NFT
What We Know About The Contract Vulnerability Worrying Web3 – Crypto News
Today, thirdweb—creators of a popular web3 development toolkit—disclosed the existence of a major vulnerability in an open-source code library that is widely-used in smart contracts throughout web3.
According to thirdweb, this vulnerability was present—but not yet taken advantage of—in a number of thirdweb’s pre-built smart contracts. “Based on our investigation so far, this vulnerability has not been exploited in any thirdweb smart contracts. However, smart contract owners must take mitigation steps on certain pre-built smart contracts that were created on thirdweb prior to November 22nd, 2023 at 7pm PT,” they said in a post on X.
Thirdweb noted that the vulnerability may have been present in some of the pre-built contracts that their users had set up to drop fungible or non-fungible tokens—including some ERC20, ERC721 and ERC1155s.
While they have not disclosed the nature of the vulnerability—stating on their newly-launched mitigation website that this would risk the security of others—thirdweb have included a full list of their affected contracts on that site, and have provided detailed instructions and tools for their users who need to take immediate steps to mitigate the risk. “In most cases, the mitigation steps will involve locking the contract, taking a snapshot and migrating to a new contract without the known vulnerability. The exact steps you need to take will depend on the nature of your smart contract, and you can determine these using the [mitigation] tool,” they said on X.
At present, the extent of where and how this vulnerable open-source library is deployed in other smart contracts across the web3 ecosystem is confirmed—which is causing concern across web3, with developers, builders and creators fielding worried questions from clients and colleagues. “Has anything actually been disclosed? I’ve seen this ‘we found something’ post and a bunch of others like Rarible saying ‘they found something’ but no one has said what it is or what to do or even what is impacted exactly. It’s a little frustrating because I woke up to a dozen panicked emails from various projects I’ve worked on saying ‘are we impacted? What do we need to do??’ And all I can say is ‘no idea, we just have to wait and see what gets revealed in the coming days,’” Sean Bonner, artist and veteran project creator, told nft now. “It would have been nice if the announcement also included the fix instead of just launching everyone into the unknown,” he said.
As thirdweb’s contracts have been commonly used to create NFT collections, marketplaces have been quick to respond, including OpenSea, Coinbase NFT and Rarible, which used affected thirdweb contracts in a number of drops. Although information is still sparse, the marketplaces have taken public steps to reassure users. In a post on X, Rarible addressed creators. “If your drop was on Polygon, there’s nothing you need to do. We are mitigating the issue, and we will be in touch when the solution has been implemented. If your drop was on Ethereum, you don’t need to do anything yet. We will address the vulnerability, and will be in touch with a plan for redistributing tokens on a secured contract. We will continue to monitor this issue & keep our users informed,” they posted.
“OpenSea is in touch with thirdweb after their disclosure of a security vulnerability that impacts a subset of collections,” their spokesperson told nft now. “Thirdweb has published a blog post that outlines the steps creators can take to migrate their collections to a new smart contract without the known vulnerability. We strongly encourage impacted collection owners to take action, and we are evaluating how to support the newly migrated collections on OpenSea,” they said.
Although the issue’s underlying cause is linked to third-party tooling, the OpenSea team is coordinating closely with thirdweb to support a resolution, while taking proactive measures on their own platform to ensure user safety. They also emphasized that their own SeaDrop contract is not affected. In response to a question on X, OpenSea business development lead Will Brooke underscored this point. “Confirmed—does not affect ERC721SeaDrop,” he wrote.

OpenZeppelin, the secure blockchain standard whose libraries may have been involved in the disclosed vulnerability, offered a a write-up on X, sharing early results from their enquiry that may reassure a worried web3 community. “Based on our investigation, the issue is inherent to a problematic integration of specific patterns, and NOT particular to the implementations contained in the OpenZeppelin Contracts library. Nonetheless, we will lead the effort to assess who in the community is affected and provide them with mitigation strategies. At the appropriate time, we will responsibly disclose this vulnerability following best practices for the safety of the community,” they wrote. They also assured the public that after giving those affected time to mitigate the vulnerability, they will disclose it in accordance with responsible cybersecurity practices.
The post What We Know About The Contract Vulnerability Worrying Web3 appeared first on nft now.
-
Blockchain1 week agoTokenized Deposits for Payments, Treasury – Crypto News
-
Metaverse1 week agoTech layoffs: From Meta, Amazon to Google — these IT majors have cut AI related jobs – Crypto News
-
Cryptocurrency1 week ago
Robinhood Lists HYPE As Hyperliquid Flips Aster, Lighter In Perp DEX Volume – Crypto News
-
Cryptocurrency1 week ago
XRP News: Ripple Unveils ‘Ripple Prime’ After Closing $1.25B Hidden Road Deal – Crypto News
-
Cryptocurrency1 week agoTrump plans to pick Michael Selig to lead CFTC: Report – Crypto News
-
De-fi1 week agoAster Rallies on ‘Rocket Launch’ Incentives Campaign – Crypto News
-
Blockchain1 week agoAfrica Countries Pass Crypto Laws to Attract Industry – Crypto News
-
Blockchain7 days agoBinance Stablecoin Outflow On A Steady Rise — What This Means For The Market – Crypto News
-
others6 days ago
JPY soft and underperforming G10 in quiet trade – Scotiabank – Crypto News
-
De-fi6 days agoNearly Half of US Retail Crypto Holders Haven’t Earned Yield: MoreMarkets – Crypto News
-
Technology1 week agoSundar Pichai hails ‘verifiable’ quantum computing breakthrough as Google’s Willow surpasses ability of supercomputers – Crypto News
-
Metaverse1 week agoBezos fund believes AI can save the planet. Nvidia, Google are all-in. – Crypto News
-
Technology1 week ago‘It just freezes’: Spotify users fume over app crashes on Android devices, company responds – Crypto News
-
Cryptocurrency1 week agoCrypto update: Bitcoin and Ethereum are stable as market’s focus shifts to US inflation data – Crypto News
-
Cryptocurrency1 week agoDOGE to $0.33 in Sight? Dogecoin Must Defend This Key Level First – Crypto News
-
Technology1 week agoFrom Studio smoke to golden hour: How to create stunning AI portraits with Google Gemini – 16 viral prompts – Crypto News
-
Business1 week ago
White House Crypto Czar Backs Michael Selig as ‘Excellent Choice’ To Lead CFTC – Crypto News
-
Blockchain1 week agoISM Data Hints Bitcoin Cycle Could Last Longer Than Usual – Crypto News
-
Technology7 days agoNothing OS 4.0 Beta introduces pre-installed apps to Phone (3a) series: Co-founder Akis Evangelidis explains the update – Crypto News
-
De-fi6 days agoHYPE Jumps 10% as Robinhood Announces Spot Listing – Crypto News
-
Blockchain6 days agoEthereum Rebounds From Bull Market Support: Can It Conquer The ‘Golden Pocket’ Next? – Crypto News
-
others6 days ago
Platinum price recovers from setback – Commerzbank – Crypto News
-
Cryptocurrency6 days agoWestern Union eyes stablecoin rails in pursuit of a ‘super app’ vision – Crypto News
-
Blockchain6 days agoXRP Price Gains Traction — Buyers Pile In Ahead Of Key Technical Breakout – Crypto News
-
Technology3 days agoSam Altman says OpenAI is developing a ‘legitimate AI researcher’ by 2028 that can discover new science on its own – Crypto News
-
Technology1 week agoYouTube brings a new feature to stop you from endlessly scrolling Shorts: here’s how it works – Crypto News
-
Business1 week ago
Peter Schiff Challenges Binance Founder CZ to Debate as Bitcoin Vs. Gold Rivalry Heats Up – Crypto News
-
Business1 week ago
Breaking: Trump To Meet China’s President On October 30, Bitcoin Bounces – Crypto News
-
De-fi1 week agoSolana DEX Meteora Launches Native MET Token – Crypto News
-
Technology1 week agoGoogle and Apple face extra UK scrutiny over strategic role in mobile platforms – Crypto News
-
Cryptocurrency1 week agoWhat next for Avantis price after the 73% recovery? – Crypto News
-
Technology1 week agoUniswap Foundation (UNI) awards Brevis $9M grant to accelerate V4 adoption – Crypto News
-
Cryptocurrency6 days agoUSDJPY Forecast: The Dollar’s Winning Streak Why New Highs Could Be At Hand – Crypto News
-
Cryptocurrency1 week ago155 Filings Across 35 Assets, Analyst Backs Index Funds – Crypto News
-
others1 week ago
JPY weak and underperforming – Scotiabank – Crypto News
-
Cryptocurrency1 week agoLedger Nano Gen5 feels like Flex for less – Crypto News
-
Blockchain6 days agoEntire Startup Lifecycle to Move Onchain – Crypto News
-
Cryptocurrency6 days agoNEAR’s inflation reduction vote fails pass threshold, but it may still be implemented – Crypto News
-
Blockchain6 days agoXRP/BTC Retests 6-Year Breakout Trendline, Analyst Calls For Decoupling – Crypto News
-
Technology6 days agoSurvival instinct? New study says some leading AI models won’t let themselves be shut down – Crypto News
-
Technology1 week agoSolana’s RWA market surpasses $700M all-time high as adoption accelerates – Crypto News
-
Cryptocurrency1 week agoJito’s JTO token rises on a16z’s $50 million investment in Solana staking protocol – Crypto News
-
Technology1 week ago
Dogecoin Price Crash Looms as Flag, Death Cross, Falling DOGE ETF Inflows Coincide – Crypto News
-
Blockchain1 week agoBitcoin Whale From 2009 Moves Coins After 14 Years Asleep – Crypto News
-
Cryptocurrency1 week agoFetch.ai and Ocean Protocol move toward resolving $120M FET dispute – Crypto News
-
Technology1 week agoOpenAI announces major Sora update: Editing, trending cameos, and Android launch on the way – Crypto News
-
Business1 week ago
HBAR Price Targets 50% Jump as Hedera Unleashes Massive Staking Move – Crypto News
-
Metaverse1 week agoGemini in Gmail automates meeting schedules effortlessly – Crypto News
-
Business1 week ago
PEPE Coin Price Prediction as Weekly Outflows Hit $17M – Is Rebound Ahead? – Crypto News
-
Cryptocurrency1 week agoHYPE Breaks Out After Robinhood Listing and S-1 Filing: What’s Next? – Crypto News

Important PSA: