Incident case

Anyswap / Multichain Router V3 2021 MPC key exploit

Anyswap disclosed exploitation of prototype V3 cross-chain liquidity pools after repeated ECDSA R values exposed an MPC private key. Four malicious transactions across Ethereum, BNB Smart Chain and Fantom stole 2,398,496.02 USDC and 5,509,222.73 MIM. The operator stated that its V1/V2 bridge was not affected.

reviewedcurrent

Incident facts

Incident title
Anyswap / Multichain Router V3 2021 MPC key exploit
Bridge
Multichain
Incident date
2021-07-10
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, BNB Chain, Fantom
Affected assets
USDC, Unknown
Attack category
Private Key Compromise
Reported loss
2,398,496.02 USDC and 5,509,222.73 MIM reported stolen; no USD aggregate is asserted here.
Amount confidence
High
Loss amount basis
Official Incident Statement; Token Amounts Preserved Without USD Conversion
Recovery
None Confirmed
Reimbursement
Announced
Restart
Unknown
Current outcome
Limited After Incident
Postmortem
Partial
Resolution
Unresolved
Last reviewed
2026-08-26
Last verified
2026-08-26

Amount and valuation

2,398,496.02 USDC and 5,509,222.73 MIM reported stolen; no USD aggregate is asserted here.

The official statement provides token-denominated amounts. This record intentionally does not manufacture a USD total.

Why this remains unresolved

Timeline events

  • Anyswap commits to compensate affected users2021-07

    The operator committed to compensate user losses connected to the V3 exploit.

    Compensation CommitmentHigh

    Compensation completion is not asserted.

  • Anyswap V3 exploit disclosed2021-07-10

    Anyswap disclosed exploitation of prototype V3 cross-chain liquidity pools after MPC private-key exposure caused by repeated ECDSA R values.

    Exploit DisclosedHigh

    The operator explicitly stated that its V1/V2 bridge was not affected.

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.