

NFT
What We Know About The Contract Vulnerability Worrying Web3 – Crypto News
Today, thirdweb—creators of a popular web3 development toolkit—disclosed the existence of a major vulnerability in an open-source code library that is widely-used in smart contracts throughout web3.
According to thirdweb, this vulnerability was present—but not yet taken advantage of—in a number of thirdweb’s pre-built smart contracts. “Based on our investigation so far, this vulnerability has not been exploited in any thirdweb smart contracts. However, smart contract owners must take mitigation steps on certain pre-built smart contracts that were created on thirdweb prior to November 22nd, 2023 at 7pm PT,” they said in a post on X.
Thirdweb noted that the vulnerability may have been present in some of the pre-built contracts that their users had set up to drop fungible or non-fungible tokens—including some ERC20, ERC721 and ERC1155s.
While they have not disclosed the nature of the vulnerability—stating on their newly-launched mitigation website that this would risk the security of others—thirdweb have included a full list of their affected contracts on that site, and have provided detailed instructions and tools for their users who need to take immediate steps to mitigate the risk. “In most cases, the mitigation steps will involve locking the contract, taking a snapshot and migrating to a new contract without the known vulnerability. The exact steps you need to take will depend on the nature of your smart contract, and you can determine these using the [mitigation] tool,” they said on X.
At present, the extent of where and how this vulnerable open-source library is deployed in other smart contracts across the web3 ecosystem is confirmed—which is causing concern across web3, with developers, builders and creators fielding worried questions from clients and colleagues. “Has anything actually been disclosed? I’ve seen this ‘we found something’ post and a bunch of others like Rarible saying ‘they found something’ but no one has said what it is or what to do or even what is impacted exactly. It’s a little frustrating because I woke up to a dozen panicked emails from various projects I’ve worked on saying ‘are we impacted? What do we need to do??’ And all I can say is ‘no idea, we just have to wait and see what gets revealed in the coming days,’” Sean Bonner, artist and veteran project creator, told nft now. “It would have been nice if the announcement also included the fix instead of just launching everyone into the unknown,” he said.
As thirdweb’s contracts have been commonly used to create NFT collections, marketplaces have been quick to respond, including OpenSea, Coinbase NFT and Rarible, which used affected thirdweb contracts in a number of drops. Although information is still sparse, the marketplaces have taken public steps to reassure users. In a post on X, Rarible addressed creators. “If your drop was on Polygon, there’s nothing you need to do. We are mitigating the issue, and we will be in touch when the solution has been implemented. If your drop was on Ethereum, you don’t need to do anything yet. We will address the vulnerability, and will be in touch with a plan for redistributing tokens on a secured contract. We will continue to monitor this issue & keep our users informed,” they posted.
“OpenSea is in touch with thirdweb after their disclosure of a security vulnerability that impacts a subset of collections,” their spokesperson told nft now. “Thirdweb has published a blog post that outlines the steps creators can take to migrate their collections to a new smart contract without the known vulnerability. We strongly encourage impacted collection owners to take action, and we are evaluating how to support the newly migrated collections on OpenSea,” they said.
Although the issue’s underlying cause is linked to third-party tooling, the OpenSea team is coordinating closely with thirdweb to support a resolution, while taking proactive measures on their own platform to ensure user safety. They also emphasized that their own SeaDrop contract is not affected. In response to a question on X, OpenSea business development lead Will Brooke underscored this point. “Confirmed—does not affect ERC721SeaDrop,” he wrote.

OpenZeppelin, the secure blockchain standard whose libraries may have been involved in the disclosed vulnerability, offered a a write-up on X, sharing early results from their enquiry that may reassure a worried web3 community. “Based on our investigation, the issue is inherent to a problematic integration of specific patterns, and NOT particular to the implementations contained in the OpenZeppelin Contracts library. Nonetheless, we will lead the effort to assess who in the community is affected and provide them with mitigation strategies. At the appropriate time, we will responsibly disclose this vulnerability following best practices for the safety of the community,” they wrote. They also assured the public that after giving those affected time to mitigate the vulnerability, they will disclose it in accordance with responsible cybersecurity practices.
The post What We Know About The Contract Vulnerability Worrying Web3 appeared first on nft now.
-
Blockchain1 week ago
Crypto execs cheer as Australia appoints pro-crypto assistant minister – Crypto News
-
Business6 days ago
How Mid-Sized Treasurers Are Managing Liquidity Amid Uncertainty – Crypto News
-
Blockchain1 week ago
US property manager tokenizes multifamily properties on Chintai blockchain – Crypto News
-
Blockchain1 week ago
Top Expert Declares It The Best Crypto To Buy Now – Crypto News
-
Business1 week ago
No Truth to Truth Social Memecoin: World Liberty Financial Clarifies – Crypto News
-
others1 week ago
Why Is Crypto Market Down When S&P 500 Flashes Bull Run Ahead? – Crypto News
-
others1 week ago
Hackers Attempting To Extort School Employees via Email After Millions of Students’ Personal Data Leaked in Breach: Report – Crypto News
-
Business1 week ago
XRP Flips Tether’s USDT By Market Cap Reclaiming 3rd Spot, Price Rally To $3? – Crypto News
-
Business1 week ago
Crypto News: Animoca Brands Eye NYSE Listing Amid Donald Trump’s Crypto Push – Crypto News
-
others1 week ago
MoonX: BYDFi’s On-Chain Trading Engine — A Ticket from CEX to DEX – Crypto News
-
others1 week ago
Analyst Sees Crypto Repeating Dot-Com Bubble, Predicts Rallies for XRP and One Solana Challenger – Crypto News
-
Technology1 week ago
XRP Price Prediction as Binance Data Reveals Early Signs Of Bull Run – Crypto News
-
others1 week ago
SEC Crypto Roundtable: Paul Atkins Vows To Make US Crypto Capital Of The World – Crypto News
-
others1 week ago
Investor Kidnapped, Driven to Remote Desert and Robbed of $4,000,000 in Cryptocurrency by Teenagers: Report – Crypto News
-
others1 week ago
USD/JPY falls below 148.00 despite persistent uncertainty over BoJ’s policy outlook – Crypto News
-
Metaverse1 week ago
Why AI is central to the new browser wars – Crypto News
-
Business1 week ago
Can WIF Price Hit $2? Pattern Breakout and 100% OI Surge to $445M Signal Major Upside – Crypto News
-
others1 week ago
AUD/USD gains after softer CPI data from the US and trade developments – Crypto News
-
others1 week ago
Breaking: US SEC Delays Decision on Grayscale Spot Solana and Litecoin ETFs – Crypto News
-
Technology1 week ago
Best wireless soundbars in 2025: Top 10 picks to elevate your home audio experience – Crypto News
-
Blockchain1 week ago
10 Signs a Crypto Investment Platform Is a Scam—and How to Avoid It – Crypto News
-
Technology1 week ago
Pi Coin Crashes 33% As Pi Network Community Screams ‘Betrayal’ – Crypto News
-
Business1 week ago
Bitcoin Price Risks Dropping Below $100k As Crypto Liquidations Hit $714M – Crypto News
-
others1 week ago
Pepe Coin Price Outperforms DOGE and SHIB, Targets 80% Upside Post-Retest – Crypto News
-
Blockchain1 week ago
Top Expert Declares It The Best Crypto To Buy Now – Crypto News
-
Technology1 week ago
iQOO Neo 10 vs Motorola Edge 60 Pro: Which smartphone to buy under Rs.35000 – Crypto News
-
others1 week ago
Silver trims early gains, holds above 50-day EMA as weak US CPI tempers Fed tightening bets – Crypto News
-
Cryptocurrency1 week ago
Ripple (XRP) Price Analysis: $5.5 Billion XRP Open Interest Signals Positive Reaction to Paul Atkins’ Latest Update – Crypto News
-
Business1 week ago
Ripple (XRP) Price Analysis: $5.5 Billion XRP Open Interest Signals Positive Reaction to Paul Atkins’ Latest Update – Crypto News
-
Technology1 week ago
Ripple (XRP) Price Analysis: $5.5 Billion XRP Open Interest Signals Positive Reaction to Paul Atkins’ Latest Update – Crypto News
-
Blockchain1 week ago
Alarm bells ring in US over OpenAI’s crypto project World – Crypto News
-
others1 week ago
Tests 100.50 support, with nine-day EMA providing backing – Crypto News
-
Business1 week ago
COIN Stock Soars 23% Ahead of Coinbase’s May 19 Debut on S&P 500 – Crypto News
-
Cryptocurrency1 week ago
Why investors should say ‘no’ more often – Crypto News
-
Cryptocurrency1 week ago
Why investors should say ‘no’ more often – Crypto News
-
others1 week ago
Nifty 50 Index Elliott Wave technical analysis [Video] – Crypto News
-
others6 days ago
Crypto Trader Prints 517x Profit on Solana-Based Altcoin That’s Exploded 7,000% in Just One Week: Lookonchain – Crypto News
-
Blockchain6 days ago
Stablecoin bill passes in Northern Marianas as House overrides veto – Crypto News
-
others6 days ago
Dogecoin On-Chain Metrics Hint At DOGE Mega Rally Ahead – Crypto News
-
Blockchain6 days ago
Solana Poised For Upside Move After A Bounce From $168 – Crypto News
-
others6 days ago
XRP Futures ETF Goes Live on May 19: Will It Beat ETH And BTC Debut? – Crypto News
-
Cryptocurrency6 days ago
Top crypto to buy as Saudi Central Bank reveals exposure to MSTR – Crypto News
-
Cryptocurrency6 days ago
UK confirms crypto tax data rules under CARF; first deadline set for May 2027 – Crypto News
-
Technology6 days ago
Coinbase estimates $400M cost after data breach and crypto scam – Crypto News
-
Business5 days ago
World Liberty Financial Partners Chainlink To Enable USD1 Stablecoin Cross-Chain Transfers – Crypto News
-
Blockchain5 days ago
Bitcoin Panic Buying? Eric Trump Says the World Is Stockpiling BTC – Crypto News
-
Cryptocurrency5 days ago
Ripple’s XRP may enable BRICS to ditch dollar and settle trade in gold – Crypto News
-
Technology5 days ago
XRP Price Impact If GENIUS Act Boosts Ripple’s RLUSD Market Cap to 50% of Tether’s $150B – Crypto News
-
Cryptocurrency1 week ago
XRP Price Nears $2.50 Support As Fundamentals Bring Record Highs In Sight – Crypto News
-
Technology1 week ago
Samsung Galaxy Z Fold 7 tipped to outsize last-gen Z Fold 6: Check details – Crypto News