Dilation Effect Research: Contract Approval Risks in the Main Wallets of Binance, KuCoin, and Jump
This article is jointly published by Dilation Effect and WuBlockchain. Original Article Link: https://twitter.com/dilationeffect/status/1663136716662915073 Mainstream exchanges and institutions undoubtedly invest significant resources in network security. Dilation Effect cannot ascertain the internal security levels and implementation details of these institutions. Out of curiosity, we attempt to analyze the wallet addresses of these institutions based on publicly available information. By observing the subtle details, we consider whether these addresses pose potential security risks from the perspective of ordinary users and assess the extent of potential risk exposure. The data for this flash analysis is sourced from public services such as Etherscan and Debank. 1. Selection of Analysis Targets We examine the Top 1000 Accounts on Etherscan and select the tagged institutional addresses. 2. Selection of Analysis Dimensions Given the lack of understanding regarding the technical details of wallet generation and management by these exchanges and institutions, how can we analyze the security of these addresses? In this analysis, Dilation Effect focuses on analyzing the contract approval status of these addresses. It is common for addresses to be deceived by malicious contracts or to fall victim to vulnerabilities in approved contracts, resulting in stolen funds. Limiting approval amounts and regularly cleaning up approvals have become best security practices. So how do these large exchanges handle the approval of their addresses? Let’s randomly select a few addresses for analysis. Case 1 Address: Binance 8 (0xF977814e90dA44bFA03b6295A0616a897441aceC) This is the largest wallet address in terms of balance on Binance, with a total balance of $10 billion on the Ethereum and $16.1 billion across other chains. The screenshot of some assets is as follows: When examining the contract approval status of this address on the Ethereum, it indicates a potential risk of $3.2 billion. However, this does not necessarily imply a definite security risk; it is merely a description of the potential risk exposure. Let’s take a closer look at how this address handles approvals, such as which tokens are approved to which contracts and the approval amounts. The following are selected excerpts from the query results: At this point, we notice a peculiar phenomenon: some tokens on this address have limited approval amounts, while others have unlimited approval amounts. The approval amount rules do not appear to be consistent. We pay special attention to the tokens with significant balances: BUSD, Matic, SHIB, and SAND. The balances for these tokens are $1.9 billion, $460 million, $260 million, and $140 million, respectively. The related approval records are as follows: There are several obvious issues: First, there is no regular cleaning of approvals for contracts. For example, regarding the approval for BUSD, more than two years have passed without any cleanup. This indicates that Binance lacks comprehensive system coverage in managing this aspect of internal security. Some may argue that an analysis of the relevant approved contracts revealed limited operations that can be performed, thus relatively safe. However, we want to emphasize that this is not simply a technical issue; it is more a matter of security management. Specifically, how Binance can comprehensively and systematically manage the risks associated with third-party contracts. We believe that a more rigorous and in-depth approach is possible. In fact, if you look closely, you’ll find that Aave: Lending Pool V2 is an upgradable proxy contract. Suppose (and this is purely hypothetical) the Aave contract were to be attacked. In that case, a loss of $1.9 billion would occur. Second, a large number of cryptocurrencies have unlimited approval limits. In the event of an extreme scenario where the corresponding contract is attacked, having limits on the approval amount would reduce the risk accordingly. This also highlights the lack of systematic coverage in Binance’s internal security management in this aspect. Of course, one could argue that these are extreme cases, but in the history of the crypto industry, many low-probability events have occurred. We need to increase our sensitivity to risks and maintain a strong aversion to risk, which is essential. Third, there is no uniformity in the approval rules for different cryptocurrencies. Some cryptocurrencies have limits on the approval amount, while others have no restrictions at all, indicating a lack of clear internal security management operations or coordination within the internal team at Binance. Additionally, we are curious as to why addresses with such significant asset balances frequently engage in DeFi contract operations. Can Binance implement more granular address planning and isolation designs? Reply from Binance: The team is optimizing the stake process to reduce any potential smart contract risks. The security team has set different authorization limits for different currencies, and will revoke the stake permission after each contract is completed. But Binance want to clarify that in different stake projects, different restrictions will be set for different coins, so the authorization rules for a certain coin/project will not be completely consistent. Case 2 Address: Kucoin 6 (0xD6216fC19DB775Df9774a6E33526131dA7D19a2c) This is the address of the Kucoin exchange, with $1.7 billion on the Ethereum network and a total of $1.9 billion on other chains. The asset balance screenshot of this address is shown below: Checking the contract approval status of this address on the Ethereum network reveals a risk of $1.1 billion. Similarly, this does not necessarily indicate the presence of security risks but describes a possibility of potential risk exposure. Now let’s take a closer look at the approval status of this address on Kucoin. Wow! We have discovered some interesting things. 1. The APE token in this address was approved to the Multichain cross-chain Router contract on April 2, 2022. As we know, Multichain recently experienced an event beyond its control, but Kucoin did not immediately cancel the approval for the Multichain contract. This indicates that Kucoin still has room for improvement in risk emergency response. 2. Large amounts of USDT ($500 million), USDC ($290 million), KCS ($480 million), and other cryptocurrencies in this address were all approved without any limits to a contract called Bridge. After a simple analysis, we found that Bridge is a cross-chain bridge contract for Kucoin’s community chain KCC. However, upon checking the official website of KCC, we did not find any related security audit reports, which is concerning. Does anyone still remember the 2 million BNB attack on the BNB Chain? Case 3 Address: Jump Trading (0xf584F8728B874a6a5c7A8d4d387C9aae9172D621) This is the address of the institution Jump Trading, with $140 million on the Ethereum network and a total of $150 million on other chains. The asset balance screenshot of this address is shown below: Checking the contract approval status of this address on the Ethereum network reveals a risk of $25 million. Similarly, this does not necessarily indicate the presence of security risks but describes a possibility of potential risk exposure. Now let’s take a closer look at the approval status of this address on Jump Trading. It can be observed that there are not many approvals for the cryptocurrencies in this address, and most of the approvals have set limits, indicating overall good management. However, the USDC was approved to the Curve contract on February 4, 2021, without setting a limit, and it has not been canceled since then. This should serve as a reminder that if there is no need for corresponding contract operations, it is recommended to cancel the approval for this contract immediately. Summary This flash analysis concludes here. Dilation Effect randomly selected several exchange and institution addresses for analysis, and the results show that these institutions have not performed perfectly in terms of contract approval. We hope our analysis can provide reference for the relevant institutions. Exchanges and institutions whose addresses were not selected can also refer to the analysis process mentioned above to check for similar issues. About Dilation Effect Dilation Effect is a recently established Web3 security community composed of cybersecurity enthusiasts from around the world. It focuses on sharing objective and neutral Web3 security viewpoints. Dilation Effect was the first in the industry to raise awareness about the risk of asset theft when using shared Apple IDs to download wallet applications on iPhones. It also exclusively disclosed the potential risks of Prime Protocol, a DeFi cross-chain lending protocol invested by Jump, and the Prime Protocol team has made rapid fixes. Dilation Effect will continue to publish various Web3 security viewpoints, assess the security of Web3 products and protocols, provide timely and effective security reminders to ordinary users, and gradually provide free cybersecurity assistance to Web3 users. Follow us on https://twitter.com/dilationeffect Follow us Wu Blockchain is free today. But if you enjoyed this post, you can tell Wu Blockchain that their writing is valuable by pledging a future subscription. You won't be charged unless they enable payments. |
Older messages
Exploring Worldcoin: Features, Privacy, and Challenges
Tuesday, May 30, 2023
Author: GaryMa, WuBlockchain With attention-grabbing terms like “OpenAI founder,” “luxurious financing background,” and “universal airdrop,” Worldcoin has garnered significant attention. Worldcoin,
Global Crypto Mining News (May 22 to May 28)
Monday, May 29, 2023
1. There was an issue during Dash Core v19 activation where blocks were no longer being produced and the issue is being investigated. Cryptocurrency has indicated that due to the situation after v19
Asia's weekly TOP10 crypto news (May 22 to May 28)
Sunday, May 28, 2023
Author:Crescent Editor:Colin Wu 1. Hong Kong's weekly summary 1.1 Hong Kong to allow retail trading of major cryptocurrencies link On May 23rd, according to Bloomberg, Hong Kong is set to announce
Weekly Project Updates: Tornado Cash's Malicious Governance Controversy, MakerDAO Proposes Increasing DAI Savings …
Saturday, May 27, 2023
1. ETH's Weekly Summary a. Summary of the 162nd Ethereum All Core Developers Meeting (ACDE) link On May 26th, according to Christine Kim's summary of the 162nd Ethereum All Core Developers
WuBlockchain Weekly:Hong Kong to allow retail trading of major cryptocurrencies、Core PCE index exceeds expectation…
Friday, May 26, 2023
Top10 News 1. Hong Kong to allow retail trading of major cryptocurrencies link According to Bloomberg, Hong Kong will announce that retail investors can trade cryptocurrencies under new rules for the
You Might Also Like
Central African Republic’s CAR memecoin raises scrutiny
Friday, February 14, 2025
Allegations of deepfake videos and opaque token distribution cast doubts on CAR's ambitious memecoin project. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
January CEX Data Report: Significant Declines in Trading Volume Across Major CEXs, Spot Down 25%, Derivatives Down…
Friday, February 14, 2025
According to data collected by the WuBlockchain team, spot trading volume on major central exchanges in January 2025 decreased by 25% compared to December 2024. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Previewing Coinbase Q4 2024 Earnings
Friday, February 14, 2025
Estimating Coinbase's Transaction and Subscriptions & Services Revenue in Q4 2024 ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
ADA outperforms Bitcoin as Grayscale seeks approval for first US Cardano ETF in SEC filing
Friday, February 14, 2025
Grayscale's Cardano ETF filing could reshape ADA's market position amid regulatory uncertainty ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
AI project trading tips: investment targets and position management
Friday, February 14, 2025
This interview delves into the investment trends, market landscape, and future opportunities within AI Agent projects. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
DeFi & L1L2 Weekly — 📈 Polymarket recorded a new high of 462.6k active users in Jan despite volume dip; Holesky a…
Friday, February 14, 2025
Polymarket recorded a new high of 462600 active users in January despite volume dip; Holesky and Sepolia testnets are scheduled to fork in Feb and Mar for Ethereum's Pectra upgrade. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
DeFi & L1L2 Weekly — 📈 Polymarket recorded a new high of 462.6k active users in Jan despite volume dip; Holesky a…
Friday, February 14, 2025
Polymarket recorded a new high of 462600 active users in January despite volume dip; Holesky and Sepolia testnets are scheduled to fork in Feb and Mar for Ethereum's Pectra upgrade. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Donald Trump taps crypto advocate a16z’s Brian Quintenz for CFTC leadership
Friday, February 14, 2025
Industry leaders back Brian Quintenz's nomination, highlighting his past efforts at the CFTC and potential to revamp crypto oversight. ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
⚡10 Tips to Make a Living Selling Info Products
Friday, February 14, 2025
PLUS: the best links, events, and jokes of the week → ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏
Interview with CryptoD: How He Made $17 Million Profit on TRUMP Coin
Friday, February 14, 2025
Author | WUblockchain, Foresight News ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏ ͏