2022 Multichain Hack
Check if your address is affected.
Multichain, originally called Anyswap, was a popular service for moving tokens between blockchains. On 10 January 2022, security firm Dedaub privately reported two serious flaws in its contracts. One of them meant its routers did not properly check the tokens they were handed, so attackers could trick them into pulling WETH and other tokens from any wallet that had approved them. Multichain made the problem public on 17 January 2022 and urged users to revoke, but the announcement also alerted attackers, who started draining wallets right away.
Roughly $5.5M has been drained in total across several chains. Whitehat hackers, including security firm BlockSec, raced the attackers to move at-risk funds to safety. Some attackers also agreed to give most of their loot back: one returned 322 ETH but kept about $150k as a tip. In the end, roughly half of the drained funds were recovered, leaving around $3M with the attackers. Many users criticized Multichain for confusing communication while the attacks were ongoing.
Multichain never patched the vulnerable routers, which cannot be upgraded. In May 2023, its CEO was detained by Chinese police, and on 14 July 2023 Multichain announced it was ceasing operations. With nobody left to maintain these contracts, wallets that still have approvals to the old routers have kept getting drained, most recently in 2026. If you ever used Anyswap or Multichain on any chain, revoke your approvals to these routers now.
Affected users remain at risk as long as they haven't revoked their approvals, so it is recommended to use the Revoke.cash Exploit Checker below to make sure that you're safe.
Next time, revoke it automatically
Revoke Ultimate monitors your approvals around the clock and revokes them automatically when an exploit like this one is identified, even while you sleep.
See how Auto-Revoking works →