

NFT
What We Know About The Contract Vulnerability Worrying Web3 – Crypto News
Today, thirdweb—creators of a popular web3 development toolkit—disclosed the existence of a major vulnerability in an open-source code library that is widely-used in smart contracts throughout web3.
According to thirdweb, this vulnerability was present—but not yet taken advantage of—in a number of thirdweb’s pre-built smart contracts. “Based on our investigation so far, this vulnerability has not been exploited in any thirdweb smart contracts. However, smart contract owners must take mitigation steps on certain pre-built smart contracts that were created on thirdweb prior to November 22nd, 2023 at 7pm PT,” they said in a post on X.
Thirdweb noted that the vulnerability may have been present in some of the pre-built contracts that their users had set up to drop fungible or non-fungible tokens—including some ERC20, ERC721 and ERC1155s.
While they have not disclosed the nature of the vulnerability—stating on their newly-launched mitigation website that this would risk the security of others—thirdweb have included a full list of their affected contracts on that site, and have provided detailed instructions and tools for their users who need to take immediate steps to mitigate the risk. “In most cases, the mitigation steps will involve locking the contract, taking a snapshot and migrating to a new contract without the known vulnerability. The exact steps you need to take will depend on the nature of your smart contract, and you can determine these using the [mitigation] tool,” they said on X.
At present, the extent of where and how this vulnerable open-source library is deployed in other smart contracts across the web3 ecosystem is confirmed—which is causing concern across web3, with developers, builders and creators fielding worried questions from clients and colleagues. “Has anything actually been disclosed? I’ve seen this ‘we found something’ post and a bunch of others like Rarible saying ‘they found something’ but no one has said what it is or what to do or even what is impacted exactly. It’s a little frustrating because I woke up to a dozen panicked emails from various projects I’ve worked on saying ‘are we impacted? What do we need to do??’ And all I can say is ‘no idea, we just have to wait and see what gets revealed in the coming days,’” Sean Bonner, artist and veteran project creator, told nft now. “It would have been nice if the announcement also included the fix instead of just launching everyone into the unknown,” he said.
As thirdweb’s contracts have been commonly used to create NFT collections, marketplaces have been quick to respond, including OpenSea, Coinbase NFT and Rarible, which used affected thirdweb contracts in a number of drops. Although information is still sparse, the marketplaces have taken public steps to reassure users. In a post on X, Rarible addressed creators. “If your drop was on Polygon, there’s nothing you need to do. We are mitigating the issue, and we will be in touch when the solution has been implemented. If your drop was on Ethereum, you don’t need to do anything yet. We will address the vulnerability, and will be in touch with a plan for redistributing tokens on a secured contract. We will continue to monitor this issue & keep our users informed,” they posted.
“OpenSea is in touch with thirdweb after their disclosure of a security vulnerability that impacts a subset of collections,” their spokesperson told nft now. “Thirdweb has published a blog post that outlines the steps creators can take to migrate their collections to a new smart contract without the known vulnerability. We strongly encourage impacted collection owners to take action, and we are evaluating how to support the newly migrated collections on OpenSea,” they said.
Although the issue’s underlying cause is linked to third-party tooling, the OpenSea team is coordinating closely with thirdweb to support a resolution, while taking proactive measures on their own platform to ensure user safety. They also emphasized that their own SeaDrop contract is not affected. In response to a question on X, OpenSea business development lead Will Brooke underscored this point. “Confirmed—does not affect ERC721SeaDrop,” he wrote.

OpenZeppelin, the secure blockchain standard whose libraries may have been involved in the disclosed vulnerability, offered a a write-up on X, sharing early results from their enquiry that may reassure a worried web3 community. “Based on our investigation, the issue is inherent to a problematic integration of specific patterns, and NOT particular to the implementations contained in the OpenZeppelin Contracts library. Nonetheless, we will lead the effort to assess who in the community is affected and provide them with mitigation strategies. At the appropriate time, we will responsibly disclose this vulnerability following best practices for the safety of the community,” they wrote. They also assured the public that after giving those affected time to mitigate the vulnerability, they will disclose it in accordance with responsible cybersecurity practices.
The post What We Know About The Contract Vulnerability Worrying Web3 appeared first on nft now.
-
Technology1 week ago
Chip Designer Arm Plans to Become Chip Manufacturer – Crypto News
-
Cryptocurrency3 days ago
SUI eyes 24% rally as bullish price action gains strength – Crypto News
-
others6 days ago
Japanese Yen remains depressed amid modest USD strength; downside seems limited – Crypto News
-
Technology1 week ago
MacBook Air M3 15-inch model gets a ₹12,000 price drop on Amazon: Deal explained – Crypto News
-
Cryptocurrency2 days ago
Coinbase scores major win as SEC set to drop lawsuit – Crypto News
-
others1 week ago
Japan Foreign Investment in Japan Stocks declined to ¥-384.4B in February 7 from previous ¥-315.2B – Crypto News
-
Technology1 week ago
Perplexity takes on ChatGPT and Gemini with new Deep Research AI that completes most tasks in under 3 minutes – Crypto News
-
Technology1 week ago
Lava Pro Watch X with 1.44-inch AMOLED display, in-built GPS launched in India at ₹4,499 – Crypto News
-
Blockchain6 days ago
XRP Set To Outshine Gold? Analyst Predicts 1,000% Surge – Crypto News
-
Cryptocurrency1 week ago
Advisers on crypto: Takeaways from another survey – Crypto News
-
others1 week ago
Remains subdued below 1.4200 near falling wedge’s lower threshold – Crypto News
-
Cryptocurrency1 week ago
0xLoky Introduces AI-powered Intel for Crypto Data & On-chain Insights – Crypto News
-
Technology1 week ago
Factbox-China’s AI firms take spotlight with deals, low-cost models – Crypto News
-
Technology1 week ago
Massive price drops on Samsung Galaxy devices: Up to ₹10000 discount on Watch Ultra, Tab S10 Plus, and more – Crypto News
-
Cryptocurrency1 week ago
Tether Acquires a Minority Stake in Italian Football Giant Juventus – Crypto News
-
Blockchain1 week ago
XRP To 3 Digits? The ‘Signs’ That Could Confirm It, Basketball Analyst Says – Crypto News
-
others1 week ago
Australian Dollar jumps to highs since December on USD weakness – Crypto News
-
Technology1 week ago
Weekly Tech Recap: JioHotstar launched, Sam Altman vs Elon Musk feud intensifies, Perplexity takes on ChatGPT and more – Crypto News
-
Technology1 week ago
What will it take for India to become a global data centre hub? – Crypto News
-
Technology1 week ago
ChatGPT vs Perplexity: Sam Altman praises Aravind Srinivas’ Deep Research AI; ‘Proud of you’ – Crypto News
-
Blockchain1 week ago
NEAR Breaks Below Parallel Channel: Key Levels To Watch – Crypto News
-
Blockchain7 days ago
Will BTC Rebound Or Drop To $76,000? – Crypto News
-
Blockchain7 days ago
XRP Price Settles After Gains—Is a Fresh Upside Move Coming? – Crypto News
-
Metaverse6 days ago
How AI will divide the best from the rest – Crypto News
-
Business6 days ago
What Will be KAITO Price At Launch? – Crypto News
-
Business6 days ago
Elon Musk’s DOGE Launches Probe into US SEC, Ripple Lawsuit To End? – Crypto News
-
Blockchain6 days ago
XRP Price Pulls Back From Highs—Are Bulls Still in Control? – Crypto News
-
Business5 days ago
Whales Move From Shiba Inu to FXGuys – Here’s Why – Crypto News
-
Technology1 week ago
Best phones under ₹20,000 in February 2025: Poco X7, Motorola Edge 50 Neo and more – Crypto News
-
Blockchain1 week ago
Popular Investor Says Memecoin More Superior With ‘World’s Best Chart’ – Crypto News
-
Cryptocurrency1 week ago
Crypto narratives as we await next market move – Crypto News
-
Cryptocurrency1 week ago
Who is Satoshi Nakamoto, The Creator of Bitcoin? – Crypto News
-
Technology1 week ago
Grok 3 is coming! Elon Musk announces launch date, promises ‘smartest AI on Earth’ – Crypto News
-
Technology7 days ago
Union Minister Ashwini Vaishnaw to launch India AI Mission portal soon, 10 companies set to provide 14,000 GPUs – Crypto News
-
Business6 days ago
These 3 Altcoins Will Help You Capitalize on Stellar’s Recent DIp – Crypto News
-
others6 days ago
Forex Today: What if the RBA…? – Crypto News
-
Cryptocurrency5 days ago
Hayden Davis crypto scandal deepens as LIBRA memecoin faces fraud allegations – Crypto News
-
Technology5 days ago
Luminious inverters for your home to never see darkness again – Crypto News
-
Technology3 days ago
Stellantis Debuts System to Handle ‘Routine Driving Tasks’ – Crypto News
-
Metaverse1 week ago
Strange Love: why people are falling for their AI companions – Crypto News
-
Technology1 week ago
Former Google CEO warns of ‘Bin Laden scenario’ for AI: ‘They could misuse it and do real harm’ – Crypto News
-
Cryptocurrency1 week ago
Yap-to-earn takes over Twitter – Blockworks – Crypto News
-
Cryptocurrency1 week ago
Someone Just Won $100K in Bitcoin From a $50 Pack of Trading Cards – Crypto News
-
Technology1 week ago
Cyber fraud alert: Doctor duped of ₹15.50 lakh via fake trading app; here’s what happened – Crypto News
-
Business1 week ago
How Will It Affect Pi Coin Price? – Crypto News
-
Cryptocurrency1 week ago
GameStop Stock Price Pumps After Report of Bitcoin Buying Plans – Crypto News
-
Blockchain1 week ago
XRP Bullish Pennant Targets $15-$17 But Confirmation Is Required – Crypto News
-
Technology7 days ago
South Korea removes DeepSeek from app stores, existing users advised to ‘service with caution’ – Crypto News
-
Business6 days ago
Why Ethereum (ETH) Price Revival Could Start Soon After Solana Mess? – Crypto News
-
Business6 days ago
Market Veteran Predicts XRP Price If Ripple Completes Cup and Handle Pattern – Crypto News