Multichain Collapse: The Private Key Leak That Drained $125M+

Research Incident Analysis
Multichain Collapse: The Private Key Leak That Drained $125M+

Project name: Multichain

Project type: Bridge

Date of exploit: July 6, 2023

Asset loss: More than $125M

Vulnerability: Private Key Issue

Date of audit report publishing:

  • Nov 11, 2022: MultiChain Foundation - Cardano (Golang)
  • Nov 21, 2022: MultiChain Foundation - Aptos (Move)

Conclusion: Out of Audit Scope

Details of the Exploit

Background

Multichain is a centralized cross-chain bridge protocol that allows users to bridge tokens between chains.

Nature of the Vulnerability

  • The private key of Multichain is compromised, allowing the attacker to drain assets from the bridge protocol

CertiK Audit Overview

Screenshot 2024-01-08 at 6.04.37 AM

Conclusion

On July 6, 2023, the cross-chain bridge protocol Multichain experienced large unauthorized withdrawals, suggesting a likely Private Key issue.

It is identified as an out-of-scope issue since it is not an implementation bug.

Related Blogs

How to Prepare for a CCSS Audit

How to Prepare for a CCSS Audit

Institutional counterparties ask crypto businesses a hard question: how do you safeguard your private keys? A bank wants evidence before it opens an account. A fund wants it before it deposits assets. The CryptoCurrency Security Standard (CCSS) exists to answer that question with an audit instead of a claim. This guide explains what the standard covers, how certification works and how you prepare for it.

Resolv Protocol Incident Analysis

Resolv Protocol Incident Analysis

On 22 March 2026, the Revolv protocol was exploited, resulting in a loss of ~$26.8M due to a compromise of the project's cloud infrastructure which gave access to Resolv’s AWS Key Management Service (KMS).

Skynet Wrench Attacks Report

Skynet Wrench Attacks Report

In 2025, wrench attacks unfortunately crossed a critical threshold. What was once treated as an edge-case risk has become a structural threat to digital asset ownership. Attackers are no longer acting opportunistically; they are operating as organized, transnational groups that combine OSINT-driven targeting, social engineering, and extreme physical violence to extract private keys.