Fun

Attacker Hacks Arbitrum’s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit

News Feed - 2022-03-05 03:03:50

Attacker Hacks Arbitrum"s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit


A non-fungible token market platform built on top of Arbitrum called Treasure DAO was hacked on March 3 at 7:33 a.m. (EST), according to a post mortem analysis authored by the security-focused firm Certik. The company’s report notes that “over 100 NFTs were stolen in the attack,” as the attacker leveraged a vulnerability in the marketplace’s “buyer buy item” function. Post Mortem Analysis by Certik Shows Arbitrum NFT Trading Platform Treasure DAO Exploited for More Than 100 NFTs


The leading Arbitrum NFT marketplace Treasure DAO was attacked on Thursday after an attacker discovered an exploit that resulted in the loss of “more than 100 NFTs from unsuspecting users.” The post mortem analysis of the attack was sent to Bitcoin.com News from the blockchain security firm Certik, a company that analyzes, monitors, and assesses smart contracts, blockchain tech, and decentralized finance (defi) protocols.


“Treasure DAO, an NFT trading platform on Arbitrum, was exploited by an unknown attacker who took advantage of a flaw in the platform’s code,” Certik’s analysis details. “The exploit resulted in the loss of more than 100 NFTs from unsuspecting users. After some initial analysis and tracing of the hacker’s wallet on Twitter, many stolen NFTs were returned.” “The attacker took advantage of an error in the marketplace’s Buyer.buyItem function, which allowed them to set the _quantity equal to 0,” Certik’s post mortem says. “With a quantity of 0, totalPrice is also 0, as totalPrice = _pricePerItem * _quantity. This means the attacker paid nothing for the NFTs they ‘purchased.’ As there is no requirement that _quantity > 0, the function executes normally. This bug could be resolved by requiring a greater than 0 value for the _quantity variable.”


Additionally, Certik’s analysis of the Treasure DAO situation notes that the protocol’s native token MAGIC shed over 40% in losses against the U.S. dollar. Treasure DAO co-founder John Patten also tweeted about the event after the attacker stole the funds. “Treasure marketplace is being exploited. Please delist your items. We will cover the costs of the exploit—I will personally give up all of my Smols to repair this,” Patten said. The Treasure DAO co-founder added: I cannot fathom what subhuman targets a fair launch marketplace for robbery, but they will not defeat the community. Certik Says Ongoing On-Chain Analysis and Pre-Deployment Audits Can Curb Future Blockchain Protocol Exploits


Certik security analysts say that no one knows who was behind the exploit but added that many users were “simply be glad to have their stolen NFTs returned.” The company’s post mortem summary of the situation concludes by adding that significant losses can happen by simply exploiting one line of code. The firm wholeheartedly believes on-chain monitoring of specific blockchain protocols and pre-deployment audits can help stop future vulnerabilities.


“This hack once again highlights the million-dollar ramifications that a single line of code can have,” Certik’s report concludes. “A thorough pre-deployment audit paired with ongoing on-chain analysis is the best way for Web3 projects to demonstrate their commitment to security and assure their customers that their funds are safe.” Tags in this story 100 NFTs, Arbitrum, Arbitrum Chain, attacker, Blockchain security, bug Treasure DAO, certik, Certik analysis, Certik post mortem, Certik Security, Hack, Hacker, John Patten, MAGIC, Magic token, nft, NFT hack, NFT Market, NFT marketplace, NFTs, Treasure DAO, Treasure DAO bug, Treasure DAO exploit, Treasure DAO hack, Web3 projects


What do you think about the Treasure DAO hack and Certik’s post mortem report? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. South Korean Crypto Exchanges Restrict Russians" Access Over War in Ukraine NEWS | 7 hours ago Infura Mistakenly Leaves Venezuelan Users Without Metamask Support NEWS | 9 hours ago


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleTechnical Analysis: ANC Captures Friday’s Largest Gains, as WAVES up Nearly 100% in the Last Week Next articleBitcoin Miners Catch a Break as Mining Difficulty Drops for the First Time in 3 Months Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItStarlink Terminals Arrive in Ukraine as Elon Musk Makes Good on Promise


Spacex has managed to deliver Starlink equipment to Ukraine as promised by its founder, Elon Musk. The hardware will provide access to high-speed internet for users in the country, which has been experiencing disruptions in communications as a result of ... read more.South African Mobile Network Operator MTN Buys Land in the Metaverse Leaked Images Suggest Opensea Plans to Add Solana-Based NFT Support Square Enix to Bring Dungeon Siege IP to The Sandbox US Senator Urges Regulators to Increase Scrutiny on Crypto as It Risks Undermining Sanctions Against Russia

News Feed

Biggest Movers: ATOM, SOL Remain Close to Multi-Week Highs, as Markets Consolidate Recent Gains
Biggest Movers: ATOM, SOL Remain Close to Multi-Week Highs, as Markets Consolidate Recent Gains Cosmos climbed by as much as 5% in Wednesday’s session, as the token remained
XRP Forms Bullish Flag Pattern: What’s Next For The Altcoin?
Este artículo también está disponible en español. XRP is capturing attention across the crypto market as it forms a bullish flag pattern, a classic technical setup often
TSMC becomes first Asian company to reach $1T as AI demand surges
Tristan Greene7 hours agoTSMC becomes first Asian company to reach $1T as AI demand surgesThe company is now worth more than Broadcom and closing in on Meta.1539 Total views3 Total sharesListen to article 0:00NewsOwn thi
South Korean foundation to recover funds from defunct crypto exchanges
Derek Andersen1 hour agoSouth Korean foundation to recover funds from defunct crypto exchangesThe Digital Asset User Protection Foundation will be set up by the DAXA self-regulatory organization and receive support from
Phillips Auction Featuring Basquiat Painting Worth $70M to Accept Bitcoin, Ethereum Payments
Phillips Auction Featuring Basquiat Painting Worth $70M to Accept Bitcoin, Ethereum Payments On May 18, the auction house Phillips will be hosting an evening sale featuring the wor
Debate Intensifies Over Significance and Implications of Ordinal Inscriptions on Bitcoin Blockchain
Debate Intensifies Over Significance and Implications of Ordinal Inscriptions on Bitcoin Blockchain During the past two weeks, members of the cryptocurrency community have discusse
Fidelity, Sygnum partner with Chainlink to bring NAV data onchain
Ana Paula Pereira3 hours agoFidelity, Sygnum partner with Chainlink to bring NAV data onchainThe partnership will make the Net Asset Value of Fidelity’s $6.9 billion Institutional Liquidity Fund accessible onchain in r
New Philippines Central Bank Governor: Crypto Investors Are Adherents of the Greater Fool Theory
New Philippines Central Bank Governor: Crypto Investors Are Adherents of the Greater Fool Theory The incoming governor of the Philippine central bank, Felipe Medalla, has suggested
Financial system ‘outdated’ but crypto is no fix either — US swing voters
Brayden Lindrea3 hours agoFinancial system ‘outdated’ but crypto is no fix either — US swing votersIn a survey by the Digital Currency Group, 70% of swing state voters agreed the current financial system is “outd
Coinbase asks court to reject SEC’s ‘empty chair’ securities judgment
Martin Young2 hours agoCoinbase asks court to reject SEC’s ‘empty chair’ securities judgmentCoinbase lawyers have requested that a U.S. court throw out a previous default judgment that deemed the secondary sales of
Cryptocurrency Exchange Kucoin Raises $150 Million in Pre-Series B Funding Round, Reaches $10 Billion Valuation
Cryptocurrency Exchange Kucoin Raises $150 Million in Pre-Series B Funding Round, Reaches $10 Billion Valuation Kucoin, a Seychelles-based cryptocurrency exchange, has announced it
Crypto Exchange Bitfinex Stops Servicing Ontario Customers, Asks Users to Withdraw Funds
Crypto Exchange Bitfinex Stops Servicing Ontario Customers, Asks Users to Withdraw Funds Cryptocurrency exchange Bitfinex has asked its Ontario users to withdraw their funds since