Warning: Undefined array key "HTTP_ACCEPT_LANGUAGE" in /home/u596154002/domains/usbusinessreviews.com/public_html/wp-includes/load.php on line 2057

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the rank-math domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u596154002/domains/usbusinessreviews.com/public_html/wp-includes/functions.php on line 6114
Some ‘Smol’ NFTs returned after Treasure marketplace exploit leads to theft - Best Business Review Site 2024

Some ‘Smol’ NFTs returned after Treasure marketplace exploit leads to theft

[ad_1]

Hackers who exploited a vulnerability in NFT marketplace Treasure began returning most of the “Smol Brain” and “Legion” NFTs they stole on Thursday.

The people behind the attack were able to mint several NFTs for free thanks to the vulnerability.  

Blockchain analysis firm PeckShield said more than 100 NFTs were stolen from several collections in the Treasure marketplace. 

The situation began on Tuesday, when reports emerged that the Treasure marketplace was being exploited. Treasure did not respond to requests for comment, but co-founder John Patten took to Twitter to confirm that the platform was facing a spate of thefts. 

“Treasure marketplace is being exploited. Please delist your items. We will cover the costs of the exploit—I will personally give up all of my Smols to repair this. I cannot fathom what subhuman targets a fair launch marketplace for robbery, but they will not defeat the community,” Patten said. 

“I vow to keep making free mints that make people happy even if this evil individual exploits every single one. This is just the beginning.”

Treasure released its own official statement, writing that their team was “focused on finding the 50 NFTs that remain stolen and making buyers whole.”

A number of people compared the issue to something popular NFT marketplace OpenSea also faced recently, where hackers gained the ability to re-list an NFT at a new price without cancelling the previous listing. 

Other experts like Harry Denley, a member of the security team at MetaMask, urged users to delist. Denley told ZDNet that the issue facing Treasure is different than the one that affected OpenSea, but noted that the end result was somewhat the same: NFTs being stolen for low, and sometimes $0, value.

“The issue with Treasure was a logic flaw in their smart contract within the buyItem() function. The function did not validate the quantity of the listing you were buying from, so a bad actor could craft a transaction to call buyItem() to create a specific buy order with 0 quantity for a listing,” Denley explained.

“Because of 0 quantity, the price to pay was 0 (price * quantity = 0), and if that was satisfied (as in the transaction sent the correct amount of money, which will always be $0, to buy the order at), the NFTs were transferred to the buyer. A simple sanity check was missing from the function.”

Denley added that he was unsure of the number of stolen NFTs and their value but noted that most have been returned to their owners. CoinDesk pegged the value of the stolen NFTs at around $1.4 million. 

Denley said the marketplace is in a “pause” state and explained that they set their Oracle to a “burn” address in transaction causing all interactions with the marketplace to fail. 

“After they have redeployed the contracts with the fix and hopefully have the contracts audited, then they’ll start opening up the marketplace,” Denley said. 

“I think it’s worth noting that it is still yet to be determined if this attack was a white hat or a black hat that had a change of heart due to their on-chain activity possibly being linked to their real-world identity. For example, 201 days ago, the exploiter received funds from a Binance account to their Ethereum main net address, which could be KYC’d or exposed identify somewhere on that platform,” he added, pointing to an address implicated in the attack.

In Treasure’s Discord channel, developers said they identified and rectified the cause of the issue.

“This was a basic bug arising from a prior fix that should have been identified earlier,” they wrote. “Once we have the full list of remaining impacted parties who did not receive back their stolen NFTs, we will propose a number of remediation options to ensure users are made whole.”

Treasure is the biggest NFT marketplace on the Arbitrum blockchain. 



[ad_2]

Source link

slot gacor slot gacor togel macau slot hoki bandar togel slot dana slot mahjong link slot link slot777 slot gampang maxwin slot hoki slot mahjong slot maxwin slot mpo slot777 slot toto slot toto situs toto toto slot situs toto situs toto situs toto situs toto slot88 toto slot slot gacor thailand slot bet receh situs toto situs toto slot toto slot situs toto situs toto situs toto situs togel macau toto slot slot demo slot pulsa slot pragmatic situs toto deposit dana 10k surga slot toto slot link situs toto situs toto slot situs toto situs toto slot777 slot gacor situs toto slot slot pulsa 10k toto togel situs toto slot situs toto slot gacor terpercaya slot dana slot gacor pay4d agen sbobet kedai168 kedai168 deposit pulsa situs toto slot pulsa situs toto slot pulsa situs toto situs toto situs toto slot dana toto slot situs toto slot pulsa toto slot situs toto slot pulsa situs toto situs toto situs toto toto slot toto slot slot toto akun pro maxwin situs toto slot gacor maxwin slot gacor maxwin situs toto slot slot depo 10k toto slot toto slot situs toto situs toto toto slot toto slot toto slot toto togel slot toto togel situs toto situs toto toto slot slot gacor slot gacor slot gacor situs toto situs toto cytotec toto slot situs toto situs toto toto slot situs toto situs toto slot gacor maxwin slot gacor maxwin link slot 10k slot gacor maxwin slot gacor slot pulsa situs slot 10k slot 10k toto slot toto slot situs toto situs toto situs toto bandar togel 4d toto slot