CryptoPotato
CryptoPotato
  • Crypto News
  • Margin Trading
  • Guides
    • Bitcoin & Crypto Guides 101
    • Bitcoin For Beginners
    • Editorials
  • DeFi & NFT
  • Buy
  • Language
  • Crypto News
  • Bitcoin For Beginners
  • Cryptocurrency Guides 101
  • Editorials
  • Bitcoin & Crypto Margin Trading
  • DeFi & NFT News
  • Bitcoin Price Analysis
  • CryptoPotato Crypto Fund
  • Ethereum (ETH) Price Analysis
  • Ripple (XRP) Price Analysis
  • Market Updates
  • Interviews
  • Buy Bitcoin with Card
  • bitcoin
    BTC$27,390.00
  • ethereum
    ETH$1,737.98
    • Market Updates
    • BTC Analysis
    • ETH Analysis
    • XRP Analysis
    • Interviews
    • Opinions
    CryptoPotato
    CryptoPotato
    • Crypto News
    • Margin Trading
    • Guides
      • Bitcoin & Crypto Guides 101
      • Bitcoin For Beginners
      • Editorials
    • DeFi & NFT
    • Buy
    • Language
    • Crypto News
    • Bitcoin For Beginners
    • Cryptocurrency Guides 101
    • Editorials
    • Bitcoin & Crypto Margin Trading
    • DeFi & NFT News
    • Bitcoin Price Analysis
    • CryptoPotato Crypto Fund
    • Ethereum (ETH) Price Analysis
    • Ripple (XRP) Price Analysis
    • Market Updates
    • Interviews
    • Buy Bitcoin with Card
    Home » Crypto News » Cyber Security Firm Discovers Critical Vulnerability on NFT Marketplace Rarible

    Cyber Security Firm Discovers Critical Vulnerability on NFT Marketplace Rarible

    Author: Chayanika Deka

    Last Updated Apr 15, 2022 @ 06:32

    CPR researchers claim that the security threat, if exploited, could have enabled a threat actor to steal a user’s NFTs and crypto tokens in a single transaction.

    Check Point, the American-Israeli multinational that provides hardware and software products for IT security, has revealed identifying a security flaw in the popular NFT marketplace Rarible, which boasts over two million monthly active users.

    Security Flaw on Rarible

    In a blog post, CPR stated that the flaw, if exploited, would have allowed a malicious actor to siphon off a user’s NFTs and cryptocurrency wallets in a single transaction.

    Rarible is one of the most established marketplaces in the NFTF sector. It reported more than $273 million in trading volume in 2021. Hence, CPR mentioned that platform users are “less suspicious and familiar with submitting transactions.” Researchers at the firm alerted Rarible of the discovery on April 5th, following which the NFT platform acknowledged the flaw and fixed it immediately.

    Outlining the attack method, CPR noted:

    “Victim receives a link to the malicious NFT or browses the marketplace and clicks on it. The Malicious NFT executes JavaScript code and attempts to send a setApprovalForAll request to the victim. Victim submits the request and grants full access to this NFT’s/Crypto Token to the attacker.”

    CPR first became intrigued by these types of cases after a popular Taiwanese singer Jay Chou fell victim to a similar cyber-attack. Reportedly, attackers stole Chou’s NFT and later sold it for $500k.

    ADVERTISEMENT

    Interestingly, the firm also detected critical security vulnerabilities on OpenSea last October, which could have potentially enabled attackers to “hijack user accounts and steal entire cryptocurrency wallets by crafting malicious NFTs.”

    It also urged users to exercise caution while reviewing what is being requested. If the request appears abnormal or suspicious, they should reject it and inspect it further before providing any kind of authorization.

    Rampant Attacks on NFT Marketplaces

    The development comes a little over a month after Arbitrum-based NFT marketplace – TreasureDAO – witnessed hundreds of NFTs being stolen in an exploit in a series of transactions. The malicious entities exploited a security vulnerability in the protocol that enabled them to mint non-fungible tokens for free.

    OpenSea’s front-end was also exploited at the beginning of the year, which targeted Bored Ape Yacht Club (BAYC) holders. As reported earlier, the perpetrator managed to steal around $750K worth of ETH.

    SPECIAL OFFER (Sponsored)
    Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).

    PrimeXBT Special Offer: Use this link to register & enter POTATO50 code to receive up to $7,000 on your deposits.

    You Might Also Like:

    • opensea_guide2_cover
      $1.7 Million in ETH Stolen from OpenSea Users: The NFT Marketplace Investigates
    • hack_cover
      Hackers Exploit Arbitrum-based Marketplace Treasure: Over 100 NFTs Stolen
    • Dego_Finance_Hack
      DeFi Project Dego Finance Hacked: Exploiters Reportedly Drain Over $10M
    Tags: Hacking Non-Fungible Token (NFT)
    Enjoy reading? Share with your friends
    Facebook Twitter LinkedIn Telegram

    About The Author

    Chayanika Deka
    More posts by this author

    Chayanika has been working as a financial journalist for three years. A graduate in Political Science and Journalism, her interest lies in regulatory implications with a focus on technological evolution in the crypto realm. Contact:Linkedin

  • bitcoin
    BTC$27,390.00
  • ethereum
    ETH$1,737.98
  • Join Our Community

    FacebookTwitter YouTubeTelegram


    Editorials
    Artificial Intelligence & Crypto Guide: Here Are the Top 5 AI Coins

    Artificial Intelligence & Crypto Guide: Here Are the Top 5 AI Coins

    How to Keep Your Crypto Safe, MetaMask Future Plans, and Digital Identities: Talking Wallets With PM Alex Jupiter

    How to Keep Your Crypto Safe, MetaMask Future Plans, and Digital Identities: Talking Wallets With PM Alex Jupiter

    What is Optimism (OP): Guide to One of Ethereum’s Layer-Two Scaling Solutions

    What is Optimism (OP): Guide to One of Ethereum’s Layer-Two Scaling Solutions

    Why ZK-Rollups Are the Future of Ethereum Scaling: Interview with StarkWare PM Gal Ron

    Why ZK-Rollups Are the Future of Ethereum Scaling: Interview with StarkWare PM Gal Ron

    2022 Was Crypto’s Dot Com Bust: Let’s Recap Tech Stocks After 2000 (Opinion)

    2022 Was Crypto’s Dot Com Bust: Let’s Recap Tech Stocks After 2000 (Opinion)

    How Long Will the Ethereum LSD Narrative Last? Talking 2023 Trends with Nansen’s Martin Lee

    How Long Will the Ethereum LSD Narrative Last? Talking 2023 Trends with Nansen’s Martin Lee

    Everything That’s Going on With Pi Network: From Start to Latest Controversial Listing

    Everything That’s Going on With Pi Network: From Start to Latest Controversial Listing

    Join Our Newsletter
    Become a CryptoPotato VIP
    One Weekly Email Can Change Your Crypto Life.
    Sign-up FREE to receive our extended weekly market update and coin analysis report
    We NEVER send spam. You can unsubscribe at any time.
    Invalid email address
    Thanks for subscribing!
    Footer Logo
    About
    Advertise on CryptoPotato
    About Us | Contact Us | Careers
    Editorial Policy
    Terms of service | Privacy Policy | GDPR
    More Sections
    IEO List | Evaluations
    Airdrops
    Scholarship
    Disclaimer
    Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. Full disclaimer
    © Copyright CryptoPotato 2016 - 2021
    Scroll to top
    One Weekly Email Can Change Your Crypto Life.

    Sign-up FREE to receive our extended weekly market update and coin analysis report

    We never send SPAM. You can unsubscribe at any moment
    Invalid email address
    Thanks for subscribing!