• Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021
No Result
View All Result
CryptoABC.net
No Result
View All Result

2 Million Users’ NFTs At Risk After Security Firm Identifies Flaw In Rarible

April 19, 2022
in Australian Crypto News
Reading Time: 2min read
0 0
A A
0
2 Million Users’ NFTs At Risk After Security Firm Identifies Flaw In Rarible
0
SHARES
4
VIEWS
ShareShareShareShareShare

Cyber security software firm Check Point Research (CPR) has identified a vulnerability in NFT marketplace Rarible that could have seen any of its 2 million monthly users lose their NFTs in a single transaction.

Attackers Could Have Gained Full Access

CPR has previously identified exploits, among them the infamous hack of OpenSea in October 2021. According to CPR:

CPR identified a security flaw in Rarible, the NFT marketplace with over two million active users. If exploited, the vulnerability would have enabled a threat actor to steal a user’s NFTs and crypto tokens in a single transaction. CPR immediately disclosed findings to Rarible, who acknowledged the security flaw. CPR’s revelations mark the second time that their researchers discovered security flaws in an NFT marketplace. In October 2021, CPR found security issues in OpenSea, the world’s largest NFT marketplace.

Check Point Research

According to CPR, the exploit would have occurred when a malicious NFT within Rarible’s marketplace itself, where users are less suspicious and familiar with submitting transactions, and the exploit would have begun with the victim receiving a link to a malicious NFT who then clicks on it.

Attack Methodology

CPR has provided outlines of the attack methodology:

  • Victims receive a link to the malicious NFT or browse the marketplace and click on it.
  • The malicious NFT executes JavaScript code and attempts to send a setApprovalForAll request to the victim.
  • The victim submits the request and grants full access to the NFTs/crypto tokens to the attacker.

CPR immediately disclosed the findings to Rarible, which has since acknowledged the security flaw and taken action against the attack.

NFT Thefts Rampant

Earlier this year, Crypto News Australia reported a flaw on multibillion-dollar GameFi company Illuvium that caused it to drain its liquidity pools. Had it not done so, the flaw could have ended in billions of dollars lost due to the flaw.

Share this article

Join in the conversation on this article’s Twitter thread.

Disclaimer:
The content and views expressed in the articles are those of the original authors own and are not necessarily the views of Crypto News. We do actively check all our content for accuracy to help protect our readers. This article content and links to external third-parties is included for information and entertainment purposes. It is not financial advice. Please do your own research before participating.


Credit: Source link

ShareTweetSendPinShare
Previous Post

Beanstalk Stablecoin Loses $182 Million In Flash Loan Exploit

Next Post

ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

Next Post
ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

ETH Privacy Tool Tornado Cash Starts Blocking Sanctioned Addresses

You might also like

Bitcoin Moves Into Accumulation Zone That Will Send It On Next All-Time High Run To $250,000

Bitcoin Moves Into Accumulation Zone That Will Send It On Next All-Time High Run To $250,000

June 2, 2026
After a $60M short assault, Aave recommends governance reforms.

AAVE Price Prediction: Oversold Bounce to $80 Within 48 Hours as Whales Load Up

June 4, 2026
The Rapid XRP Growth Trajectory That Investors Should Be Aware Of

The Rapid XRP Growth Trajectory That Investors Should Be Aware Of

June 3, 2026
Pundit Says Dogecoin Is About To Do Something Insane, Here’s What

Pundit Says Dogecoin Is About To Do Something Insane, Here’s What

June 3, 2026
Bitcoin Falls Below $66K As Short-Term Holder Stress Reaches February Levels

Bitcoin Falls Below $66K As Short-Term Holder Stress Reaches February Levels

June 4, 2026
Bloomberg’s Weisenthal Lists 12 Reasons

Bloomberg’s Weisenthal Lists 12 Reasons

June 3, 2026
CryptoABC.net

This is an Australian online news/education portal that aims to provide the latest crypto news, real-time updates, education and reviews within Australia and around the world. Feel free to get in touch with us!

What's New Here!

This ChatGPT AI XRP Price Prediction Should Not Make Sense But It Does

This ChatGPT AI XRP Price Prediction Should Not Make Sense But It Does

June 8, 2026
Dogecoin Will ‘Pump Hard’ After This Happens, Analyst Clocks Generational Entry

Dogecoin Will ‘Pump Hard’ After This Happens, Analyst Clocks Generational Entry

June 8, 2026

Subscribe Now

  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 cryptoabc.net - All rights reserved!

No Result
View All Result
  • Live Crypto Prices
  • Crypto News
    • Worldwide
      • Bitcoin
      • Ethereum
      • Altcoin
      • Blockchain
      • Regulation
    • Australian Crypto News
  • Education
    • Cryptocurrency For Beginners
    • Where to Buy Cryptocurrency
    • Where to Store Cryptos
    • Cryptocurrency Tax in Australia 2021

© 2021 cryptoabc.net - All rights reserved!

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter CoinGecko Free Api Key to get this plugin works.