Skip to content
Incident record

Multichain Unauthorised Outflows, July 2023: What Happened & What to Check

Assets left Multichain bridge contracts with no exploit visible on-chain, amid the reported detention of the project's chief executive.

Disputed Discovered Disclosed
Share X in @
Schematic of the Multichain incident showing the bridge exploit stage as the failure point.
Schematic of the Multichain incident showing the bridge exploit stage as the failure point.

At a glance

AFFECTED ENTITY
Multichain
REPORTED LOSS
approx. US$126 million(Multichain, 7 Jul 2023)
OFFICIAL RESPONSE
multichain.org

Why this one is Disputed

Conisec marks a record Disputed when credible parties disagree on whether an event occurred, its scale, or its cause. Here the outflows are undisputed and visible on-chain; the cause is not. No exploit was identified. The transactions looked authorised. The team’s own explanation centred on the unavailability of an individual who held operational control.

We do not characterise that as theft, misappropriation or any other legal conclusion, because no authoritative body has. Recording it as Disputed and saying why is more useful than picking a narrative.

The structural point

A bridge described as decentralised depended on infrastructure controlled by one person, and that dependency became visible only when the person was unavailable. Key management questions are usually asked as “how many signatures?” The better question is “how many people could unilaterally stop or move this, and what happens if one of them disappears?”

Timeline

Append-only. Corrections are added as their own dated entry; earlier entries are never rewritten.

  1. Large unauthorised-looking outflows are observed from Multichain bridge contracts across several chains. Multichain
  2. Multichain states it is unable to contact its chief executive, who held control of key operational infrastructure, and suspends services. Multichain

What to check

Multichain's own statements are the record. Note that they are limited and, by the team's own account, incomplete.

Conisec does not host or link recovery, revocation or "checker" tools. After a public incident, attackers routinely seed exactly those links using the names of publications covering the story. Use the affected project's own official channel, linked above, and nothing else.

Sources

  1. Multichain, Official statements (6 Jul 2023)

Not advice. This is a summary of published facts, not legal, tax or security advice. Verify against the primary sources linked above.

Last verified by Conisec Staff.