

NFT
What We Know About The Contract Vulnerability Worrying Web3 – Crypto News
Today, thirdweb—creators of a popular web3 development toolkit—disclosed the existence of a major vulnerability in an open-source code library that is widely-used in smart contracts throughout web3.
According to thirdweb, this vulnerability was present—but not yet taken advantage of—in a number of thirdweb’s pre-built smart contracts. “Based on our investigation so far, this vulnerability has not been exploited in any thirdweb smart contracts. However, smart contract owners must take mitigation steps on certain pre-built smart contracts that were created on thirdweb prior to November 22nd, 2023 at 7pm PT,” they said in a post on X.
Thirdweb noted that the vulnerability may have been present in some of the pre-built contracts that their users had set up to drop fungible or non-fungible tokens—including some ERC20, ERC721 and ERC1155s.
While they have not disclosed the nature of the vulnerability—stating on their newly-launched mitigation website that this would risk the security of others—thirdweb have included a full list of their affected contracts on that site, and have provided detailed instructions and tools for their users who need to take immediate steps to mitigate the risk. “In most cases, the mitigation steps will involve locking the contract, taking a snapshot and migrating to a new contract without the known vulnerability. The exact steps you need to take will depend on the nature of your smart contract, and you can determine these using the [mitigation] tool,” they said on X.
At present, the extent of where and how this vulnerable open-source library is deployed in other smart contracts across the web3 ecosystem is confirmed—which is causing concern across web3, with developers, builders and creators fielding worried questions from clients and colleagues. “Has anything actually been disclosed? I’ve seen this ‘we found something’ post and a bunch of others like Rarible saying ‘they found something’ but no one has said what it is or what to do or even what is impacted exactly. It’s a little frustrating because I woke up to a dozen panicked emails from various projects I’ve worked on saying ‘are we impacted? What do we need to do??’ And all I can say is ‘no idea, we just have to wait and see what gets revealed in the coming days,’” Sean Bonner, artist and veteran project creator, told nft now. “It would have been nice if the announcement also included the fix instead of just launching everyone into the unknown,” he said.
As thirdweb’s contracts have been commonly used to create NFT collections, marketplaces have been quick to respond, including OpenSea, Coinbase NFT and Rarible, which used affected thirdweb contracts in a number of drops. Although information is still sparse, the marketplaces have taken public steps to reassure users. In a post on X, Rarible addressed creators. “If your drop was on Polygon, there’s nothing you need to do. We are mitigating the issue, and we will be in touch when the solution has been implemented. If your drop was on Ethereum, you don’t need to do anything yet. We will address the vulnerability, and will be in touch with a plan for redistributing tokens on a secured contract. We will continue to monitor this issue & keep our users informed,” they posted.
“OpenSea is in touch with thirdweb after their disclosure of a security vulnerability that impacts a subset of collections,” their spokesperson told nft now. “Thirdweb has published a blog post that outlines the steps creators can take to migrate their collections to a new smart contract without the known vulnerability. We strongly encourage impacted collection owners to take action, and we are evaluating how to support the newly migrated collections on OpenSea,” they said.
Although the issue’s underlying cause is linked to third-party tooling, the OpenSea team is coordinating closely with thirdweb to support a resolution, while taking proactive measures on their own platform to ensure user safety. They also emphasized that their own SeaDrop contract is not affected. In response to a question on X, OpenSea business development lead Will Brooke underscored this point. “Confirmed—does not affect ERC721SeaDrop,” he wrote.

OpenZeppelin, the secure blockchain standard whose libraries may have been involved in the disclosed vulnerability, offered a a write-up on X, sharing early results from their enquiry that may reassure a worried web3 community. “Based on our investigation, the issue is inherent to a problematic integration of specific patterns, and NOT particular to the implementations contained in the OpenZeppelin Contracts library. Nonetheless, we will lead the effort to assess who in the community is affected and provide them with mitigation strategies. At the appropriate time, we will responsibly disclose this vulnerability following best practices for the safety of the community,” they wrote. They also assured the public that after giving those affected time to mitigate the vulnerability, they will disclose it in accordance with responsible cybersecurity practices.
The post What We Know About The Contract Vulnerability Worrying Web3 appeared first on nft now.
-
others1 week ago
Customer Who Stole $830,000 From Wells Fargo After Initiating Fraudulent Payments Sentenced to Prison – Crypto News
-
Cryptocurrency1 week ago
Shiba Inu burn surges 2,408%: Can SHIB finally escape bearish pressure? – Crypto News
-
Blockchain1 week ago
American Rapper Cardi B Endorses WAP Token Again—But Is It A Rugpull? – Crypto News
-
others1 week ago
XRP Price Prediction for June: Key Levels to Watch as Technicals Flash 2017 Bull Signs – Crypto News
-
Metaverse1 week ago
Samsung tapping Perplexity AI for all devices — what does this mean for you? – Crypto News
-
Cryptocurrency1 week ago
Top crypto predictions: XRP, Monero, Bitcoin Pepe – Crypto News
-
Cryptocurrency1 week ago
$106,313,218 Solana (SOL) In One Transfer — What Happened? – Crypto News
-
Cryptocurrency1 week ago
Crypto ATM scams in Australia cause over AUD 3.1 million in losses – Crypto News
-
Technology1 week ago
Final Fantasy Tactics returns once again with remastered edition – The Ivalice Chronicles; all details here – Crypto News
-
others1 week ago
‘Nothing Stops This Train’ – Macro Guru Lyn Alden Warns Fed Has No Way To Slow Down Debt Growth in US Financial System – Crypto News
-
Cryptocurrency1 week ago
Ethereum’s Pectra Upgrade leaves massive loophole for scammers – Crypto News
-
Cryptocurrency1 week ago
Ethereum retests $2,500 as companies bet big on ETH – Crypto News
-
Technology1 week ago
Why are people choosing smart rings over smartwatches in 2025 – Crypto News
-
Cryptocurrency1 week ago
what’s fueling the June crypto rally? – Crypto News
-
Technology1 week ago
Apple WWDC 2025: How to watch the keynote and what all to expect – Crypto News
-
Blockchain1 week ago
JPMorgan to Accept Bitcoin ETFs as Loan Collateral – Crypto News
-
Technology7 days ago
Best water purifiers under ₹15000: Explore the top 6 options from Aquaguard, Urban Company and more – Crypto News
-
Cryptocurrency1 week ago
XRP Saved? Bears Not Taking Control – Crypto News
-
others1 week ago
Bitcoin Rises As FED Chair Jerome Powell Fails To Speak On Economic Outlook – Crypto News
-
Business1 week ago
From Buffett to Zuck: Satoshi Bitcoin Wealth on Path to Surpass Tech and Finance Titans – Crypto News
-
others1 week ago
Pound Sterling Price News and Forecast: GBP/USD steadies near 1.3540 – Crypto News
-
Cryptocurrency1 week ago
Cardano Price Downside Extends As Ethereum Upsurge Adds Pressure – Crypto News
-
others1 week ago
WTI Crude Oil extends gains as Canada wildfires, geopolitical tensions, and a broadly weaker US Dollar support prices – Crypto News
-
Technology1 week ago
Wi-Fi router buying guide: Speed, range and smart home tips – Crypto News
-
others1 week ago
Australian Dollar holds ground as Q1 GDP expands 0.2% QoQ – Crypto News
-
Technology1 week ago
Google Search now shows AI-generated weather snapshots for select users: Report – Crypto News
-
Technology1 week ago
Top 5 AI tools in 2025 to boost your productivity, stay ahead and help you save time – Crypto News
-
others1 week ago
Canadian Dollar lurches into fresh highs after BoC holds off on rate cuts – Crypto News
-
Cryptocurrency4 days ago
French Exoskeleton Company Wandercraft Pivots to Humanoid Robots – Crypto News
-
Cryptocurrency4 days ago
French Exoskeleton Company Wandercraft Pivots to Humanoid Robots – Crypto News
-
Blockchain1 week ago
Solana Analyst Sets $300 Target – Can Bulls Sustain A Rally? – Crypto News
-
others5 days ago
Gold prices fall as the USD extends gains post NFP – Crypto News
-
Technology4 days ago
Gemini can now schedule tasks, send reminders and keep you on track: Here’s how it works – Crypto News
-
Blockchain3 days ago
Ethereum Price Performance Could Hinge On This Binance Metric — Here’s Why – Crypto News
-
Blockchain2 days ago
OpenLedger Invests $25 Million to Combat ‘Extractive’ AI Economy – Crypto News
-
others1 week ago
BlackRock Analyst Warns of Overexposure to US Markets, Says One Country On Right Side of Incoming ‘Tectonic Shifts’ – Crypto News
-
Cryptocurrency1 week ago
Pi Coin slumps amid renewed migration activity on Pi Network – Crypto News
-
Technology1 week ago
Nintendo Can’t Afford a Slip Up With Switch 2 – Crypto News
-
Technology1 week ago
Dashcam buying guide: 5 things to know before making a purchase in 2025 – Crypto News
-
Blockchain1 week ago
JPMorgan Plans to Allow Financing Against Crypto ETFs: Report – Crypto News
-
Cryptocurrency1 week ago
Best crypto to buy as Truth Social files for a Spot Bitcoin ETF – Crypto News
-
Technology7 days ago
Why Anthropic CEO Dario Amodei thinks a 10-year AI regulation freeze is dangerous – Crypto News
-
Technology6 days ago
The Quiet Voices Questioning China’s AI Hype – Crypto News
-
Cryptocurrency6 days ago
Donald Trump Ready to Ditch His Tesla Amid Musk Feud? (Report) – Crypto News
-
Cryptocurrency5 days ago
Trump-Elon feud Erupts, Crypto falls, Coinbase to list Fartcoin – Crypto News
-
Business1 week ago
$3.5B UK Firm Opens XRP Spot Trading In Retail Crypto Push – Crypto News
-
Business1 week ago
$3.5B UK Firm Opens XRP Spot Trading In Retail Crypto Push – Crypto News
-
Business1 week ago
Just-In: BlackRock Breaks Acccumulation Streak, Moves $429M In Bitcoin To Coinbase Prime – Crypto News
-
Business1 week ago
Strategy Announces STRD Offering To Facilitate More Bitcoin Purchases – Crypto News
-
others1 week ago
EUR/USD slips as Greenback gains on data surge, trade fears rattle markets – Crypto News