Multichain's Detained CEO Leaves an Entire Bridge — and the Fantom Chain — in Limbo
The speculation has been confirmed: Multichain's founder, known online as Zhaojun, has reportedly been held by Chinese authorities since May 21st, according to a statement from the project itself.
Because Zhaojun controlled the cryptographic keys to the protocol's MPC wallets, his detention has left the bridge effectively unable to operate. Every device with wallet access is said to now be in the custody of Chinese authorities, with a single exception: one computer belonging to Zhaojun's sister, who is also reported to have since been detained.

This contradicts claims made in Multichain's own documentation, which stated that "the SMPC nodes are run by different organisations, institutions and individuals." In practice, the setup was far more centralized than advertised — an operational security failure that has now paralyzed a core piece of DeFi infrastructure.
Fantom was especially exposed, since the chain relied on Multichain-wrapped versions of USDC, USDT, DAI, wETH and wBTC. As the crisis unfolded, all of those wrapped assets lost their pegs, and Fantom's ecosystem has largely emptied out as a result.
01Timeline of the collapse
Rumors first surfaced on May 23rd after a delayed upgrade broke functionality on some bridging routes. Speculation about an insider selling tokens, fueled by an ambiguously translated Chinese-language tweet, briefly raised fears that the protocol's entire TVL was at risk.
Multichain did not offer a clear explanation at the time, attributing the disruption to "force majeure." The panic eased once the bridges kept functioning and fixes rolled out to the remaining routes.
According to the team's latest statement, Zhaojun's family had allowed Multichain engineers physical access to his home computer solely to repair Router2 and Router5. Control was never actually transferred to the rest of the team, who were reportedly told that Zhaojun would be released soon and were asked to keep maintaining the system in the meantime.
Then came a nine-figure shock, followed days later by another large outflow — a clear sign that something had gone badly wrong.
Two withdrawals stand out: $126M on July 6th (of which roughly $65M has since been frozen) and $103M on July 10th. Per the team's account, the first was a hack originating from "an IP address in Kunming," while the second was framed as a rescue operation. Because Fantom-based wrapped assets have fallen 80-90% in value, the $103M "rescued" sum is now worth only about $69M at current prices. A separate wallet, also attributed to funds recovered by Zhaojun's sister, holds roughly $75M.
The team's newest disclosure ends a silence that had lasted since July 7th, when the earlier incident went unaddressed. Whether this account is accurate or the whole affair is simply an elaborate rug pull remains an open question — Multichain would hardly be the first project to dress up a collapse with a dramatic narrative. Regardless of motive, Multichain is again telling users to avoid interacting with its contracts, and says it hopes to take the front end offline, though it claims it no longer even controls the domain account.
02Fantom bears the brunt
The chain that suffered most from this mess is Fantom, whose users had been directly reassured by the Fantom Foundation itself. On June 1st, in an apparent effort to head off an exodus, the Foundation posted that Fantom relies on the "regular bridge and router 1," that Multichain's CEO has no admin control over either, and that his absence would not affect the safety of Fantom's assets or bridging.
Yet the Foundation's own actions suggest it wasn't so confident: partnerships with LayerZero (whose team is now taking a victory lap) and Axelar went live on July 6th — the exact day $126M disappeared from Multichain. If the Foundation had enough doubt to line up two alternative bridge providers, why continue vouching for Multichain publicly? And if leadership suspected trouble, why leave users exposed?

It's striking that an entire ecosystem entrusted its bridging infrastructure to one provider, especially given that this same provider (then called Anyswap) had already been hacked two years earlier, without a backup plan ever being built. Fantom's users are the ones paying the price now, having followed a bridge that assured them of safety right up until there was no way out. Geist, Fantom's Aave fork, has already announced it will shut down, since its Chainlink price feeds track native assets and no longer reflect the depegged Multichain tokens. More protocols on the chain may follow before this settles.
03An audit blind spot
Multichain reportedly passed eight audits, yet none of them examined the off-chain custody and key-management practices that ultimately caused this collapse — a gap that may fall outside a typical audit's scope, but is glaring in hindsight. As security researcher Mikko Ohtamaa put it, auditors who treat themselves as untouchable experts deserving huge fees for low-quality work don't deserve to be called security providers at all.
The community should push auditors toward a more comprehensive standard — a Solidity code checklist alone isn't sufficient, and auditors know it. But as long as "test in production" culture around celebrated developers persists, cutting corners will keep paying off.
As rekt has written before: put your trust in idols, and you will get burned. Yearn (twice), CREAM (twice), and Anyswap-turned-Multichain have all landed on the leaderboard — and now Fantom finds itself collateral damage. Coincidence, or the so-called Cronje Curse?
Get new scam files the moment we publish them — usually 2–3 emails a week.