Fun

Attacker Hacks Arbitrum’s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit

News Feed - 2022-03-05 03:03:50

Attacker Hacks Arbitrum"s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit


A non-fungible token market platform built on top of Arbitrum called Treasure DAO was hacked on March 3 at 7:33 a.m. (EST), according to a post mortem analysis authored by the security-focused firm Certik. The company’s report notes that “over 100 NFTs were stolen in the attack,” as the attacker leveraged a vulnerability in the marketplace’s “buyer buy item” function. Post Mortem Analysis by Certik Shows Arbitrum NFT Trading Platform Treasure DAO Exploited for More Than 100 NFTs


The leading Arbitrum NFT marketplace Treasure DAO was attacked on Thursday after an attacker discovered an exploit that resulted in the loss of “more than 100 NFTs from unsuspecting users.” The post mortem analysis of the attack was sent to Bitcoin.com News from the blockchain security firm Certik, a company that analyzes, monitors, and assesses smart contracts, blockchain tech, and decentralized finance (defi) protocols.


“Treasure DAO, an NFT trading platform on Arbitrum, was exploited by an unknown attacker who took advantage of a flaw in the platform’s code,” Certik’s analysis details. “The exploit resulted in the loss of more than 100 NFTs from unsuspecting users. After some initial analysis and tracing of the hacker’s wallet on Twitter, many stolen NFTs were returned.” “The attacker took advantage of an error in the marketplace’s Buyer.buyItem function, which allowed them to set the _quantity equal to 0,” Certik’s post mortem says. “With a quantity of 0, totalPrice is also 0, as totalPrice = _pricePerItem * _quantity. This means the attacker paid nothing for the NFTs they ‘purchased.’ As there is no requirement that _quantity > 0, the function executes normally. This bug could be resolved by requiring a greater than 0 value for the _quantity variable.”


Additionally, Certik’s analysis of the Treasure DAO situation notes that the protocol’s native token MAGIC shed over 40% in losses against the U.S. dollar. Treasure DAO co-founder John Patten also tweeted about the event after the attacker stole the funds. “Treasure marketplace is being exploited. Please delist your items. We will cover the costs of the exploit—I will personally give up all of my Smols to repair this,” Patten said. The Treasure DAO co-founder added: I cannot fathom what subhuman targets a fair launch marketplace for robbery, but they will not defeat the community. Certik Says Ongoing On-Chain Analysis and Pre-Deployment Audits Can Curb Future Blockchain Protocol Exploits


Certik security analysts say that no one knows who was behind the exploit but added that many users were “simply be glad to have their stolen NFTs returned.” The company’s post mortem summary of the situation concludes by adding that significant losses can happen by simply exploiting one line of code. The firm wholeheartedly believes on-chain monitoring of specific blockchain protocols and pre-deployment audits can help stop future vulnerabilities.


“This hack once again highlights the million-dollar ramifications that a single line of code can have,” Certik’s report concludes. “A thorough pre-deployment audit paired with ongoing on-chain analysis is the best way for Web3 projects to demonstrate their commitment to security and assure their customers that their funds are safe.” Tags in this story 100 NFTs, Arbitrum, Arbitrum Chain, attacker, Blockchain security, bug Treasure DAO, certik, Certik analysis, Certik post mortem, Certik Security, Hack, Hacker, John Patten, MAGIC, Magic token, nft, NFT hack, NFT Market, NFT marketplace, NFTs, Treasure DAO, Treasure DAO bug, Treasure DAO exploit, Treasure DAO hack, Web3 projects


What do you think about the Treasure DAO hack and Certik’s post mortem report? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. South Korean Crypto Exchanges Restrict Russians" Access Over War in Ukraine NEWS | 7 hours ago Infura Mistakenly Leaves Venezuelan Users Without Metamask Support NEWS | 9 hours ago


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleTechnical Analysis: ANC Captures Friday’s Largest Gains, as WAVES up Nearly 100% in the Last Week Next articleBitcoin Miners Catch a Break as Mining Difficulty Drops for the First Time in 3 Months Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItStarlink Terminals Arrive in Ukraine as Elon Musk Makes Good on Promise


Spacex has managed to deliver Starlink equipment to Ukraine as promised by its founder, Elon Musk. The hardware will provide access to high-speed internet for users in the country, which has been experiencing disruptions in communications as a result of ... read more.South African Mobile Network Operator MTN Buys Land in the Metaverse Leaked Images Suggest Opensea Plans to Add Solana-Based NFT Support Square Enix to Bring Dungeon Siege IP to The Sandbox US Senator Urges Regulators to Increase Scrutiny on Crypto as It Risks Undermining Sanctions Against Russia

News Feed

Bitfinex database breach 'seems fake,' says CTO
Ciaran Lyons3 hours agoBitfinex database breach "seems fake," says CTOBitfinex CTO Paolo Ardoino explained that if the hacking group was telling the truth, they would have asked for a ransom, but he "couldn"t find a
Derek Andersen15 hours agoSingapore central bank reports on tokenized asset network models after trialsThree trial use cases have been completed as part of the project, and the report uses them as a “framework for cons
Bitcoin, Ethereum Technical Analysis: BTC Back Above $21,000 Despite Genesis Bankruptcy
Bitcoin, Ethereum Technical Analysis: BTC Back Above $21,000 Despite Genesis Bankruptcy Bitcoin crept back up to the $21,000 level on Friday, as volatility in the cryptocurrency ma
UK Digital Bank Ziglu Launches P2P Payments for Bitcoin and Bitcoin Cash
UK Digital Bank Ziglu Launches P2P Payments for Bitcoin and Bitcoin CashLondon-based challenger bank Ziglu said Monday that it has been licensed as an Electronic Money Institution (
IRS Building ‘Hundreds’ of Crypto Cases — Official Says $7 Billion in Crypto Seized in 2022
IRS Building "Hundreds" of Crypto Cases — Official Says $7 Billion in Crypto Seized in 2022 The Internal Revenue Service (IRS) is building “hundreds” of crypto cases
Coinbase teases ‘cbBTC’ days after BitGo Wrapped Bitcoin controversy
Tom Mitchelhill4 hours agoCoinbase teases ‘cbBTC’ days after BitGo Wrapped Bitcoin controversySpeculators think the post refers to Coinbase’s own wrapped Bitcoin product, which will potentially be launched on its l
Derek Andersen4 hours agoCourt approves sale of FTX digital assetsAssets will be sold off weekly, with special handling for BTC, ETH and "insider-affiliated tokens."1842 Total views16 Total sharesListen to arti
Texas company mounts court challenge to SEC crypto authority
Derek Andersen3 hours agoTexas company mounts court challenge to SEC crypto authorityThe parent company of a yet-to-launch crypto exchange teamed up with the Crypto Freedom Alliance of Texas in hopes of heading off secur
Savannah Fortis10 hours agoBiden AI executive order ‘certainly challenging’ for open-source AI — Industry insidersThe executive order on AI safety from the Biden administration has laid out its standards for the in
Solana Eyes $200 Target As It Gains Momentum – Recovery Could Mirror 3-Month Downtrend
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Bitcoin Long-Term Holders Are Buying Again — Can They Push BTC Price Higher?
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Bitcoin price aims for a bullish weekly open — Will DOGE, TON, STX and FTM follow?
Rakesh Upadhyay1 hour agoBitcoin price aims for a bullish weekly open — Will DOGE, TON, STX and FTM follow?Bitcoin bulls attempt to establish control over BTC price, a move that could benefit DOGE, TON, STX and FTM.646