Top 5 NFT smart contract vulnerabilities to watch out for

cryptoslate发布于2022-03-14更新于2022-03-21

文章摘要

The NFT sector has seen several problems since it emerged which made a lot of people concerned that NFTs are not as safe as previously thought. However, the problem does not lie with NFTs themselves.

The NFT sector has seen several problems since it emerged which made a lot of people concerned that NFTs are not as safe as previously thought. However, the problem does not lie with NFTs themselves.

NFTs are actually smart contracts, and these contracts are subject to vulnerabilities. In their essence, smart contracts are just code, and the more complex the code is, the more room there is for errors to show up. Of course, developers tend to comb their code for errors and vulnerabilities time and time again, but even after extensive search — a flaw or two can still remain and cause problems down the road, especially if bad actors manage to identify them.

This is why security audits should still be carried out, as the code of the smart contracts requires a greater amount of attention. Then, and only then can smart contracts — and to some extent, the NFTs — be adequately secured.

Let’s take a look at some of the more common but still quite dangerous flaws that tend to be present in smart contracts:

NFT token sale vulnerabilities

The first opportunity that bad actors have to use the flaws of smart contracts to disrupt an NFT project is during token sales. One of the most notable examples is the Adidas NFT token sale.

As the sale was underway, an attacker managed to bypass the limits on the maximum purchased tokens for a wallet. As a result, the hacker managed to score 330 NFTs, permanently disrupting Adidas’ otherwise successful debut NFT collection “Into the Metaverse.” All that the hacker had to do to achieve this is remove the limit that said that only two NFTs can be scored per Ethereum wallet.

Marketplace vulnerabilities

The next flaw does not necessarily involve the NFTs themselves, but the marketplaces where they can be found. One example of this is OpenSea, the largest NFT marketplace in the world. Not too long ago, OpenSea suffered an attack during which the offending party managed to buy coins at their old price.

This loophole allowed several people to buy valuable NFTs at prices significantly under the tokens’ market value. The most notable project that was affected by this was the Bored Ape Yacht Club, with one of its NFTs (#9991) purchased for 0.77 ETH, only for the attacker to resell it for 84.2 ETH.

Exposed private keys

The third problem that I would like to mention is not specific to NFTs. In fact, it has been a part of the crypto industry ever since there was a crypto industry. It revolves around the safe storage of private keys, which are used for accessing wallets and conducting payments.

Hackers have identified many methods that can be used against uninformed investors to steal their private keys and access their coins and tokens. One of the most commonly used methods is phishing. Once again, OpenSea comes to mind, as it recently suffered a phishing attack, where users thought that they were sending transactions to the network.

Instead, a hacker tricked them into signing the data using MetaMask, and with the help of their signature, the attacker managed to steal their funds.

Re-entrancy attacks

Another type of attack is known as re-entrancy attack, and this one concerns OpenZeppelin’s most popular NFT standard. Essentially, OpenZeppelin’s most popular implementation of the NFT standard has a callback function.

Essentially, it is a function that is intended to help developers integrate NFTs into projects, but the problem is that it can also be misused for conducting re-entrancy attacks, provided that the code developers were careless enough to forget to provide protection against them. One of the latest examples of this attack happened on February 3rd when a HypeBeast NFT contract reported an attack transaction.

The project had a limit on how many NFTs an account can mint, but the attackers used the callback function to invoke the mintNFT function again.

NFT scams and rugs

There have been plenty of examples of this, such as Cool Kittens, which promised investors an electronic token with cat art, a purpose-built token called PURR, and membership in a DAO. All rather standard promises that plenty of NFT projects have made and delivered on. Cool Kittens, however, did not. Only three weeks after announcing the NFT collection, the minting started, and the NFTs went up for sale. The project exploded, selling over 2,200 NFTs in mere hours, for a price of $70 apiece.

The developers collected $160,000 from a global audience of buyers in crypto, and then they simply disappeared with the money. This is only one example of something that is rather common in the crypto industry, so anyone participating in token sales of any kind should keep it in mind and exercise extreme caution.

Conclusion

The NFT sector provides plenty of opportunities for rather rewarding investments, but it can also be used against investors through a number of different vulnerabilities. This is not always the case, as sometimes, the flaw may lie with the marketplace that sells them, investors who don’t know how to protect themselves, or even with the NFT developers, who wish to scam the community and disappear with their money.

The only way to protect investors from this is for projects to conduct audits of their smart contracts, and for marketplaces to regularly check their systems for bugs and flaws. As for investors themselves, the only thing they can do is exercise caution and work on educating themselves on the threats that they might encounter, and what to do if they do run into any of these or other issues.

热门币种推荐

你可能也喜欢

日本加息,为什么全世界都在紧张?

日本央行在2026年6月将政策利率提升至1%,这是自1995年来的首次。尽管1%的利率在主要经济体中并不高,但由于日本长期充当全球最低成本融资中心的特殊角色,此次加息引发了全球市场的广泛关注。 过去二十余年,日本近乎零的利率环境催生了大规模的日元套利交易。国际资本以极低成本借入日元,转而投资于全球高收益资产,如美国科技股和新兴市场债券,这为全球资产价格上涨提供了重要的流动性基础。日本加息意味着这一廉价资金源头开始收紧,可能引发全球资本的去杠杆化调整。 日本长期维持超低利率,源于其人口老龄化、长期通缩和高额政府债务等结构性约束。然而,疫情后全球通胀传导、国内工资持续增长(近年春斗涨薪均超5%)以及日元贬值压力,共同推动其货币政策转向。 市场担忧的核心并非当前1%的利率水平,而是日本持续三十年的超宽松货币政策框架发生根本性转变的趋势。这种变化将重塑全球套利交易的逻辑和风险资产的定价基础。不过,决定全球资本最终流向的关键,仍在于美日之间的利差变化。如果未来美联储进入降息周期而日本继续加息,两者货币政策差异的收窄可能对国际资本市场产生更深远的影响。 简言之,日本加息标志着全球最重要的低成本融资来源进入正常化进程,这可能引发建立在廉价日元资金之上的全球资本配置体系进行深度重估。

marsbit1小时前

日本加息,为什么全世界都在紧张?

marsbit1小时前

研报解读:MRVL 光学 AI 迎来爆发,为何高估值让大摩明星分析师选择按兵不动?

摩根士丹利分析师Joseph Moore于5月28日更新了对迈威尔(MRVL)的研报。尽管公司季报创纪录并大幅上调全年展望,但Moore维持“等权重”(中性)评级,目标价从172美元上调至195美元,仍低于当时股价。 **核心观点**:分析师认可迈威尔的AI增长机会,但认为当前股价已充分反映预期。195美元目标价对应约40倍2027年预期市盈率。对比英伟达,两者股价接近,但英伟达的每股盈利预期是迈威尔的两倍多。Moore认为,迈威尔需同时兑现以下假设才能支撑当前估值:1)光互联业务持续放量;2)定制AI芯片顺利大规模出货;3)存储及企业业务复苏。 **业务分析**: - **光互联**(高速增长):受益于AI集群数据传输需求,预计未来几个季度光模块产品线年化营收将达10亿美元,是当前最确定的增长点。 - **定制AI芯片**(正在爬坡):为云厂商设计专用芯片,新大客户预计2028财年量产,但今年收入尚不明朗。 - **传统业务**:存储、企业数据中心等板块仍处于去库存阶段,短期缺乏复苏动力。 **关键监测信号**:光模块营收能否如期达到10亿美元年化水平;新客户定制芯片项目能否在2028财年量产;传统业务何时复苏。若任何一环不及预期,当前高估值可能面临压力。 (本文为对第三方研报的解读,不构成投资建议。)

marsbit2小时前

研报解读:MRVL 光学 AI 迎来爆发,为何高估值让大摩明星分析师选择按兵不动?

marsbit2小时前

交易

现货
合约

热门文章

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

本周,加密市场迎来两股重磅催化——华盛顿“加密货币周”的立法攻势与以太坊机构布局的密集爆发,共同构成加密行业2025年下半年的“政策拐点”与“资金拐点”。这一轮加密周期的深层逻辑,正从比特币转向以太坊、稳定币及链上金融基础设施。我们认为:美国的政策明朗化+以太坊的机构化扩展,标志着加密行业正进入结构性转正阶段,市场配置的重心亦应逐步从“价格博弈”过渡至“规则+基础设施的制度红利捕捉”。

1.8k人学过发布于 2025.07.17更新于 2025.07.17

加密市场宏观研报:美国“加密货币周”来袭,ETH开启机构军备赛高潮

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对ETH(ETH)币价的意见。

活动图片