Fun

Attacker Hacks Arbitrum’s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit

News Feed - 2022-03-05 03:03:50

Attacker Hacks Arbitrum"s Treasure DAO for Over 100 NFTs by Leveraging Marketplace Exploit


A non-fungible token market platform built on top of Arbitrum called Treasure DAO was hacked on March 3 at 7:33 a.m. (EST), according to a post mortem analysis authored by the security-focused firm Certik. The company’s report notes that “over 100 NFTs were stolen in the attack,” as the attacker leveraged a vulnerability in the marketplace’s “buyer buy item” function. Post Mortem Analysis by Certik Shows Arbitrum NFT Trading Platform Treasure DAO Exploited for More Than 100 NFTs


The leading Arbitrum NFT marketplace Treasure DAO was attacked on Thursday after an attacker discovered an exploit that resulted in the loss of “more than 100 NFTs from unsuspecting users.” The post mortem analysis of the attack was sent to Bitcoin.com News from the blockchain security firm Certik, a company that analyzes, monitors, and assesses smart contracts, blockchain tech, and decentralized finance (defi) protocols.


“Treasure DAO, an NFT trading platform on Arbitrum, was exploited by an unknown attacker who took advantage of a flaw in the platform’s code,” Certik’s analysis details. “The exploit resulted in the loss of more than 100 NFTs from unsuspecting users. After some initial analysis and tracing of the hacker’s wallet on Twitter, many stolen NFTs were returned.” “The attacker took advantage of an error in the marketplace’s Buyer.buyItem function, which allowed them to set the _quantity equal to 0,” Certik’s post mortem says. “With a quantity of 0, totalPrice is also 0, as totalPrice = _pricePerItem * _quantity. This means the attacker paid nothing for the NFTs they ‘purchased.’ As there is no requirement that _quantity > 0, the function executes normally. This bug could be resolved by requiring a greater than 0 value for the _quantity variable.”


Additionally, Certik’s analysis of the Treasure DAO situation notes that the protocol’s native token MAGIC shed over 40% in losses against the U.S. dollar. Treasure DAO co-founder John Patten also tweeted about the event after the attacker stole the funds. “Treasure marketplace is being exploited. Please delist your items. We will cover the costs of the exploit—I will personally give up all of my Smols to repair this,” Patten said. The Treasure DAO co-founder added: I cannot fathom what subhuman targets a fair launch marketplace for robbery, but they will not defeat the community. Certik Says Ongoing On-Chain Analysis and Pre-Deployment Audits Can Curb Future Blockchain Protocol Exploits


Certik security analysts say that no one knows who was behind the exploit but added that many users were “simply be glad to have their stolen NFTs returned.” The company’s post mortem summary of the situation concludes by adding that significant losses can happen by simply exploiting one line of code. The firm wholeheartedly believes on-chain monitoring of specific blockchain protocols and pre-deployment audits can help stop future vulnerabilities.


“This hack once again highlights the million-dollar ramifications that a single line of code can have,” Certik’s report concludes. “A thorough pre-deployment audit paired with ongoing on-chain analysis is the best way for Web3 projects to demonstrate their commitment to security and assure their customers that their funds are safe.” Tags in this story 100 NFTs, Arbitrum, Arbitrum Chain, attacker, Blockchain security, bug Treasure DAO, certik, Certik analysis, Certik post mortem, Certik Security, Hack, Hacker, John Patten, MAGIC, Magic token, nft, NFT hack, NFT Market, NFT marketplace, NFTs, Treasure DAO, Treasure DAO bug, Treasure DAO exploit, Treasure DAO hack, Web3 projects


What do you think about the Treasure DAO hack and Certik’s post mortem report? Let us know what you think about this subject in the comments section below. Jamie Redman


Jamie Redman is the News Lead at Bitcoin.com News and a financial tech journalist living in Florida. Redman has been an active member of the cryptocurrency community since 2011. He has a passion for Bitcoin, open-source code, and decentralized applications. Since September 2015, Redman has written more than 5,000 articles for Bitcoin.com News about the disruptive protocols emerging today. South Korean Crypto Exchanges Restrict Russians" Access Over War in Ukraine NEWS | 7 hours ago Infura Mistakenly Leaves Venezuelan Users Without Metamask Support NEWS | 9 hours ago


Image Credits: Shutterstock, Pixabay, Wiki Commons Previous articleTechnical Analysis: ANC Captures Friday’s Largest Gains, as WAVES up Nearly 100% in the Last Week Next articleBitcoin Miners Catch a Break as Mining Difficulty Drops for the First Time in 3 Months Disclaimer: This article is for informational purposes only. It is not a direct offer or solicitation of an offer to buy or sell, or a recommendation or endorsement of any products, services, or companies. Bitcoin.com does not provide investment, tax, legal, or accounting advice. Neither the company nor the author is responsible, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any content, goods or services mentioned in this article. Read disclaimerShow comments More Popular NewsIn Case You Missed ItStarlink Terminals Arrive in Ukraine as Elon Musk Makes Good on Promise


Spacex has managed to deliver Starlink equipment to Ukraine as promised by its founder, Elon Musk. The hardware will provide access to high-speed internet for users in the country, which has been experiencing disruptions in communications as a result of ... read more.South African Mobile Network Operator MTN Buys Land in the Metaverse Leaked Images Suggest Opensea Plans to Add Solana-Based NFT Support Square Enix to Bring Dungeon Siege IP to The Sandbox US Senator Urges Regulators to Increase Scrutiny on Crypto as It Risks Undermining Sanctions Against Russia

News Feed

Technical Analysis: IOTX Captures the Biggest Gains, as Crypto Markets Fall on Friday
Technical Analysis: IOTX Captures the Biggest Gains, as Crypto Markets Fall on Friday IOTX was Friday’s big gainer, as crypto markets were lower across the board to end the
Luna Foundation’s Bitcoin Reserve Wallet Now Holds $1.1 Billion in BTC
Luna Foundation"s Bitcoin Reserve Wallet Now Holds $1.1 Billion in BTC During the last week, the cryptocurrency community has been discussing the bitcoin purchases made by Luna Fou
3 out of 4 of the Top Smart Contract Tokens Outpaced Ethereum’s 12 Month Gains
3 out of 4 of the Top Smart Contract Tokens Outpaced Ethereum"s 12 Month Gains While the price of bitcoin has been volatile during the last seven days, a number of smart contract p
SEC reviews new rules for Bitcoin options trading
Ana Paula Pereira7 hours agoSEC reviews new rules for Bitcoin options tradingThe Securities and Exchange Commission is evaluating whether exchanges’ current surveillance and enforcement mechanisms can handle Bitcoin ex
Ethereum Layer-2 Scaling Solution Arbitrum to Launch This Month
Ethereum Layer-2 Scaling Solution Arbitrum to Launch This Month Arbitrum, an Ethereum Layer-2 (L2) scaling solution, announced it would launch its mainnet for us
Zcash Will Get a Gateway Into Ethereum’s DeFi Ecosystem
When cryptocurrency fans gathered in Osaka, Japan, this week for the Devcon developer conference, the halls were filled with buzz about smaller projects seeking access to ethereum’s decentralized finance smorgasbo
SIDUS HEROES Receives Investment From Animoca Brands, Alameda Research, Bloktopia, OKEX, Polygon and Master Ventures
SIDUS HEROES Receives Investment From Animoca Brands, Alameda Research, Bloktopia, OKEX, Polygon and Master Ventures press release PRESS RELEASE. February 04th–Sydney, Austra
NFT Sales Volume Slips 8% Lower Than Last Week — Moonbirds, Electricsheep, Moonbirds Oddities Lead in Sales
NFT Sales Volume Slips 8% Lower Than Last Week — Moonbirds, Electricsheep, Moonbirds Oddities Lead in Sales During the last few weeks, non-fungible token (NFT) sales have remaine
Will DOGE reach $1 this cycle? It's a 'crapshoot,' say analysts
Ciaran Lyons4 hours agoWill DOGE reach $1 this cycle? It"s a "crapshoot," say analystsDogecoin has “historical heritage” but whether it hits a one-dollar price target is still a risky bet.13514 Total views6 Total sha
South Africa begins licensing crypto exchanges as applications pile up
Derek Andersen3 hours agoSouth Africa begins licensing crypto exchanges as applications pile upApplications poured in before the Nov. 30 deadline, so more approvals could be on the way.2732 Total views3 Total sharesListe
US Seizes Cryptocurrency Worth $30 Million From North Korean Hackers
US Seizes Cryptocurrency Worth $30 Million From North Korean Hackers Blockchain data analytics firm Chainalysis has revealed that U.S. authorities have seized cryptocurrency worth
Brayden Lindrea37 minutes agoCrypto exchange Binance reopens exchange services in BelgiumIn June, Binance was ordered to halt its services in Belgium "with immediate effect," leading to the exchange redirecting