The private key of the DEX aggregator Paraswap deployer is suspected to have been leaked, and the multi-signature treasury may be at risk
ChainCatcher news, the security team Supremacy stated on Twitter that the wallet address of the DEX aggregator Paraswap deployer initiated abnormal transactions across multiple chains (ETH, BSC, FTM), transferring the entire balance from its address to 0xf35875a064cdbc29d7174f5c699f1ebeaa407036. This address is linked to a Profanity exploit user, with a history of stealing assets from multiple vanity address accounts.
It is reported that ParaSwap is an on-chain aggregator exchange that not only builds its own ParaSwapPool exchange pool but also aggregates protocols such as Kyber, Bancor, Uniswap, Oasis, Curve, and 0x. Currently, only the deployer's own assets have been stolen, and it does not affect the Paraswap multi-signature treasury (with a signature threshold of 2), but there may still be risks. (Source link)