T
iTokenly

Multichain hack — July 2023

Verified — 3 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Publicly disclosedJuly 7, 2023
Target typeCross-chain bridge
Loss$125,000,000Published estimates range $125,000,000 to $130,000,000Price at time of incident
MethodPrivate key compromiseUnauthorised access to MPC node servers held on the detained CEO's personal cloud account
ChainsEthereum, Fantom, Other
Attributed toUnidentified; Chainalysis noted circumstances consistent with an insider event or rug pull rather than an external intrusionSuspected
OutcomeProject shut down

What happened

Multichain, a cross-chain bridge formerly called Anyswap, lost custody of user assets held in its MPC addresses on 6 July 2023. Chainalysis counted over $125 million in unauthorised withdrawals, most of it — about $120 million — from the Fantom bridge, plus $6.8 million from the Moonriver bridge and roughly $666,000 from the Dogecoin bridge; CoinDesk reported the total as $130 million. The assets included wrapped bitcoin, wrapped ether, USDC and Tether. Multichain said user assets on the MPC addresses had been moved abnormally to unknown addresses and told users to stop interacting with the protocol.

The circumstances were unusual. Multichain later disclosed that its chief executive, known as Zhaojun, had been taken into custody by Chinese police on 21 May 2023, and that his computers, phones, hardware wallets and mnemonic phrases were confiscated. The MPC node servers ran on Zhaojun's personal cloud account, and the team found its access keys to that infrastructure had been revoked; during the abnormal transfers Zhaojun's sister found login activity on the cloud platform from an IP address in Kunming. She had been helping run day-to-day operations and then moved about $220 million of remaining assets into wallets she controlled, saying she was preserving them; she was herself detained on 13 July 2023, leaving those funds inaccessible.

Multichain announced on 14 July 2023 that it was ceasing operations, citing a lack of both alternative sources of information and operating funds. Chainalysis noted that MPC systems remain vulnerable if an attacker obtains enough key shares, but observed that the CEO's prior disappearance, the attacker's failure to swap out of centrally-controlled stablecoins as an ordinary thief would, and the sister's involvement were circumstances more consistent with an insider event or rug pull than with an external intrusion. No one has been publicly identified as the perpetrator.

Law enforcement

Multichain said chief executive Zhaojun was taken into custody by Chinese police on 21 May 2023 and that his computers, phones, hardware wallets and mnemonic phrases were confiscated. His sister was detained on 13 July 2023. No charges relating to the July 2023 outflows have been publicly disclosed.

Sources

  1. ChainalysisSecondary · retrieved 2026-08-01
  2. CoinDeskSecondary · retrieved 2026-08-01
  3. DL NewsSecondary · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Multichain hack — July 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/multichain
https://itokenly.com/hacks/multichain

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.