• bitcoinBitcoin (BTC) $ 113,101.00
  • ethereumEthereum (ETH) $ 4,168.57
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 2.85
  • bnbBNB (BNB) $ 1,011.03
  • solanaSolana (SOL) $ 206.92
  • usd-coinUSDC (USDC) $ 0.999698
  • staked-etherLido Staked Ether (STETH) $ 4,167.97
  • dogecoinDogecoin (DOGE) $ 0.230059
  • tronTRON (TRX) $ 0.335683
  • cardanoCardano (ADA) $ 0.790701
  • wrapped-stethWrapped stETH (WSTETH) $ 5,064.54
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,495.22
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • chainlinkChainlink (LINK) $ 21.36
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 113,029.00
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.05
  • avalanche-2Avalanche (AVAX) $ 29.38
  • hyperliquidHyperliquid (HYPE) $ 45.32
  • stellarStellar (XLM) $ 0.364377
  • suiSui (SUI) $ 3.24
  • wrapped-eethWrapped eETH (WEETH) $ 4,491.50
  • bitcoin-cashBitcoin Cash (BCH) $ 551.09
  • wethWETH (WETH) $ 4,168.96
  • hedera-hashgraphHedera (HBAR) $ 0.213987
  • leo-tokenLEO Token (LEO) $ 9.61
  • litecoinLitecoin (LTC) $ 105.37
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • usdsUSDS (USDS) $ 0.999581
  • usdt0USDT0 (USDT0) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 113,063.00
  • shiba-inuShiba Inu (SHIB) $ 0.000012
  • crypto-com-chainCronos (CRO) $ 0.193651
  • the-open-networkToncoin (TON) $ 2.63
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • whitebitWhiteBIT Coin (WBT) $ 41.72
  • polkadotPolkadot (DOT) $ 3.89
  • mantleMantle (MNT) $ 1.82
  • moneroMonero (XMR) $ 297.80
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.198889
  • daiDai (DAI) $ 0.999644
  • uniswapUniswap (UNI) $ 7.59
  • aaveAave (AAVE) $ 272.37
  • okbOKB (OKB) $ 188.84
  • pepePepe (PEPE) $ 0.000009
  • memecoreMemeCore (M) $ 2.29
  • ethenaEthena (ENA) $ 0.548379
  • bitget-tokenBitget Token (BGB) $ 5.23
  • nearNEAR Protocol (NEAR) $ 2.65
  • jito-staked-solJito Staked SOL (JITOSOL) $ 255.23
  • myx-financeMYX Finance (MYX) $ 16.06
  • aptosAptos (APT) $ 4.27
  • aster-2Aster (ASTER) $ 1.79
  • bittensorBittensor (TAO) $ 304.07
  • ethereum-classicEthereum Classic (ETC) $ 18.33
  • ondo-financeOndo (ONDO) $ 0.880270
  • usd1-wlfiUSD1 (USD1) $ 0.999662
  • story-2Story (IP) $ 8.54
  • worldcoin-wldWorldcoin (WLD) $ 1.24
  • binance-staked-solBinance Staked SOL (BNSOL) $ 222.48
  • binance-peg-wethBinance-Peg WETH (WETH) $ 4,167.03
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999977
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.224849
  • internet-computerInternet Computer (ICP) $ 4.17
  • arbitrumArbitrum (ARB) $ 0.411436
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.57
  • pi-networkPi Network (PI) $ 0.262485
  • susdssUSDS (SUSDS) $ 1.07
  • kaspaKaspa (KAS) $ 0.074924
  • falcon-financeFalcon USD (USDF) $ 0.997799
  • plasmaPlasma (XPL) $ 1.09
  • kucoin-sharesKuCoin (KCS) $ 15.41
  • gatechain-tokenGate (GT) $ 16.20
  • pump-funPump.fun (PUMP) $ 0.005430
  • cosmosCosmos Hub (ATOM) $ 4.06
  • flare-networksFlare (FLR) $ 0.025437
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,768.13
  • vechainVeChain (VET) $ 0.021694
  • usdtbUSDtb (USDTB) $ 0.999603
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,397.49
  • algorandAlgorand (ALGO) $ 0.204478
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 45.41
  • hash-2Provenance Blockchain (HASH) $ 0.035092
  • render-tokenRender (RENDER) $ 3.35
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.027339
  • bfusdBFUSD (BFUSD) $ 0.999151
  • sei-networkSei (SEI) $ 0.272853
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,392.46
  • skySky (SKY) $ 0.066288
  • filecoinFilecoin (FIL) $ 2.18
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,499.87
  • official-trumpOfficial Trump (TRUMP) $ 7.35
  • bonkBonk (BONK) $ 0.000019
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.558286
  • tether-goldTether Gold (XAUT) $ 3,818.46
  • immutable-xImmutable (IMX) $ 0.704937
  • jupiter-exchange-solanaJupiter (JUP) $ 0.428023
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,415.56
  • xdce-crowd-saleXDC Network (XDC) $ 0.074059
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 113,088.00
  • nexoNEXO (NEXO) $ 1.25
  • wbnbWrapped BNB (WBNB) $ 1,010.96
  • optimismOptimism (OP) $ 0.665749
  • injective-protocolInjective (INJ) $ 11.77
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.13
  • pax-goldPAX Gold (PAXG) $ 3,826.88
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 112,701.00
  • celestiaCelestia (TIA) $ 1.38
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,486.28
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 236.07
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997644
  • zcashZcash (ZEC) $ 65.53
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999627
  • blockstackStacks (STX) $ 0.569421
  • lido-daoLido DAO (LDO) $ 1.14
  • sonic-3Sonic (S) $ 0.257288
  • curve-dao-tokenCurve DAO (CRV) $ 0.668884
  • msolMarinade Staked SOL (MSOL) $ 274.78
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 113,187.00
  • aerodrome-financeAerodrome Finance (AERO) $ 1.01
  • spx6900SPX6900 (SPX) $ 0.971103
  • fasttokenFasttoken (FTN) $ 2.07
  • kaiaKaia (KAIA) $ 0.150675
  • clbtcclBTC (CLBTC) $ 114,092.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.51
  • saros-financeSaros (SAROS) $ 0.323469
  • the-graphThe Graph (GRT) $ 0.080072
  • pyth-networkPyth Network (PYTH) $ 0.144819
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,980.35
  • ripple-usdRipple USD (RLUSD) $ 0.999615
  • pendlePendle (PENDLE) $ 4.63
  • flokiFLOKI (FLOKI) $ 0.000080
  • ether-fiEther.fi (ETHFI) $ 1.46
  • conflux-tokenConflux (CFX) $ 0.143204
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 4,169.96
  • global-dollarGlobal Dollar (USDG) $ 0.999592
  • ousgOUSG (OUSG) $ 112.75
  • tbtctBTC (TBTC) $ 112,817.00
  • dogwifcoindogwifhat (WIF) $ 0.708632
  • tezosTezos (XTZ) $ 0.665464
  • raydiumRaydium (RAY) $ 2.60
  • theta-tokenTheta Network (THETA) $ 0.687094
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.996337
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.07
  • iotaIOTA (IOTA) $ 0.164363
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 1.01
  • newton-projectAB (AB) $ 0.008303
  • galaGALA (GALA) $ 0.014290
  • ethereum-name-serviceEthereum Name Service (ENS) $ 19.85
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 4,162.97
  • beldexBeldex (BDX) $ 0.088062
  • the-sandboxThe Sandbox (SAND) $ 0.261970
  • gtethGTETH (GTETH) $ 4,168.18
  • stader-ethxStader ETHx (ETHX) $ 4,463.79
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.84
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 4,168.98
  • vaultaVaulta (A) $ 0.395451
  • aethirAethir (ATH) $ 0.050366
  • jito-governance-tokenJito (JTO) $ 1.57
  • fartcoinFartcoin (FARTCOIN) $ 0.601306
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.229915
  • bittorrentBitTorrent (BTT) $ 0.00000059
  • jasmycoinJasmyCoin (JASMY) $ 0.012006
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,482.57
  • swissborgSwissBorg (BORG) $ 0.574055
  • morphoMorpho (MORPHO) $ 1.69
  • starknetStarknet (STRK) $ 0.136691
  • walrus-2Walrus (WAL) $ 0.386708
  • flowFlow (FLOW) $ 0.347180
  • swethSwell Ethereum (SWETH) $ 4,581.29
  • usual-usdUsual USD (USD0) $ 0.998394
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,589.34
  • zero-gravity0G (0G) $ 2.56
  • decentralandDecentraland (MANA) $ 0.285519
  • dexeDeXe (DEXE) $ 9.47
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.27
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,482.29
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 113,075.00
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.52
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 35.98
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • true-usdTrueUSD (TUSD) $ 0.999351
  • sun-tokenSun Token (SUN) $ 0.025431
  • loaded-lionsLoaded Lions (LION) $ 0.015628
  • wormholeWormhole (W) $ 0.101087
  • bitcoin-svBitcoin SV (BSV) $ 23.80
  • kinetiq-earn-vaultKinetiq Earn Vault (VKHYPE) $ 45.24
  • usddUSDD (USDD) $ 1.00
  • wrapped-avaxWrapped AVAX (WAVAX) $ 29.39
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 4,169.25
  • dydx-chaindYdX (DYDX) $ 0.591201
  • frax-etherFrax Ether (FRXETH) $ 4,151.59
  • usdaiUSDai (USDAI) $ 1.03
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999813
  • bybit-staked-solBybit Staked SOL (BBSOL) $ 228.97
  • falcon-finance-ffFalcon Finance (FF) $ 0.187781
  • bridged-usdc-polygon-pos-bridgeBridged USDC (Polygon PoS Bridge) (USDC.E) $ 0.999722
  • vision-3Vision (VSN) $ 0.130542

$78 Million Lost to ‘Laundering Loophole’ in Tether Freezing Method Since 2017

0 102

$78 Million Lost to ‘Laundering Loophole’ in Tether Freezing Method Since 2017

There is “significant lag” between exchanges saying they’re going to freeze USDT held by malicious addresses and, well, actually doing it, according to a new report from AMLBot.

AMLBot’s report found that on-chain freezing enforcement of Tether’s USDT stablecoin has been sluggish. As a result, the anti-money laundering firm said, at least $78 million has been lost to bad actors on Ethereum and Tron since 2017.

The “laundering loophole” is the result of Tether’s multi-signature contract set up, AMLBot explained in the report. 

First, a freeze request is sent on-chain which requires multiple signatures to approve before the freeze can be executed. As a result, a “window of opportunity” is created allowing illicit actors to move funds before their address is frozen.

One example provided in the report showcases a 44 minute delay between the freeze request and confirmation on Tron. 

AMLBot claims that $49.6 million has been withdrawn by bad actors on the Tron network since 2017 as a result of the vulnerability. Wallets were able to make up to three transactions during the delay window with 4.88% of blacklisted wallets exploiting the lag on the network.

Meanwhile on Ethereum, the firm found $28.5 million USDT withdrawn within the same timeframe. Totalling $78.1 million across the two chains.

Security firm PeckShield reviewed the report and confirmed that the loophole exists.

“It does not necessarily indicate a problem with the contract itself. Rather, it is an operational issue that creates a time window between when the blacklist transaction is submitted and when it is executed,” a PeckShield spokesperson told Decrypt. “Given the security-sensitive nature of the issue, improvements are definitely necessary.”

Tether is the issuer of the largest stablecoin in crypto USDT, which aims to peg its price to the U.S. dollar. The company blacklists addresses from trading their products if they’re connected to illegal activity, such as wallets linked to the $1.4 billion Bybit hack earlier this year. 

Being blacklisted means the address can no longer move Tether issued assets, effectively making the tokens worthless. 

However, AMLBot believes malicious actors know of the aforementioned lag and are creating tools to exploit it. 

“Tools can be programmed to monitor the blockchain for specific contract interactions, such as submitTransaction() calls linked to freeze requests,” Slava Demchuk, CEO of AMLBot, told Decrypt. “The bots can alert wallet owners the moment a freeze is initiated but before it’s enforced. Given the delay introduced by Tether’s multi-signature process, this provides a narrow but critical window for illicit actors to quickly move funds.”

“While we haven’t directly observed the bots themselves, the on-chain behavior strongly suggests such automation is in play,” he added.

PeckShield warned that the lag is inherent to how multi-sig accounts are designed to function. Simply, it takes time to have multiple people sign a transaction despite it being required in some cases to boost security. The firm suggested that Tether could bundle together the freeze request with the signatures into one transaction to eliminate the window.

Tether did not respond to Decrypt’s request for comment in time for publication, this article will be updated once received.

Source

Leave A Reply

Your email address will not be published.