{"id":207418,"date":"2023-12-06T17:09:11","date_gmt":"2023-12-06T11:39:11","guid":{"rendered":"https:\/\/dripp.zone\/news\/?p=207418"},"modified":"2023-12-06T17:09:11","modified_gmt":"2023-12-06T11:39:11","slug":"what-we-know-about-the-contract-vulnerability-worrying-web3-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/what-we-know-about-the-contract-vulnerability-worrying-web3-crypto-news\/","title":{"rendered":"What We Know About The Contract Vulnerability Worrying Web3 &#8211; Crypto News"},"content":{"rendered":"<p><\/p>\n<p class=\"has-drop-cap\">Today, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/thirdweb\">thirdweb<\/a>\u2014creators of a popular web3 development toolkit\u2014disclosed the existence of a major vulnerability in an open-source code library that is widely-used in smart contracts throughout web3.<\/p>\n<p>According to thirdweb, this vulnerability was present\u2014but not yet taken advantage of\u2014in a number of thirdweb\u2019s pre-built smart contracts. \u201cBased on our investigation so far, this vulnerability has not been exploited in any thirdweb smart contracts. However, smart contract owners must take mitigation steps on certain pre-built smart contracts that were created on thirdweb prior to November 22nd, 2023 at 7pm PT,\u201d they said in a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/x.com\/thirdweb\/status\/1731841493407576247\">post<\/a> on X.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">IMPORTANT <\/p>\n<p>On November 20th, 2023 6pm PST, we became aware of a security vulnerability in a commonly used open-source library in the web3 industry.<\/p>\n<p>This impacts a variety of smart contracts across the web3 ecosystem, including some of thirdweb\u2019s pre-built smart contracts.\u2026<\/p>\n<p>\u2014 thirdweb (@thirdweb) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/thirdweb\/status\/1731841493407576247?ref_src=twsrc%5Etfw\">December 5, 2023<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>Thirdweb noted that the vulnerability may have been present in some of the pre-built contracts that their users had set up to drop fungible or non-fungible tokens\u2014including some ERC20, ERC721 and ERC1155s.<\/p>\n<p>While they have not disclosed the nature of the vulnerability\u2014<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.thirdweb.com\/security-vulnerability\/\">stating<\/a> on their <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/mitigate.thirdweb.com\/\">newly-launched mitigation website<\/a> that this would risk the security of others\u2014thirdweb have included a full list of their affected contracts on that site, and have provided detailed instructions and tools for their users who need to take immediate steps to mitigate the risk. \u201cIn most cases, the mitigation steps will involve locking the contract, taking a snapshot and migrating to a new contract without the known vulnerability. The exact steps you need to take will depend on the nature of your smart contract, and you can determine these using the [mitigation] tool,\u201d they said on X.<\/p>\n<p>At present, the extent of where and how this vulnerable open-source library is deployed in other smart contracts across the web3 ecosystem is confirmed\u2014which is causing concern across web3, with developers, builders and creators fielding worried questions from clients and colleagues. \u201cHas anything actually been disclosed? I\u2019ve seen this \u2018we found something\u2019 post and a bunch of others like Rarible saying \u2018they found something\u2019 but no one has said what it is or what to do or even what is impacted exactly. It\u2019s a little frustrating because I woke up to a dozen panicked emails from various projects I\u2019ve worked on saying \u2018are we impacted? What do we need to do??\u2019 And all I can say is \u2018no idea, we just have to wait and see what gets revealed in the coming days,\u2019\u201d <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/seanbonner\">Sean Bonner<\/a>, artist and veteran project creator, told nft now. \u201cIt would have been nice if the announcement also included the fix instead of just launching everyone into the unknown,\u201d he said.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\"><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/14.0.0\/72x72\/26a0.png\" alt=\"\u26a0\" class=\"wp-smiley\" style=\"height: 1em;max-height: 1em\" \/> Important PSA:  <\/p>\n<p>Today, thirdweb announced that some of their smart contracts are affected by a security vulnerability in a commonly used open-source library.  <\/p>\n<p>Rarible utilized some of these smart contracts with various drops.  <\/p>\n<p>At this time, this vulnerability has not\u2026 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/t.co\/PzXM0ZJaQj\">https:\/\/t.co\/PzXM0ZJaQj<\/a><\/p>\n<p>\u2014 Rarible (@rarible) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/rarible\/status\/1731842338186555463?ref_src=twsrc%5Etfw\">December 5, 2023<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>As thirdweb\u2019s contracts have been commonly used to create NFT collections, marketplaces have been quick to respond, including <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/x.com\/opensea\/status\/1731887099153125528\">OpenSea<\/a>, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/x.com\/coinbase_nft\/status\/1731850381594898818\">Coinbase NFT<\/a> and Rarible, which used affected thirdweb contracts in a number of drops. Although information is still sparse, the marketplaces have taken public steps to reassure users. In a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/x.com\/rarible\/status\/1731842338186555463\">post<\/a> on X, Rarible addressed creators. \u201cIf your drop was on Polygon, there\u2019s nothing you need to do. We are mitigating the issue, and we will be in touch when the solution has been implemented. If your drop was on Ethereum, you don\u2019t need to do anything yet. We will address the vulnerability, and will be in touch with a plan for redistributing tokens on a secured contract.  We will continue to monitor this issue &amp; keep our users informed,\u201d they posted.<\/p>\n<p>\u201cOpenSea is in touch with thirdweb after their disclosure of a security vulnerability that impacts a subset of collections,\u201d their spokesperson told nft now. \u201cThirdweb has published a blog post that outlines the steps creators can take to migrate their collections to a new smart contract without the known vulnerability. We strongly encourage impacted collection owners to take action, and we are evaluating how to support the newly migrated collections on OpenSea,\u201d they said.<\/p>\n<p>Although the issue\u2019s underlying cause is linked to third-party tooling, the OpenSea team is coordinating closely with thirdweb to support a resolution, while taking proactive measures on their own platform to ensure user safety. They also emphasized that their own SeaDrop contract is not affected. In response to a question on X, OpenSea business development lead Will Brooke underscored this point. \u201cConfirmed\u2014does not affect ERC721SeaDrop,\u201d <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/x.com\/wjbrooke\/status\/1732045907359850574\">he wrote<\/a>.<\/p>\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"2000\" height=\"2000\" src=\"https:\/\/nftnow.com\/wp-content\/uploads\/2023\/12\/Thirdweb-Logo-Black-BG.png\" alt=\"thirdweb logo\" class=\"wp-image-59857\" \/><\/figure>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The OpenZeppelin team was informed yesterday Monday (12\/4) at 4pm ET by <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/thirdweb?ref_src=twsrc%5Etfw\">@thirdweb<\/a> about a security vulnerability involved in but not limited to Thirdweb\u2019s versions of DropERC20, ERC721, ERC1155 (all versions), and AirdropERC20 pre-built contracts.<\/p>\n<p>As far as we know, this\u2026<\/p>\n<p>\u2014 OpenZeppelin (@OpenZeppelin) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/OpenZeppelin\/status\/1732004962131923349?ref_src=twsrc%5Etfw\">December 5, 2023<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>OpenZeppelin, the secure blockchain standard whose libraries may have been involved in the disclosed vulnerability, offered a a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/openzeppelin\/status\/1732004962131923349\">write-up<\/a> on X, sharing early results from their enquiry that may reassure a worried web3 community. \u201cBased on our investigation, the issue is inherent to a problematic integration of specific patterns, and NOT particular to the implementations contained in the OpenZeppelin Contracts library. Nonetheless, we will lead the effort to assess who in the community is affected and provide them with mitigation strategies. At the appropriate time, we will responsibly disclose this vulnerability following best practices for the safety of the community,\u201d they wrote. They also assured the public that after giving those affected time to mitigate the vulnerability, they will disclose it in accordance with responsible cybersecurity practices.<\/p>\n<p>The post <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/nftnow.com\/news\/what-we-know-about-the-contract-vulnerability-worrying-web3\/\">What We Know About The Contract Vulnerability Worrying Web3<\/a> appeared first on <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/nftnow.com\">nft now<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Today, thirdweb\u2014creators of a popular web3 development toolkit\u2014disclosed the existence of a major vulnerability in an open-source code library that is widely-used in smart contracts throughout web3. According to thirdweb, this vulnerability was present\u2014but not yet taken advantage of\u2014in a number of thirdweb\u2019s pre-built smart contracts. \u201cBased on our investigation so far, this vulnerability has [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":207419,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[245,239,243,242,244,202,184,241,240,189],"class_list":["post-207418","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nft","tag-azuki","tag-board-ape","tag-erc115","tag-erc721","tag-metamask","tag-nft","tag-nft-technology","tag-opensea","tag-sbt","tag-soul-bound-token"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/207418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=207418"}],"version-history":[{"count":2,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/207418\/revisions"}],"predecessor-version":[{"id":207421,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/207418\/revisions\/207421"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/207419"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=207418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=207418"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=207418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}