffa5174ce9543bf12ee625dbd62b17a6271df08cb227ea70a551a and therefore the contract at the address 0x55736853bb3e8cf40bec933757fe5cde80e68e34 was able to change the rewards. When the dev called the getReward function, it called the loansFactory which sets the rewards to all the LPs in the SC. The dev did the same for all the available pools."
Multi Financial existed for all of 3 days, and obtained a reported 5000 BNB from investors.
While Twitter and the site were deleted, their single Medium post is still present online.
Example Domain (Mar 23)
SlowMist Hacked - SlowMist Zone (May 18)
Multi.financial – Medium (Jul 18)
How to identify malicious contract on Binance Smart Chain - Binance Smart Chain (BSC) | BNBsmartchain.com (Jul 18)
@financial_multi Twitter (Jul 18)
@SensoYard Twitter (Jul 18)
Address 0xa9904d4998d8a5f846cf77e72f1fe8e4014f0831 | BscScan (Jul 18)
MULTI.financial (MULTI) Token Tracker | BscScan (Jul 18)
MULTI.financial (MULTI) ERC20 Token Analytics | Binance Smart Chain Mainnet | Bitquery (Jul 18)
How to identify malicious contract on Binance Smart Chain (Jul 18)
MULTI Finance (Jul 18)
Popcornswap, SharkYield, Zap Finance, Tin Finance, Multi Financial — осторожно (Jul 10)
Worldwide crypto & NFT rug pulls and scams tracker - Comparitech (Dec 15)