Cryptocurrency

Tweet thread by 0xQuit

2023-04-21 [vendor] Blur bid acceptance bug [chain] ethereum
Primary Source ↗
Blockchain(s) Ethereum

Incident Details

The Blur NFT marketplace appeared to become vulnerable to a bug in which old, canceled bids could still be accepted. This meant that people who had placed bids on NFTs when they were selling for higher prices, then canceled them, suddenly found those purchases going through — in some cases on NFTs that were selling for considerably less.Blur disabled bid acceptance functionality while investigating the bug. Amusingly, this led people to begin placing huge bids they knew couldn’t be accepted in order to farm Blur points, some kinds of which are awarded based on bids rather than purchases.It’s not clear how much money was lost due to the bug, but Blur cofounder “Pacman” announced that “any losses will be refunded once the issue is resolved”.

Technical Details

Initial Attack Vector
Software bug / unintentional loss
Vendor / Product
Blur bid acceptance bug

Timeline

  1. 2023-04-21 Breach occurred
  2. 2023-04-21 Publicly disclosed