Cryptocurrency
"Smart contract security vulnerability 12/4"
Primary Source ↗Blockchain(s)
Ethereum, Polygon
Incident Details
Projects using the suite of pre-built smart contracts from crypto development platform ThirdWeb have been racing to migrate to patched versions as ThirdWeb has disclosed a vulnerability affecting dozens of its contracts. Although they claim no contracts containing the vulnerability have been exploited, they’ve urged projects using them to urgently migrate to updated versions without the flaw.Projects relying on these pre-built smart contracts will have to lock the old contract and deploy new ones, then provide new versions of tokens via airdrop or a claim page — a fairly disruptive process.Major NFT marketplace OpenSea issued a statement that they were working with ThirdWeb about a vulnerability “impacting some NFT collections”. Rarible also stated that some NFT collections on their platform were affected, including some on the Polygon sidechain. Coinbase and Base also disclosed that some projects on their platforms were vulnerable. Projects by groups including Cool Cats and Mocaverse will need to be migrated.
Technical Details
- Initial Attack Vector
- Software bug / unintentional loss
- Vendor / Product
- ThirdWeb vulnerability
Timeline
- 2023-12-04 Breach occurred
- 2023-12-04 Publicly disclosed