Anyswap / Multichain Router V3 2021 MPC key exploit
Anyswap disclosed exploitation of prototype V3 cross-chain liquidity pools after repeated ECDSA R values exposed an MPC private key. Four malicious transactions across Ethereum, BNB Smart Chain and Fantom stole 2,398,496.02 USDC and 5,509,222.73 MIM. The operator stated that its V1/V2 bridge was not affected.
Incident facts
- Incident title
- Anyswap / Multichain Router V3 2021 MPC key exploit
- Bridge
- Multichain
- Incident date
- 2021-07-10
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, BNB Chain, Fantom
- Affected assets
- USDC, Unknown
- Attack category
- Private Key Compromise
- Reported loss
- 2,398,496.02 USDC and 5,509,222.73 MIM reported stolen; no USD aggregate is asserted here.
- Amount confidence
- High
- Loss amount basis
- Official Incident Statement; Token Amounts Preserved Without USD Conversion
- Recovery
- None Confirmed
- Reimbursement
- Announced
- Restart
- Unknown
- Current outcome
- Limited After Incident
- Postmortem
- Partial
- Resolution
- Unresolved
- Last reviewed
- 2026-08-26
- Last verified
- 2026-08-26
Amount and valuation
2,398,496.02 USDC and 5,509,222.73 MIM reported stolen; no USD aggregate is asserted here.
The official statement provides token-denominated amounts. This record intentionally does not manufacture a USD total.
2,398,496.02 USDC and 5,509,222.73 MIM
Exact token amounts from the operator statement.
Why this remains unresolved
- The operator committed to compensate user losses, but completion is not established in the reviewed canonical evidence.
Timeline events
Anyswap commits to compensate affected users2021-07
The operator committed to compensate user losses connected to the V3 exploit.
Compensation completion is not asserted.
Anyswap V3 exploit disclosed2021-07-10
Anyswap disclosed exploitation of prototype V3 cross-chain liquidity pools after MPC private-key exposure caused by repeated ECDSA R values.
The operator explicitly stated that its V1/V2 bridge was not affected.
Evidence records
- Anyswap Multichain Router V3 Exploit StatementMultichain / Anyswap · Tier 1 · High reliability · primary · 2021-07Claim scope: Incident Case
First-party exploit statement covering affected V3 pools, chains, stolen token amounts, MPC-key root cause and compensation commitment.
- Anyswap Multichain Router V3 Exploit StatementMultichain / Anyswap · Tier 1 · High reliability · primary · 2021-07Claim scope: Reimbursement
First-party statement used specifically for the compensation commitment; completion is not inferred.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final compensation completion is not established by the reviewed evidence.
- A USD conversion of the stolen token amounts is intentionally not asserted.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.