Multichain 2022 router approval vulnerability
In January 2022, attackers exploited vulnerable Multichain/Anyswap router approval paths after a critical vulnerability disclosure. Independent technical reports document the flawed permit/underlying-token validation boundary and subsequent whitehat rescue activity.
Incident facts
- Incident title
- Multichain 2022 router approval vulnerability
- Bridge
- Multichain
- Incident date
- 2022-01-18
- Incident type
- Exploit
- Major incident
- Yes
- Affected chains
- Ethereum, Avalanche, Unknown
- Affected assets
- WETH, AVAX, Unknown
- Attack category
- Unknown
- Reported loss
- Stolen, rescued, at-risk and later reimbursed amounts are distinct; this bounded record does not collapse them into a single USD loss.
- Amount confidence
- Low
- Loss amount basis
- Technical Incident Reports; Conservative Amount Boundary
- Recovery
- Partial Recovery
- Reimbursement
- Announced
- Restart
- Reopened
- Current outcome
- Limited After Incident
- Postmortem
- Full
- Resolution
- Unresolved
- Last reviewed
- 2026-08-23
- Last verified
- 2026-08-23
Amount and valuation
Stolen, rescued, at-risk and later reimbursed amounts are distinct; this bounded record does not collapse them into a single USD loss.
The review authority preserves separate stolen/rescued/reimbursement figures; canonical amount remains unset until those claims are reconciled against stable preserved sources.
Why this remains unresolved
- Final completion of the announced 100% reimbursement program is not established in this bounded package.
Timeline events
Whitehat rescue and mitigation reduce Multichain exposure2022-01
Security responders carried out whitehat rescue activity while users were urged to revoke vulnerable approvals and affected contracts were migrated or upgraded.
Reimbursement completion is not asserted.
Multichain router vulnerability exploitation begins2022-01-18
Attackers exploited vulnerable Multichain/Anyswap router approval paths after disclosure of critical permit-handling vulnerabilities.
Evidence records
- Multichain Contract Vulnerability Post MortemMultichain · Tier 1 · High reliability · primary · 2022-02-19Claim scope: Root Cause
Official Multichain postmortem covering the router/liquidity-pool vulnerabilities, exploitation, mitigation timeline, rescued funds and compensation plan.
- Multichain Contract Vulnerability Post MortemMultichain · Tier 1 · High reliability · primary · 2022-02-19Claim scope: Recovery
Official Multichain postmortem documenting whitehat rescue, returned funds, V6 migration and the proposed 100% reimbursement boundary.
Source tiers describe evidence authority, not certainty for every claim. Tier 1 is the strongest source class; Tier 2 and Tier 3 provide progressively more secondary or supporting context. Source notes define what each record actually supports.
Known unknowns
- Final reimbursed amount and completion date remain outside this bounded evidence package.
Help maintain incident aftermath records
Support recovery, reimbursement, restart, migration, shutdown, evidence, and correction checks.
Report a correction
Report missing evidence, incorrect dates, outcome changes, recovery details, reimbursement status, or broken links. GitHub Issues are preferred for structured review; the Google Form is available if you do not use GitHub.