Fun

Attacker Hacks Arbitrum’s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit

News Feed - 2022-03-05 03:03:50

Attacker Hacks Arbitrum"s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit


A non-fungible token market platform built on top of Arbitrum called Treasure DAO was hacked on March 3 at 7:33 a.m. (EST), according to a post mortem analysis authored by the security-focused firm Certik. The company’s report notes that “over 100 NFTs were stolen in the attack,” as the attacker leveraged a vulnerability in the marketplace’s “buyer buy item” function. Post Mortem Analysis by Certik Shows Arbitrum NFT Trading Platform Treasure DAO Exploited for More Than 100 NFTs


The leading Arbitrum NFT marketplace Treasure DAO was attacked on Thursday after an attacker discovered an exploit that resulted in the loss of “more than 100 NFTs from unsuspecting users.” The post mortem analysis of the attack was sent to Bitcoin.com News from the blockchain security firm Certik, a company that analyzes, monitors, and assesses smart contracts, blockchain tech, and decentralized finance (defi) protocols.


“Treasure DAO, an NFT trading platform on Arbitrum, was exploited by an unknown attacker who took advantage of a flaw in the platform’s code,” Certik’s analysis details. “The exploit resulted in the loss of more than 100 NFTs from unsuspecting users. After some initial analysis and tracing of the hacker’s wallet on Twitter, many stolen NFTs were returned.” “The attacker took advantage of an error in the marketplace’s Buyer.buyItem function, which allowed them to set the _quantity equal to 0,” Certik’s post mortem says. “With a quantity of 0, totalPrice is also 0, as totalPrice = _pricePerItem * _quantity. This means the attacker paid nothing for the NFTs they ‘purchased.’ As there is no requirement that _quantity > 0, the function executes normally. This bug could be resolved by requiring a greater than 0 value for the _quantity variable.”


Additionally, Certik’s analysis of the Treasure DAO situation notes that the protocol’s native token MAGIC shed over 40% in losses against the U.S. dollar. Treasure DAO co-founder John Patten also tweeted about the event after the attacker stole the funds. “Treasure marketplace is being exploited. Please delist your items. We will cover the costs of the exploit—I will personally give up all of my Smols to repair this,” Patten said. The Treasure DAO co-founder added: I cannot fathom what subhuman targets a fair launch marketplace for robbery, but they will not defeat the community. Certik Says Ongoing On-Chain Analysis and Pre-Deployment Audits Can Curb Future Blockchain Protocol Exploits


Certik security analysts say that no one knows who was behind the exploit but added that many users were “simply be glad to have their stolen NFTs returned.” The company’s post mortem summary of the situation concludes by adding that significant losses can happen by simply exploiting one line of code. The firm wholeheartedly believes on-chain monitoring of specific blockchain protocols and pre-deployment audits can help stop future vulnerabilities.


“This hack once again highlights the million-dollar ramifications that a single line of code can have,” Certik’s report concludes. “A thorough pre-deployment audit paired with ongoing on-chain analysis is the best way for Web3 projects to demonstrate their commitment to security and assure their customers that their funds are safe.” Tags in this story 100 NFTs, Arbitrum, Arbitrum Chain, attacker, Blockchain security, bug Treasure DAO, certik, Certik analysis, Certik post mortem, Certik Security, Hack, Hacker, John Patten, MAGIC, Magic token, nft, NFT hack, NFT Market, NFT marketplace, NFTs, Treasure DAO, Treasure DAO bug, Treasure DAO exploit, Treasure DAO hack, Web3 projects


What do you think about the Treasure DAO hack and Certik’s post mortem report? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. South Korean Crypto Exchanges Restrict Russians" Access Over War in Ukraine NEWS | 7 hours ago Infura Mistakenly Leaves Venezuelan Users Without Metamask Support NEWS | 9 hours ago


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleTechnical Analysis: ANC Captures Friday’s Largest Gains, as WAVES up Nearly 100% in the Last Week Next articleBitcoin Miners Catch a Break as Mining Difficulty Drops for the First Time in 3 Months Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItStarlink Terminals Arrive in Ukraine as Elon Musk Makes Good on Promise


Spacex has managed to deliver Starlink equipment to Ukraine as promised by its founder, Elon Musk. The hardware will provide access to high-speed internet for users in the country, which has been experiencing disruptions in communications as a result of ... read more.South African Mobile Network Operator MTN Buys Land in the Metaverse Leaked Images Suggest Opensea Plans to Add Solana-Based NFT Support Square Enix to Bring Dungeon Siege IP to The Sandbox US Senator Urges Regulators to Increase Scrutiny on Crypto as It Risks Undermining Sanctions Against Russia

News Feed

Buy Dogecoin Now? Analyst Says This Is the Spot
Este artículo también está disponible en español. Crypto analyst Kevin (known on X as @Kev_Capital_TA) has outlined what he deems a potentially ideal accumulation window
Crypto Predictions 2025: Dragonfly’s Managing Partner Unveils What’s Ahead
Este artículo también está disponible en español. Haseeb Qureshi, managing partner at Dragonfly Capital, outlined his crypto predictions 2025 via X, forecasting transform
Cardano Might See A Massive Pump Around November 18 – Analyst Exposes 2020 Similarities
Este artículo también está disponible en español. The crypto market is heating up, with Bitcoin on the brink of all-time highs and anticipating a major breakout across as
Indian Police Arrest 11 People in Cryptocurrency Scheme Defrauding 2,000 Investors
Indian Police Arrest 11 People in Cryptocurrency Scheme Defrauding 2,000 Investors Indian police have arrested 11 people so far in connection with a fraudulent cryptocurrency schem
APAC crypto crime spikes amid legal resource shortages: Chainalysis report
Josh O"Sullivan1 hour agoAPAC crypto crime spikes amid legal resource shortages: Chainalysis reportAPAC’s struggle with increasing crypto crime is exacerbated by a shortage of legal resources and inadequate training fo
3 reasons why Ethereum (ETH) price could hit $4K in the short-term
Nancy Lubale4 hours ago3 reasons why Ethereum (ETH) price could hit $4K in the short-termDespite Bitcoin’s sell-off at $69,000, ETH continues to show strength, and bulls appear to be targeting the $4,000 level.3087 Tot
Dogecoin Will Start A Move To $4 If Current Demand Holds – Can Bulls Step In?
Este artículo también está disponible en español. Dogecoin is trading below key liquidity levels as the price struggles with intense selling pressure. The entire meme coi
Alice Ivey12 hours agoHow to detect fake news with natural language processingUnravel the power of NLP in spotting fake news with various techniques and real-world examples.963 Total views15 Total sharesListen to article
Invictus Capital Announces NFT Collection to Give African Artists Global Exposure
Invictus Capital Announces NFT Collection to Give African Artists Global Exposure Invictus Capital has unveiled its first non-fungible token collection, called “Out of Afric
Analyst Predicts Dogecoin Price Surge To $4 — Here’s How
Este artículo también está disponible en español. The Dogecoin price has been under intense bearish pressure so far in 2025, falling a further 10% in the last seven days.
Sentient closes $85M seed round for open-source AI
Ana Paula Pereira10 hours agoSentient closes $85M seed round for open-source AIThe round was led by Peter Thiel’s Founders Fund alongside Pantera Capital, Framework Ventures and others.1409 Total views2 Total sharesLis
Wormhole raises $225M at $2.5B valuation
Zhiyuan Sun9 hours agoWormhole raises $225M at $2.5B valuationThe protocol reached a total value locked of $3.8 billion at its peak.1388 Total views14 Total sharesListen to article 0:00NewsJoin us on social networksCross