$126M Vanishes From Multichain's Bridges as Fantom and Moonriver Take the Hit
Multichain's addresses were drained of a combined $126M in the previous day's activity, wiping out roughly 50% of the FTM bridge's holdings and 80% of the Moonriver bridge's.
This is far from the project's first brush with disaster. Under its former name, Anyswap, the protocol was hacked for $8M nearly two years earlier. In early 2022, six of its multi-token contracts turned out to be exposed to an approvals-draining exploit that cost users an estimated $3M. Then, this past May, the team triggered widespread alarm over bridging delays, rumors of insider selling, and reports that staff had been detained, brushing the episode off with a vague reference to "force majeure."

01An unsettling official statement
This time, the project's own messaging did little to reassure anyone. Multichain said that assets locked in its MPC address had been moved to an unknown destination under abnormal circumstances, that the team did not yet understand what had happened and was investigating, and it advised all users to pause use of Multichain services and revoke any related contract approvals.
Fantom, which leans heavily on Multichain-issued versions of USDC, USDT, DAI, wETH and wBTC, also had no answers to offer at the time.
Given this track record, and the absence of a confirmed root cause, several theories are circulating: another test-in-production experiment from Andre Cronje's orbit gone wrong, the largest rug pull yet witnessed, or possibly the work of an unusually cautious whitehat.
02How the funds moved
Per analysis credited to Beosin, the large withdrawals first drew attention on social media, and early speculation tying the movements to Stargate/LayerZero's rollout of new FTM offerings was quickly dismissed by the LayerZero team itself.
While the precise attack method hasn't been confirmed, transaction behavior suggests the attacker had direct control over the relevant addresses. Possible explanations floated include a back-end compromise, private keys obtained through spearphishing, or involvement of a malicious insider. Notably, when Multichain (still called Anyswap at the time) was hacked previously, the attacker managed to reverse-engineer private keys by analyzing repeated transactions from the newly launched v3 router.
03Where the money sits
As of this writing, the exploiter-linked addresses hold a combined $126.3M:
- 0x9d5765ae1c95c21d4cc3b1d5bba71bad3b012b68 — $16.7M, including DAI, LINK, USDT and CRV
- 0xefeef8e968a0db92781ac7b3b7c821909ef10c88 — $30.1M in USDC
- 0x418ed2554c010a0c63024d1da3a93b4dc26e5bb7 — $13.4M in wETH
- 0x622e5f32e9ed5318d3a05ee2932fd3e118347ba0 — $30.9M in wBTC
- 0x48bead89e696ee93b04913cb0006f35adb844537 — $7.5M in USDC, USDT, DAI and wBTC drawn from Moonriver
- 0x027f1571aca57354223276722dc7b572a5b05cd8 — $27.7M in USDC
A complete asset breakdown is available here.
Despite the scale of the losses, none of the drained funds have been swapped or moved on since the withdrawals, which some observers interpret as evidence of whitehat involvement rather than malicious theft. Separately, more than half the total — around $65M — could potentially be frozen by Tether and Circle.

04Part of a broader pattern
This marks the second cross-chain bridge to land on the leaderboard within a single week, following the compromise of Poly Network's multisig the previous Saturday. It's yet another entry in the ongoing string of bridge failures, and a fresh reminder of Vitalik Buterin's longstanding caution that a multi-chain rather than cross-chain approach may be the safer path for the industry — a point underscored, ironically, by the name of today's victim.
As rekt observed following the Wormhole hack that exceeded $300M: in the rush toward newer and more lucrative opportunities across chains, many are quick to trust unproven technology, and when one of these bridging gateways fails, the resulting damage can be enormous.
Once again, a project tied to Andre Cronje's network of ventures — sometimes described as a decentralised monopoly — joins the leaderboard, alongside others that have appeared there more than once, including Yearn.
Get new scam files the moment we publish them — usually 2–3 emails a week.