Anyswap Multichain Router V3 hack — July 2021
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 11, 2021 |
| Target type | Cross-chain bridge |
| Loss | $7,900,000Price at time of incident |
| Method | Private key compromiseECDSA nonce reuse. The V3 router's MPC signing account produced two transactions on BNB Chain carrying the same R value, meaning the same random k was used twice. With two signatures sharing an R value the private key can be solved for algebraically from public on-chain data; the attacker recovered the key and used it to move the pooled stablecoins. |
| Chains | Ethereum, BNB Chain, Fantom |
| Outcome | Users reimbursed |
What happened
Anyswap's newly launched Multichain Router V3 was drained on 10 July 2021 at about 20:00 UTC. According to the team's own exploit statement, roughly $7.9 million left the V3 cross-chain liquidity pools: 5,509,222.73 MIM and 2,398,496.02 USDC, across Ethereum, BNB Chain and Fantom.
The root cause was a cryptographic implementation error rather than a smart-contract flaw. The V3 router's MPC account signed two transactions on BNB Chain that reused the same ECDSA nonce, producing signatures with an identical R value. When two signatures from one key share an R value, the private key can be recovered algebraically from data that is already public on the chain. This failure mode has been documented since at least 2010, when the group fail0verflow demonstrated it against Sony's PlayStation 3 signing key. Whoever noticed the repeated R value derived the MPC account's key and used it to move the pooled stablecoins.
Anyswap said only the new V3 cross-chain liquidity pools were affected and that the bridge continued operating through its V1 and V2 routers. It patched the signing code to prevent identical R values, said it had put remedial measures in place to compensate liquidity providers in full, engaged Trail of Bits for auditing, and relaunched V3 later in July 2021. An analysis published by Wanchain's research team independently reconstructed the nonce-reuse arithmetic from the on-chain signatures.
No perpetrator was identified. This is a separate event from the July 2023 collapse of Multichain, the protocol Anyswap later became, in which much larger sums left the bridge's custody.
Sources
- Anyswap (later Multichain)Primary · retrieved 2026-08-01
- CryptoPotato (analysis by the Wanchain R&D team)Secondary · retrieved 2026-08-01
- HalbornSecondary · retrieved 2026-08-01
Official post-mortem: https://medium.com/multichainorg/anyswap-multichain-router-v3-exploit-statement-6833f1b7e6fb
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Anyswap Multichain Router V3 hack — July 2021", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/anyswap-v3-routerhttps://itokenly.com/hacks/anyswap-v3-routerPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.