OAK — OnChain Attack Knowledge

Worked example · 2023-07

Multichain — cross-chain bridge protocol — 2023-07-06

Loss
~$126M across the Multichain cross-chain bridge protocol; ~$120M from the Fantom bridge alone, with smaller drains from the Moonriver (~$6.8M) and Dogechain (~$0.66M) deployments. Affected assets included wETH, wBTC, USDC, DAI, and LINK.
Attribution
unattributed — the fund movements are unresolved in the public record (external MPC-compromise vs. insider / CEO-detention / possible authority-seizure vs. exit-scam), with no entity attribution and explicitly not Lazarus / OAK-G01. Consistent with the companion file examples/2023-07-multichain-mpc-bridge-verification-model-collapse.md.
OAK Techniques observed
OAK-T10.001 (Validator / Signer Key Compromise) — broadly construed; the bridge's MPC-based authorisation function ceased to be controlled by its publicly-claimed key-management posture, regardless of whether the precipitating event was external compromise or insider action. OAK-T7.001 (Mixer-Routed Hop — structured deposits into mixing infrastructure consistent with the post-Tornado-Cash G01 playbook); OAK-T7.003 (Cross-Chain Bridge Laundering — DEX-swaps to ETH then cross-chain hops via Tron / TRC-20 USDT as the primary laundering rail).
OAK-Gnn
No actor-group attribution. Not OAK-G01 Lazarus. Both an external-MPC-compromise hypothesis and an insider-action / wind-down-event hypothesis are publicly debated, and neither has been confirmed by a regulator or law-enforcement public statement — so OAK records this as unattributed rather than assigning any actor.
Off-OAK precondition
On May 21, 2023 Multichain CEO Zhaojun was arrested by Chinese police in Kunming; per Multichain team statements, hardware containing MPC key shares was confiscated, and the platform was unable to perform necessary technical maintenance after his arrest. This precondition is off-chain and out of OAK's on-chain Tactic scope, but it is load-bearing context for the July 6 incident's attribution-strength language.
Key teaching point
Multichain is OAK's canonical T10.001 inferred-weak example because the public record genuinely does not converge on a single attack narrative — and the framework is more useful for preserving that ambiguity than for resolving it. A worked example here that picked one hypothesis (external compromise, insider, or wind-down) would do exactly what the OAK attribution-strength tiers are designed to prevent: collapse a multi-hypothesis public record into a single narrative for narrative cleanliness, at the cost of misinforming downstream contributors about what is and is not known.

Summary

Multichain (formerly Anyswap) was a cross-chain bridge protocol whose authorisation function relied on a multi-party computation (MPC) signing scheme — key shares were distributed across multiple parties such that a threshold subset could collectively authorise outbound transfers from bridge-locked liquidity. On July 6, 2023, approximately $126M of locked assets were moved from Multichain MPC-controlled addresses to addresses not controlled by the publicly-known operator. The Fantom bridge was the largest single-deployment loss (~$120M); Moonriver and Dogechain deployments saw smaller but proportionally severe drains.

The incident sits in an unusual attribution-strength regime. The off-chain precondition is unambiguous on the public record: CEO Zhaojun was arrested on May 21, 2023, his hardware (containing MPC key shares per the team's own statements) was confiscated by Chinese authorities, and the global Multichain team lost the ability to operate or maintain the platform. The on-chain July 6 extraction event is consistent with at least three hypotheses:

  1. External compromise of MPC key shares whose secure custody had degraded after the CEO's arrest.
  2. Insider action by parties retaining residual MPC-share access — supported circumstantially by the post-event Singapore court proceedings (the Fantom Foundation pointed to the "sudden incorporation" of Multichain Pte Ltd shortly before the breach as evidence of intent), though the Singapore Judicial Commissioner explicitly ruled that this allegation was outside the scope of his decision.
  3. A downstream operational consequence of the CEO situation — e.g., a wind-down-style move of remaining assets executed by parties asserting some claim of authority, subsequently characterised as an exploit.

OAK does not adjudicate between these hypotheses. Under OAK-T10.001 broadly construed, the load-bearing observation is that the bridge's authorisation function ceased to be controlled by its publicly-claimed key-management posture — the defenders' threat model around "the MPC quorum is operated by Multichain's team" no longer described reality, regardless of which hypothesis explains why. Multichain announced cessation of operations on July 14, 2023, citing the CEO's continued detention, the additional detention of his sister on July 13 (after she had moved residual assets to wallets she controlled), and lack of operational funds.

Timeline (UTC)

When Event OAK ref
2023-05-21 Multichain CEO Zhaojun arrested by Chinese police in Kunming; hardware including devices holding MPC key shares confiscated (off-OAK precondition; off-chain)
2023-05-24 to 2023-05-27 Users report abnormal delays in cross-chain transfers; Binance suspends deposits of Multichain-bridged tokens (operational degradation; visible signal)
2023-06-04 Zhaojun's family regains access to the cloud-server platform hosting Multichain infrastructure via saved credentials from his personal computer (off-chain key-management posture in flux)
2023-07-06 ~$126M of locked assets moved from Multichain MPC-controlled addresses to addresses not controlled by the publicly-known operator; ~$120M from the Fantom bridge T10.001 extraction (broadly construed)
2023-07-07 Multichain confirms exploit across Fantom, Moonriver, and Dogechain bridges; services halted; bridge transactions stuck on source chains (public disclosure)
2023-07-09 (approx.) Zhaojun's sister moves residual assets to wallets she controls in an attempt to preserve them (contested-authority operational event)
2023-07-13 Zhaojun's sister taken into custody by Chinese authorities (off-chain)
2023-07-14 Multichain announces cessation of operations citing CEO's continued detention and lack of operational funds (organisational wind-down)
2024 onward Singapore court proceedings: Judicial Commissioner Mohamed Faizal rules Multichain owes Fantom Foundation ~$2.2M for July 2023 losses; allegation of asset diversion to Multichain Pte Ltd raised by Fantom but ruled outside scope (legal status; partial)
2025-05-09 Singapore Supreme Court (Justice Kwek Mean Luck) grants Sonic Labs' (formerly Fantom Foundation) request to declare Multichain Foundation bankrupt and appoint KPMG liquidators (legal status; liquidation)

What defenders observed

  • Pre-event (off-chain key-management posture degradation): The May 21 CEO arrest and the team's own subsequent statement that they could not contact him and "lost the platform's MPC keys" were the load-bearing pre-event indicator. From a defender's perspective, this is a category of signal — sudden discontinuity in the human and infrastructural custody of key shares — that does not show up in on-chain telemetry but should change the threat model for any party with exposure to the bridge.
  • Pre-event (visible operational degradation): The May 24–27 window of abnormal cross-chain delays and Binance's suspension of Multichain-bridged token deposits was a public, observable signal that the bridge's operational posture had deteriorated. Counterparties continuing to use the bridge after this signal were operating against a degraded threat model.
  • At-event (on-chain extraction): The July 6 outflows were detected by independent on-chain monitoring (CyVers and others) effectively in real time. As with Ronin, the extraction transactions themselves were authorised by the bridge's threshold-signing mechanism — they were on-chain-indistinguishable from legitimate operator-authorised transfers. The detection signal was anomaly-against-baseline (size, destination clustering), not protocol-violation.
  • Post-event (attribution did not converge): Unlike Ronin (FBI / Treasury attribution within ~3 weeks) or even WazirX (industry forensic providers converged on OAK-G01 within months), Multichain's attribution did not converge to a single hypothesis on the public record. The Singapore court ruling fanned suspicions of an inside job without confirming it; the wind-down hypothesis remains live; an external-compromise hypothesis is also publicly defensible. This non-convergence is itself the defender-relevant observation.

What this example tells contributors writing future Technique pages

  • T10.001 broadly construed accommodates the full key-share-control-loss class. The public-record uncertainty about external-compromise vs insider-action vs wind-down at Multichain is real and not resolvable from on-chain data alone. Contributors writing future T10.001 examples should not force a single attack-narrative when the public record does not support one — the load-bearing observation is that the bridge's authorisation function ceased to be controlled by its publicly-claimed key-management posture, and this can be catalogued under T10.001 without adjudicating the precipitating mechanism.
  • Attribution-strength language matters more than attribution itself for cases like this. Multichain is the canonical OAK case for inferred-weak attribution: industry coverage describes both insider and external hypotheses; the Singapore court explicitly declined to rule on diversion; no regulator or law-enforcement public statement attributes the on-chain event to a specific actor. Contributors should mark this case inferred-weak and preserve the multi-hypothesis framing rather than collapsing it for narrative cleanliness. The OAK attribution-strength tiers (confirmed / inferred-strong / inferred-weak) exist precisely so that this case can be catalogued without overstating what is known.
  • MPC key-share recovery is a distinct wind-down risk. Standard threat models for MPC-based bridges focus on adversarial compromise of key shares. Multichain illustrates a different failure mode: graceful degradation of the human-and-hardware custody posture for key shares, where no single key-share has been adversarially extracted but the operator is no longer in a position to execute the threshold-signing protocol as designed. Contributors writing T10 examples for MPC-based architectures should call out custody continuity (operator availability, hardware recoverability, key-share rotation procedure under operator-loss conditions) as a distinct risk dimension from share-extraction adversarial compromise.
  • Insider-vs-external attribution can remain genuinely undetermined. The Multichain case should be cited when contributors are tempted to force a binary classification on cases where the public record does not support one. Preserving the uncertainty is itself the defender-relevant artefact — it informs how downstream actors (counterparty exchanges, restitution-claim filers, bridge-class threat-modellers) calibrate their response.

Public references

  • [chainalysismultichain2023] — Chainalysis primary forensic write-up (loss size, MPC-architecture description, hack-vs-rug-pull framing).
  • [halbornmultichain2023] — Halborn technical analysis (Fantom-bridge focus, MPC-share compromise mechanism).
  • [dlnewsmultichain2023] — DL News coverage of the Singapore court ruling and the Fantom Foundation's diversion allegation (ruled outside scope by Judicial Commissioner Faizal).
  • [chainalysis2024laundering] — broader cross-chain laundering context (used as the standing OAK reference for downstream T7.003 patterns; not a primary Multichain source).

Discussion

Multichain is OAK's canonical T10.001 inferred-weak example because the public record genuinely does not converge on a single attack narrative — and the framework is more useful for preserving that ambiguity than for resolving it. A worked example here that picked one hypothesis (external compromise, insider, or wind-down) would do exactly what the OAK attribution-strength tiers are designed to prevent: collapse a multi-hypothesis public record into a single narrative for narrative cleanliness, at the cost of misinforming downstream contributors about what is and is not known.

The case also extends the T10.001 frame in a way contributors should preserve. Ronin and WazirX both fit the standard adversarial-key-compromise mental model: a specific actor obtained key-share access via a specific entry vector and executed an extraction transaction. Multichain's load-bearing observation is structurally different: the bridge's authorisation function ceased to be controlled by its publicly-claimed key-management posture, and OAK catalogues that fact without specifying the mechanism. Contributors writing future MPC-based bridge cases should be prepared for both shapes — the Ronin / WazirX shape (adversarial entry vector, executable narrative) and the Multichain shape (operator-side custody discontinuity, multi-hypothesis on-chain event) — and should not force one into the other's frame.

A reasonable open question for future OAK iterations is whether the Multichain shape eventually warrants its own sub-Technique under T10 — something like "T10.001.x Operator-Side Custody Discontinuity" — distinct from adversarial share-compromise. At v0.1 the broadly-construed T10.001 mapping is preferred because the on-chain manifestation (threshold-authorised outbound transfer to non-operator-controlled addresses) is the same regardless of mechanism, and creating a sub-Technique would imply a confidence in mechanism-classification that the public record does not support.

Techniques demonstrated (3)