אַטאַקער כאַקס אַרביטרום ס אוצר דאַאָ פֿאַר איבער 100 NFTs דורך לעווערידזשינג מאַרקעטפּלאַסע עקספּלאָיט - ביטקאָין נייַעס

A non-fungible token market platform built on top of Arbitrum called Treasure DAO was hacked on March 3 at 7:33 a.m. (EST), according to a post mortem analysis authored by the security-focused firm Certik. The company’s report notes that “over 100 NFTs were stolen in the attack,” as the attacker leveraged a vulnerability in the marketplace’s “buyer buy item” function.

Post Mortem Analysis by Certik Shows Arbitrum NFT Trading Platform Treasure DAO Exploited for More Than 100 NFTs

The leading Arbitrum NFT marketplace Treasure DAO was attacked on Thursday after an attacker discovered an exploit that resulted in the loss of “more than 100 NFTs from unsuspecting users.” The post mortem analysis of the attack was sent to Bitcoin.com News from the blockchain security firm Certik, a company that analyzes, monitors, and assesses smart contracts, blockchain tech, and decentralized finance (defi) protocols.

“Treasure DAO, an NFT trading platform on Arbitrum, was exploited by an unknown attacker who took advantage of a flaw in the platform’s code,” Certik’s analysis details. “The exploit resulted in the loss of more than 100 NFTs from unsuspecting users. After some initial analysis and tracing of the hacker’s wallet on Twitter, many stolen NFTs were returned.”

Attacker Hacks Arbitrum's Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit
“The attacker took advantage of an error in the marketplace’s Buyer.buyItem function, which allowed them to set the _quantity equal to 0,” Certik’s post mortem says. “With a quantity of 0, totalPrice is also 0, as totalPrice = _pricePerItem * _quantity. This means the attacker paid nothing for the NFTs they ‘purchased.’ As there is no requirement that _quantity > 0, the function executes normally. This bug could be resolved by requiring a greater than 0 value for the _quantity variable.”

Additionally, Certik’s analysis of the Treasure DAO situation notes that the protocol’s native token MAGIC shed over 40% in losses against the U.S. dollar. Treasure DAO co-founder John Patten also tweeted about the event after the attacker stole the funds. “Treasure marketplace is being exploited. Please delist your items. We will cover the costs of the exploit—I will personally give up all of my Smols to repair this,” Patten said. The Treasure DAO co-founder added:

I cannot fathom what subhuman targets a fair launch marketplace for robbery, but they will not defeat the community.

Certik Says Ongoing On-Chain Analysis and Pre-Deployment Audits Can Curb Future Blockchain Protocol Exploits

Certik security analysts say that no one knows who was behind the exploit but added that many users were “simply be glad to have their stolen NFTs returned.” The company’s post mortem summary of the situation concludes by adding that significant losses can happen by simply exploiting one line of code. The firm wholeheartedly believes on-chain monitoring of specific blockchain protocols and pre-deployment audits can help stop future vulnerabilities.

“This hack once again highlights the million-dollar ramifications that a single line of code can have,” Certik’s report concludes. “A thorough pre-deployment audit paired with ongoing on-chain analysis is the best way for Web3 projects to demonstrate their commitment to security and assure their customers that their funds are safe.”

טאַגס אין דעם דערציילונג
100 NFTs, Arbitrum, Arbitrum Chain, attacker, Blockchain security, bug Treasure DAO, certik, Certik analysis, Certik post mortem, Certik Security, Hack, Hacker, John Patten, MAGIC, Magic token, nft, NFT hack, NFT Market, NFT marketplace, NFTs, Treasure DAO, Treasure DAO bug, Treasure DAO exploit, Treasure DAO hack, Web3 projects

What do you think about the Treasure DAO hack and Certik’s post mortem report? Let us know what you think about this subject in the comments section below.

Jamie redman

Jamie Redman איז די נייַעס פירן ביי Bitcoin.com News און אַ פינאַנציעל טעק זשורנאַליסט לעבעדיק אין פלאָרידאַ. Redman איז אַן אַקטיוו מיטגליד פון די קריפּטאָקוררענסי קהל זינט 2011. ער האט אַ לייַדנשאַפט פֿאַר ביטקאָין, אָפֿן-מקור קאָד, און דיסענטראַלייזד אַפּלאַקיישאַנז. זינט סעפטעמבער 2015, Redman האט געשריבן מער ווי 5,000 אַרטיקלען פֿאַר Bitcoin.com נייַעס וועגן די דיסראַפּטיוו פּראָטאָקאָלס ימערדזשינג הייַנט.




בילד קרעדיץ: שוטטערסטאָקק, פּיקסאַבייַ, Wiki Commons

אָפּלייקענונג: דער אַרטיקל איז בלויז פֿאַר ינפאָרמיישאַנאַל צוועקן. עס איז נישט אַ דירעקט פאָרשלאָג אָדער סאַליסיטיישאַן פון אַ פאָרשלאָג צו קויפן אָדער פאַרקויפן, אָדער אַ רעקאָממענדאַטיאָן אָדער ענדאָרסמאַנט פון פּראָדוקטן, באַדינונגען אָדער קאָמפּאַניעס. Bitcoin.com גיט ניט ינוועסמאַנט, שטייער, לעגאַל אָדער אַקאַונטינג עצה. ניט די פירמע אדער דער מחבר זענען פאַראַנטוואָרטלעך, גלייַך אָדער מינאַצאַד, פֿאַר קיין שעדיקן אָדער אָנווער געפֿירט אָדער אַלעדזשאַד צו זיין געפֿירט דורך אָדער אין קשר מיט די נוצן פון אָדער צוטרוי אויף קיין אינהאַלט, סכוירע אָדער באַדינונגען דערמאנט אין דעם אַרטיקל.

Source: https://news.bitcoin.com/attacker-hacks-arbitrums-treasure-dao-for-over-100-nfts-by-leveraging-marketplace-exploit/