• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

2 Million Users’ NFTs At Risk After Security Firm Identifies Flaw In Rarible

April 19, 2022
in Australian Crypto News
Reading Time: 2min read
0 0
A A
0
2 Million Users’ NFTs At Risk After Security Firm Identifies Flaw In Rarible
0
SHARES
4
VIEWS
ShareShareShareShareShare

Cyber security software firm Check Point Research (CPR) has identified a vulnerability in NFT marketplace Rarible that could have seen any of its 2 million monthly users lose their NFTs in a single transaction.

Attackers Could Have Gained Full Access

CPR has previously identified exploits, among them the infamous hack of OpenSea in October 2021. According to CPR:

CPR identified a security flaw in Rarible, the NFT marketplace with over two million active users. If exploited, the vulnerability would have enabled a threat actor to steal a user’s NFTs and crypto tokens in a single transaction. CPR immediately disclosed findings to Rarible, who acknowledged the security flaw. CPR’s revelations mark the second time that their researchers discovered security flaws in an NFT marketplace. In October 2021, CPR found security issues in OpenSea, the world’s largest NFT marketplace.

Check Point Research

According to CPR, the exploit would have occurred when a malicious NFT within Rarible’s marketplace itself, where users are less suspicious and familiar with submitting transactions, and the exploit would have begun with the victim receiving a link to a malicious NFT who then clicks on it.

Attack Methodology

CPR has provided outlines of the attack methodology:

  • Victims receive a link to the malicious NFT or browse the marketplace and click on it.
  • The malicious NFT executes JavaScript code and attempts to send a setApprovalForAll request to the victim.
  • The victim submits the request and grants full access to the NFTs/crypto tokens to the attacker.

CPR immediately disclosed the findings to Rarible, which has since acknowledged the security flaw and taken action against the attack.

NFT Thefts Rampant

Earlier this year, Crypto News Australia reported a flaw on multibillion-dollar GameFi company Illuvium that caused it to drain its liquidity pools. Had it not done so, the flaw could have ended in billions of dollars lost due to the flaw.

Share this article

Join in the conversation on this article’s Twitter thread.

Disclaimer:
The content and views expressed in the articles are those of the original authors own and are not necessarily the views of Crypto News. We do actively check all our content for accuracy to help protect our readers. This article content and links to external third-parties is included for information and entertainment purposes. It is not financial advice. Please do your own research before participating.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Beanstalk Stablecoin Loses $182 Million In Flash Loan Exploit

Next Post

ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

Next Post
ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

You might also like

Bitcoin Analyst Predicts Lowest Level Before Run To $200,000

Bitcoin Analyst Predicts Lowest Level Before Run To $200,000

April 22, 2026
Solana Nears Triangle Apex: Is A 10% Breakout Move Coming?

Solana Nears Triangle Apex: Is A 10% Breakout Move Coming?

April 28, 2026
Bitcoin Price Prediction: $50K Warns Analyst, Data Points $80K

Bitcoin Price Prediction: $50K Warns Analyst, Data Points $80K

April 24, 2026
Andreessen Horowitz to Raise $4.5B for Two New Crypto Funds

Stablecoins Shift from Speculation to Payments Infrastructure

April 24, 2026
The Crash Is Over? XRP Price About To Hit ‘Significant Bottom’

The Crash Is Over? XRP Price About To Hit ‘Significant Bottom’

April 25, 2026
Helium Network to Migrate to Solana Blockchain

Tokens.xyz Streamlines Solana (SOL) Asset Data with Unified Pages

April 25, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

Chainlink Exchange Outflows Hit 970,430 LINK, Largest Of 2026

Chainlink Exchange Outflows Hit 970,430 LINK, Largest Of 2026

April 29, 2026
XRP OI Z-Score Just Dropped To Levels Seen Before Its 600% Rally In 2024

XRP OI Z-Score Just Dropped To Levels Seen Before Its 600% Rally In 2024

April 28, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.