What's Hot

    US authorities launched a targeted campaign against cryptocurrencies: the opinion of the head of Galaxy Digital

    01.04.2023

    SpaceX will deliver a chest with a private key to 62 bitcoins to the moon

    01.04.2023

    “You can’t trade crypto without technical analysis,” Ilya Solovey

    01.04.2023
    Facebook Twitter Instagram
    Sunday, April 2
    Facebook Twitter Instagram
    Crypto News
    • Home
    • Bitcoin
    • Ethereum
      • Altcoins
      • ICO
    • Analytics
    • Blockchain
    • Other
      • DeFi
      • Mining
      • Regulators
      • Security
    Crypto News
    Home»Security»Rarible vulnerability allowed stealing all NFTs from a user’s wallet
    0544f53cf60e7fbc03503a95c6ecd9be2fd2dc53
    Security

    Rarible vulnerability allowed stealing all NFTs from a user’s wallet

    AdministratorBy Administrator14.04.2022No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Reading time: ~2 m


    Check Point Research (CPR) has discovered a vulnerability in the Rarible NFT marketplace. The exploit would allow an attacker to withdraw all the assets from the wallet of any of the two million users in one transaction.

    A successful attack could have happened with a malicious NFT on the platform. Users in this case are less suspicious and they are familiar with the procedure for sending transactions, experts noted.

    The probable attack methodology in CPR was described as follows:

    • the victim receives a link to the token containing the script or clicks on it while browsing the site;
    • JavaScript code being executed tries to send a setApprovalForAll request to the user;
    • the victim confirms it and grants the attacker full access to their assets.

    According to experts, they were motivated to check the security of Rarible for the possibility of such an attack, because they had already encountered a similar incident. On April 1, Taiwanese singer Jay Chou was tricked into confirming a transaction, after which his NFT Bored Ape #3738 was sold on the marketplace for $500,000.

    Also, CPR specialists relied on the results of their study of the OpenSea marketplace in October 2021, during which they discovered critical vulnerabilities.

    According to the blog, on April 5, the company reported its findings to the Rarible team, who “acknowledged the bug and fixed it.”

    However, experts advised users to be careful when receiving requests, even on the marketplace itself. In case of any doubt, they recommended rejecting such proposals.

    Recall that in January, a vulnerability was discovered in the OpenSea listing function that allowed redeeming tokens at a reduced price. Only one of the users through API marketplace on Rarible received 347 ETH through fraud.

    The cumulative losses amounted to 750 ETH, which OpenSea reimbursed to customers.




    #Rarible #vulnerability #allowed #stealing #NFTs #users #wallet

    allowed NFTs Rarible stealing users Vulnerability Wallet
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Avatar of Administrator
    Administrator

    Related Posts

    The scammer stole almost a million Arbitrum tokens

    01.04.2023

    Cardano users will be able to deploy Ethereum smart contracts directly

    31.03.2023

    The developer of the game Final Fantasy VII has released a deluxe series of NFTs

    31.03.2023

    Binance Launches Web 3.0 DeFi Wallet

    31.03.2023
    Add A Comment

    Leave A Reply Cancel Reply

    Recent Posts
    • US authorities launched a targeted campaign against cryptocurrencies: the opinion of the head of Galaxy Digital
    • SpaceX will deliver a chest with a private key to 62 bitcoins to the moon
    • “You can’t trade crypto without technical analysis,” Ilya Solovey
    • the future of banks is determined not by banks, but by bitcoin
    • Big Week for Ethereum Scaling Technologies
    Recent Comments
    • 수원출장 on A professor from a US university restored the Tornado Cash code to GitHub
    • 123 on Taproot support added to LND Lightning client
    • houston junk car buyer on 16,000% increase in social media mentions in 2021 Shiba inu
    • Jim Carrey Memy on Bitwise Launches NFT Tracking Index Fund
    • hotshot bald cop on Kava developers launch testnet with EVM support
    Archives
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    Categories
    • Altcoins
    • Analytics
    • Bitcoin
    • Blockchain
    • Ethereum
    • ICO
    • Mining
    • Other
    • Regulators
    • Security
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Top Posts

    Subscribe to Updates

    Get the latest sports news from SportsSite about soccer, football and tennis.

    Advertisement
    Demo
    Facebook Twitter Instagram Telegram
    • Home
    • Bitcoin
    • Ethereum
    • ICO
    © 2023 Bt-Crow.com - CryptoNews

    Type above and press Enter to search. Press Esc to cancel.