Cointime

Download App
iOS & Android

Internal Rug Pull Confirmed in Merlin DEX Incident, CertiK Recovers $160K of Stolen Funds

Cointime Official

May 5 (Cointime) - Blockchain cybersecurity firm, CertiK, has provided an update on the Merlin DEX incident that occurred on April 25th. The incident involved an internal rugpull by Merlin insiders, who took $1.8M of their users' funds by abusing the owner wallet's privileges.  

Last week, Cointime reported that Merlin, the DEX built on ZkSync, has experienced a liquidity drain. Merlin had recently undergone a CertiK audit and launched a public sale on April 24.

So far, $160K of the stolen funds have been frozen with the help of partners, and the company will continue to monitor the movement of all stolen funds in an attempt to freeze and recover the remaining amount.    

According to the tweet thread,  CertiK initially tried to collaborate with the remaining members of the Merlin team to aid victims, but encountered difficulties due to several core members' unwillingness to verify their true identities. As a result, CertiK is now focusing on working with law enforcement and has submitted information to relevant US and UK agencies. The firm is also exploring all possibilities to fight exit scams with the $2M they have committed. 

CertiK has admitted that although the centralization risks were called out in the report, the impact of these findings was not made clear enough. The firm stated:

"The centralized privileges should have been distinctly highlighted so users were aware of the risks. Going forward, CertiK will prioritize centralization risks in audit summaries to ensure users have a complete picture of potential risks."

Read the full thread:

This lack of cooperation has complicated our efforts to validate and aid victims. We are focusing on working with law enforcement and have submitted information to relevant US & UK agencies.

We are exploring all possibilities to fight exit scams with the $2M we’ve committed.

We have successfully frozen $160K of the stolen funds with the help of partners. We will continue to monitor the movement of all stolen funds in an attempt to freeze and recover the remaining amount.

Although the centralization risks were called out in the report, we didn’t make the impact of these findings as clear as they needed to be.

The centralized privileges should have been distinctly highlighted so users were aware of the risks.

Going forward, CertiK will prioritize centralization risks in audit summaries to ensure users have a complete picture of potential risks.

We recognize that audit reports can be highly technical documents, and it’s our job to communicate the risks clearly and transparently.

To clarify: the $2 million we have pledged will be used to fight exit scams as well as help scam victims

Comments

All Comments

Recommended for you

  • BTC breaks through $69,000

     the market shows BTC breaking through $69,000, currently at $69,021.49, with a 24-hour increase of 1.15%. The market is highly volatile, please manage your risk accordingly.

  • Spanish Foreign Minister: Not worried about any consequences of refusing US access to military bases

     on March 3 local time, Spanish Foreign Minister Alvarez defended the Spanish government's refusal to provide the Rota and Moron military bases to the United States for participation in attacks on Iran. Alvarez stated that the operation initiated by the United States and Israel is not supported by the United Nations and is not part of the bilateral agreements allowing the use of the aforementioned Spanish sovereign military bases. Alvarez also said that the Spanish government is not concerned that this stance will have any consequences. Alvarez stated: "The position of the Spanish government represents the will of the vast majority of the Spanish people as well as the vast majority of people worldwide, which is to defend the UN Charter, respect international law, and believe that cooperation is always more powerful than confrontation."

  • Spot gold plunges nearly $100 in the short term.

     spot gold plunged nearly 100 dollars in a short time, spot gold fell below 5170 dollars/ounce, with a daily decline of 2.94%. 

  • BTC falls below $67,000

    the market shows BTC fell below $67,000, currently at $66,996.93, with a 24-hour increase of 1.18%. The market is highly volatile, please manage your risk accordingly.

  • ETH breaks $2,000

    the market shows ETH breaking through $2000, currently at $2001.64, with a 24-hour increase of 2.89%. The market is highly volatile, please manage your risks accordingly.

  • The US spot Bitcoin ETF saw a net inflow of $962.48 million yesterday.

    according to Trader T's monitoring, the US spot Bitcoin ETF had a net inflow of 962.48 million USD yesterday.

  • BTC falls below $66,000

     the market shows BTC fell below 66,000 USD, currently at 65,986.66 USD, with a 24-hour decline of 1.31%. The market is highly volatile, please manage your risks accordingly.

  • BTC falls below $66,000

     the market shows BTC fell below $66,000, currently at $65,973.16, a 24-hour drop of 2.66%. The market is highly volatile, please manage your risks accordingly.

  • ETH breaks $2,000

    market shows ETH breaking through $2000, currently at $2000.29, with a 24-hour increase of 3.73%. The market is volatile, please manage your risk accordingly.

  • The United States uses Anthropic's artificial intelligence technology in its airstrikes in the Middle East.

     United States used Anthropic's artificial intelligence technology in airstrikes in the Middle East, and just hours before the attack, Trump had just issued a ban against Anthropic.