• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

2 Million Users’ NFTs At Risk After Security Firm Identifies Flaw In Rarible

April 19, 2022
in Australian Crypto News
Reading Time: 2min read
0 0
A A
0
2 Million Users’ NFTs At Risk After Security Firm Identifies Flaw In Rarible
0
SHARES
3
VIEWS
ShareShareShareShareShare

Cyber security software firm Check Point Research (CPR) has identified a vulnerability in NFT marketplace Rarible that could have seen any of its 2 million monthly users lose their NFTs in a single transaction.

Attackers Could Have Gained Full Access

CPR has previously identified exploits, among them the infamous hack of OpenSea in October 2021. According to CPR:

CPR identified a security flaw in Rarible, the NFT marketplace with over two million active users. If exploited, the vulnerability would have enabled a threat actor to steal a user’s NFTs and crypto tokens in a single transaction. CPR immediately disclosed findings to Rarible, who acknowledged the security flaw. CPR’s revelations mark the second time that their researchers discovered security flaws in an NFT marketplace. In October 2021, CPR found security issues in OpenSea, the world’s largest NFT marketplace.

Check Point Research

According to CPR, the exploit would have occurred when a malicious NFT within Rarible’s marketplace itself, where users are less suspicious and familiar with submitting transactions, and the exploit would have begun with the victim receiving a link to a malicious NFT who then clicks on it.

Attack Methodology

CPR has provided outlines of the attack methodology:

  • Victims receive a link to the malicious NFT or browse the marketplace and click on it.
  • The malicious NFT executes JavaScript code and attempts to send a setApprovalForAll request to the victim.
  • The victim submits the request and grants full access to the NFTs/crypto tokens to the attacker.

CPR immediately disclosed the findings to Rarible, which has since acknowledged the security flaw and taken action against the attack.

NFT Thefts Rampant

Earlier this year, Crypto News Australia reported a flaw on multibillion-dollar GameFi company Illuvium that caused it to drain its liquidity pools. Had it not done so, the flaw could have ended in billions of dollars lost due to the flaw.

Share this article

Join in the conversation on this article’s Twitter thread.

Disclaimer:
The content and views expressed in the articles are those of the original authors own and are not necessarily the views of Crypto News. We do actively check all our content for accuracy to help protect our readers. This article content and links to external third-parties is included for information and entertainment purposes. It is not financial advice. Please do your own research before participating.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Beanstalk Stablecoin Loses $182 Million In Flash Loan Exploit

Next Post

ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

Next Post
ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

You might also like

XRP Price Could Stage 1,500% Rally To $20 If It Mirrors This 2017 Move

XRP Price Could Stage 1,500% Rally To $20 If It Mirrors This 2017 Move

March 10, 2026
Investors Accuse JPMorgan of Facilitating $328M Crypto Fraud

Investors Accuse JPMorgan of Facilitating $328M Crypto Fraud

March 13, 2026
Aave Oracle Glitch Causes $27M Liquidations: CAPO Misconfiguration Confirmed

Aave Oracle Glitch Causes $27M Liquidations: CAPO Misconfiguration Confirmed

March 11, 2026
TRUMP Memecoin Investors Offered Mar-a-Lago Presidential Meeting

TRUMP Memecoin Investors Offered Mar-a-Lago Presidential Meeting

March 14, 2026

Bitcoin Price Prediction: Elon Musk’s X Money Could Beat Bitcoin, Claims Famous Analyst

March 12, 2026
AAVE Price Prediction: Testing $240 Breakout with $280 Medium-Term Target Despite Bearish Momentum

AAVE Price Prediction: Targets $135-140 Recovery by April 2026

March 8, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Ethereum Currently Undervalued – But Is It Time To Buy?

Ethereum Currently Undervalued – But Is It Time To Buy?

March 15, 2026
Crypto Leaders Push Back After Boris Johnson Calls Bitcoin a Ponzi

Crypto Leaders Push Back After Boris Johnson Calls Bitcoin a Ponzi

March 15, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.