• Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service
Friday, May 1, 2026
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
Ledger - Crypto Beginners Pack
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop
No Result
View All Result
XXL24
No Result
View All Result

Multiple NFT collections at risk by flaw in open-source library

December 6, 2023
in NFT
0

A vulnerability in an open-source library that is common across the Web3 space impacts the security of pre-built smart contracts, affecting multiple NFT collections, including Coinbase.

The disclosure came earlier today from Web3 development platform Thirdweb. The announcement provides a minimum of details, which irked some users who wanted clarifications that could help them protect contracts.

Thirdweb said that it became aware of the security flaw on November 20 and pushed a remediation two days later, but did not disclose the name of the library and the type or severity of the vulnerability to prevent tipping off attackers.

The company says it has contacted the maintainers of the vulnerable library and also alerted other protocols and organizations of the issue, sharing findings and mitigations.

The following smart contracts are impacted by the flaw:

  • AirdropERC20 (v1.0.3 and later), ERC721 (v1.0.4 and later), ERC1155 (v1.0.4 and later) ERC20Claimable, ERC721Claimable, ERC1155Claimable
  • BurnToClaimDropERC721 (all versions)
  • DropERC20, ERC721, ERC1155 (all versions)
  • LoyaltyCard
  • MarketplaceV3 (All versions)
  • Multiwrap, Multiwrap_OSRoyaltyFilter
  • OpenEditionERC721 (v1.0.0 and later)
  • Pack and Pack_OSRoyaltyFilter
  • TieredDrop (all versions)
  • TokenERC20, ECRC721, ERC1155 (all versions)
  • SignatureDrop, SignatureDrop_OSRoyaltyFilter
  • Split (low impact)
  • TokenStake, NFTStake, EditionStake (All versions)

“If you used our Solidity SDK to extend our base contract or built a custom contract, we don’t believe the vulnerability extends to your contract,” explains Thirdweb, adding that this is not a guarantee because they “are unable to audit individual contracts.”

Thirdweb has shared the details of the exploit with the maintainers of the affected library and said that it has not seen the vulnerability being leveraged in attacks.

Users upset by lack of transparency

The absence of details prompted some users to ask for clarifications or to speculate that the issue is with the Thirdweb implementation of the library.

One user complained about the lack of transparency asking for the CVE (Common Vulnerabilities and Exposures) identifier of the vulnerability and for an explanation of how the mitigation works.

User complains about the lack of details in Thirdweb’s vulnerability disclosure
source: nuri

Lock vulnerable contracts

Thirdweb said that smart contract owners must take mitigation measures immediately for all pre-built contracts created before November 22, 2023, at 7 pm PT.

The advice is to lock the vulnerable contracts, take a snapshot, and then migrate it to a new contract created with a non-vulnerable version of the library. A dedicated tool and tutorial on how to mitigate impacted contracts are provided here.

Thirdweb said that it would offer retroactive gas grants to cover contract mitigations but users have to fill out a form to be approved.

Naturally, the warning has caused holders of valuable NFTs to worry and large NFT trading platforms have already responded to the situation.

In an announcement on Monday, Coinbase NFT said that it learned of the vulnerability last Friday and that it affects some of its collections created with Thirdweb.

“Coinbase itself is unaffected by this issue and all funds on Coinbase are safe,” adds the crypto exchange platform.

The mainatainers of the OpenZeppelin library for smart contract development were also informed of the issue affecting Thirdweb’s versions of DropERC20, ERC721, ERC1155 (all versions), and AirdropERC20 pre-built contract.

“Based on our investigation, the issue is inherent to a problematic integration of specific patterns, and NOT particular to the implementations contained in the OpenZeppelin Contracts library” – OpenZeppelin

Mocaverse, the membership NFT collection for the Animoca Brands ecosystem, also updated its users that their assets are safe and that it “successfully upgraded the Mocaverse NFT, Lucky Neko, and Mocaverse Relic collection smart contracts to close the relevant security vulnerability.”

On Tuesday, after conducting all mitigation steps where possible, Mocaverse signalled the potential risk to Animoca Brands subsidiary companies, to let them take the necessary measures for the safety of their users’ assets.

“For the contracts that are not upgradable, including the Realm Ticket and Honorary Collection, we have locked the relevant contracts and taken a snapshot of all the data, and will subsequently allow the original holders to claim the NFTs based on previous holding via Thirdweb based on a new smart contract without the known vulnerability” – Mocaverse

Similarly, OpenSea has announced that they were working closely with Thirdweb to mitigate the risks involved and plan to assist impacted users.



This news is republished from another source.


Previous Post

Should You Buy DeFi Kingdoms (JEWEL) Tuesday?

Next Post

SEC Delays Decision on Grayscale spot Ethereum ETF

Next Post

SEC Delays Decision on Grayscale spot Ethereum ETF

Name Price
Kinza Babylon Staked BTC
Kinza Babylon Staked BTC (KBTC)
$83,270.00
Steakhouse EURCV Morpho Vault
Steakhouse EURCV Morpho Vault (STEAKEURCV)
$0.000000
Eureka Bridged PAX Gold (Terra)
Eureka Bridged PAX Gold (Terra) (PAXG)
$4,182.54
Vested XOR
Vested XOR (VXOR)
$3,404.23
ICPanda DAO
ICPanda DAO (PANDA)
$0.003106
TruFin Staked APT
TruFin Staked APT (TRUAPT)
$8.02
kpk ETH Prime
kpk ETH Prime (KPK ETH PRIME)
$2,036.25
ApeSwap
ApeSwap (BANANA)
$0.000000
bitcoin
Bitcoin (BTC)
$77,279.00
ethereum
Ethereum (ETH)
$2,281.68

Dogecoin

Will Dogecoin Recover or Dive Below $0.1? 5thScape Set to Dominate 2024! %

July 15, 2024

Investors Shift to Clandeno (CLD) ICO Amid Global Market Uncertainty as Dogecoin (DOGE) and Polkadot (DOT) Drop

July 14, 2024

Dogecoin (DOGE) and Solana (SOL) Lead Crypto Market Recovery as Bitcoin (BTC) Reclaims $60K

July 14, 2024

DOGECOIN PRICE ANALYSIS & PREDICTION (July 13) – Doge Trades Calmly At $0.1, Can It Gain Strength From This Key Level? 

July 14, 2024

Analyst Who Bought Solana At $0.11 And Sold For $250 Says Buy ETFSwap (ETFS) At $0.01831 Now Instead Of Dogecoin (DOGE)

July 13, 2024

Leap Ahead with MOONHOP Presale As 4900% Growth Projection Dwarfs Notcoin & Dogecoin’s Declines

July 13, 2024

Metaverse

Ciz Verse Announces the Launch of Its Bitcoin-Powered Metaverse

July 15, 2024

Mil.k partners AirAsia rewards and The Sandbox to engage consumers in the metaverse

July 15, 2024

Lado Okhotnikov Reveals The Secrets Of The Realistic Meta Force Metaverse

July 14, 2024

GensoKishi Metaverse (MV) Price Down 18.4% This Week

July 14, 2024

The 3 Smartest Metaverse Stocks to Buy With $500 Right Now

July 14, 2024

Top 3 Metaverse Tokens For 3X Surge This Bull Rally!

July 13, 2024

transcosmos launches Roblox metaverse services with EbuAction

July 13, 2024
No Result
View All Result

Pages

  • Home
  • Live Rates
  • Privacy Policy
  • Shop
  • Terms of Service

Tether

Zimbabwe ZiG Hits Record Low as Interest in Tether (USDT) Rises

July 15, 2024

Solana

How Solana flipped Ethereum, Bitcoin in NFT Adoption

July 15, 2024

Solana Reaches Market Capitalization of $67.27 Billion (SOL)

July 14, 2024

Advertisement

  • Shop
  • Privacy Policy
  • Terms of Service

© 2023 XXL24


No Result
View All Result
  • Home
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • DeFi
  • Blockchain
  • Metaverse
  • Altcoin
  • Tether
  • Solana
    • Dogecoin
  • Live Rates
  • Shop

© 2023 XXL24


  • Kinza Babylon Staked BTCKinza Babylon Staked BTC(KBTC)$83,270.000.00%
  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • Eureka Bridged PAX Gold (Terra)Eureka Bridged PAX Gold (Terra)(PAXG)$4,182.540.23%
  • Vested XORVested XOR(VXOR)$3,404.231,000.00%
  • ICPanda DAOICPanda DAO(PANDA)$0.003106-39.39%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • kpk ETH Primekpk ETH Prime(KPK ETH PRIME)$2,036.250.01%
  • ApeSwapApeSwap(BANANA)$0.0000000.00%
  • bitcoinBitcoin(BTC)$77,279.001.68%
  • ethereumEthereum(ETH)$2,281.681.01%
  • kpk ETH Yieldkpk ETH Yield(KPK ETH YIELD)$2,031.88-0.04%
  • tetherTether(USDT)$1.000.01%
  • JPool Staked SOLJPool Staked SOL(JSOL)$170.103.95%
  • rippleXRP(XRP)$1.370.17%
  • binancecoinBNB(BNB)$616.310.07%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$83.931.21%
  • tronTRON(TRX)$0.3262930.09%
  • staked-etherLido Staked Ether(STETH)$2,262.76-3.72%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.24%
  • dogecoinDogecoin(DOGE)$0.1078880.89%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$57.850.73%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • USD OneUSD One(USD1)$1.000.11%
  • USDSUSDS(USDS)$1.000.00%
  • Wrapped stETHWrapped stETH(WSTETH)$2,773.89-3.48%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • HyperliquidHyperliquid(HYPE)$40.854.67%
  • leo-tokenLEO Token(LEO)$10.32-0.48%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$76,102.00-3.36%
  • cardanoCardano(ADA)$0.2475440.66%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.07%
  • bitcoin-cashBitcoin Cash(BCH)$442.18-0.71%
  • Wrapped Beacon ETHWrapped Beacon ETH(WBETH)$2,462.35-3.82%
  • Wrapped eETHWrapped eETH(WEETH)$2,462.97-3.62%
  • moneroMonero(XMR)$383.591.86%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • chainlinkChainlink(LINK)$9.130.28%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$76,319.00-3.28%
  • PengPeng(PENG)$0.60-13.59%
  • zcashZcash(ZEC)$351.445.66%
  • CantonCanton(CC)$0.149474-0.95%
  • stellarStellar(XLM)$0.159255-0.45%
  • wethWETH(WETH)$2,264.05-3.78%
  • MurasakiMurasaki(MURA)$4.32-12.46%
  • USD1USD1(USD1)$1.000.02%
  • sUSDSsUSDS(SUSDS)$1.090.12%
  • USDT0USDT0(USDT0)$1.00-0.11%