Incident case

Multichain 2022 router approval vulnerability

In January 2022, attackers exploited vulnerable Multichain/Anyswap router approval paths after a critical vulnerability disclosure. Independent technical reports document the flawed permit/underlying-token validation boundary and subsequent whitehat rescue activity.

reviewedcurrent

Incident facts

Incident title
Multichain 2022 router approval vulnerability
Bridge
Multichain
Incident date
2022-01-18
Incident type
Exploit
Major incident
Yes
Affected chains
Ethereum, Avalanche, Unknown
Affected assets
WETH, AVAX, Unknown
Attack category
Unknown
Reported loss
Stolen, rescued, at-risk and later reimbursed amounts are distinct; this bounded record does not collapse them into a single USD loss.
Amount confidence
Low
Loss amount basis
Technical Incident Reports; Conservative Amount Boundary
Recovery
Partial Recovery
Reimbursement
Announced
Restart
Reopened
Current outcome
Limited After Incident
Postmortem
Full
Resolution
Unresolved
Last reviewed
2026-08-23
Last verified
2026-08-23

Amount and valuation

Stolen, rescued, at-risk and later reimbursed amounts are distinct; this bounded record does not collapse them into a single USD loss.

The review authority preserves separate stolen/rescued/reimbursement figures; canonical amount remains unset until those claims are reconciled against stable preserved sources.

Why this remains unresolved

Timeline events

  • Whitehat rescue and mitigation reduce Multichain exposure2022-01

    Security responders carried out whitehat rescue activity while users were urged to revoke vulnerable approvals and affected contracts were migrated or upgraded.

    Partial Recovery ReportedHigh

    Reimbursement completion is not asserted.

  • Multichain router vulnerability exploitation begins2022-01-18

    Attackers exploited vulnerable Multichain/Anyswap router approval paths after disclosure of critical permit-handling vulnerabilities.

    Exploit DisclosedHigh

Evidence records

Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.

Known unknowns

Independent incident archive

Help maintain incident aftermath records

Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.

Support BIR
Record maintenance

Report a correction

Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.