A vulnerability in an open-source library that is common across the Web3 space impacts the security of pre-built smart contracts, affecting multiple NFT collections, including Coinbase. The disclosure came earlier today from Web3 development platform Thirdweb. The announcement provides a minimum of details, which irked some users who wanted clarifications that could help them protect contracts. Thirdweb said that it became aware of the security flaw on November 20 and pushed a remediation two days later, but did not disclose the name of the library and the type or severity of the vulnerability to prevent tipping off attackers. The company says it has contacted the maintainers of the vulnerable library and also alerted other protocols and organizations of the issue, sharing findings and mitigations. The following smart contracts are impacted by the flaw: "If you used our Solidity SDK to extend our base contract or built a custom contract, we don't believe the vulnerability extends to your contract," explains Thirdweb, adding that this is not a guarantee because they "are unable to audit individual contracts." Thirdweb has shared the details of the exploit with the maintainers of the affected library and said that it has not seen the vulnerability being leveraged in attacks. The absence of details prompted some users to ask for clarifications or to speculate that the issue is with the Thirdweb implementation of the library. One user complained about the lack of transparency as...
Multiple NFT collections at risk by flaw in open-source library
BleepingComputer
·Bill Toulas
·Published Dec 5, 2023
·Updated
Affected Software
9 affected components
Thirdweb Web3 development platform
Thirdweb Solidity SDK
OpenZeppelin DropERC20
OpenZeppelin ERC721
OpenZeppelin ERC1155
OpenZeppelin AirdropERC20 pre-built contract
Mocaverse Mocaverse NFT
Mocaverse Lucky Neko
Mocaverse Mocaverse Relic collection smart contracts
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a vulnerability in an open-source library affecting multiple NFT collections.
2
What security implications are discussed in the article?
The article highlights how the vulnerability jeopardizes the security of pre-built smart contracts and impacts NFT collections.
3
Which NFT collections are specifically mentioned as being at risk?
The article mentions multiple NFT collections, including those hosted by Coinbase and various Mocaverse collections.
4
What open-source libraries and platforms are affected?
The affected platforms include Thirdweb's Web3 development platform, Solidity SDK, and OpenZeppelin's various smart contract products.
5
How widespread is the vulnerability mentioned in the article?
The vulnerability is common across the Web3 ecosystem, affecting numerous NFT projects and smart contracts.