• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Thursday, September 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Rarible NFT Marketplace Flaw Could’ve Let Attackers Hijack Crypto Wallets

14 April 2022
in NFT
Reading Time: 4 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

SEC became a defendant in the NFT classification lawsuit

SEC became a defendant in the NFT classification lawsuit

30 July 2024
DraftKings Dumps NFT Business, Citing Legal Developments

DraftKings Dumps NFT Business, Citing Legal Developments

30 July 2024

Cybersecurity researchers have disclosed a now-fixed security flaw in the Rarible non-fungible token (NFT) marketplace that, if successfully exploited, could have led to account takeover and theft of cryptocurrency assets.

“By luring victims to click on a malicious NFT, an attacker can take full control of the victim’s crypto wallet to steal funds,” Check Point researchers Roman Zaikin, Dikla Barda, and Oded Vanunu said in a report shared with The Hacker News.

Rarible, an NFT marketplace that enables users to create, buy, and sell digital NFT art like photographs, games, and memes, has over 2.1 million active users.

CyberSecurity

“There is still a huge gap between, in terms of security, between Web2 and Web3 infrastructure,” Vanunu, head of products vulnerabilities research at Check Point, said in a statement shared with The Hacker News.

“Any small vulnerability can possibly allow cyber criminals to hijack crypto wallets behind the scenes. We are still in a state where marketplaces that combine Web3 protocols are lacking from a security perspective. The implications following a crypto hack can be extreme.”

The attack modus operandi hinges on a malicious actor sending a link to a rogue NFT (e.g., an image) to potential victims that, when opened in a new tab, executes arbitrary JavaScript code, potentially allowing the attacker to gain complete control over their NFTs by sending a setApprovalForAll request to the wallet.

The setApprovalForAll API allows a marketplace (in this case, Rarible) to transfer sold items from the seller’s address to the buyer’s address based on the implemented smart contract.

“This function is very dangerous by design because this may allow anyone to control your NFTs if you get tricked into signing it,” the researchers pointed out.

CyberSecurity

“It’s not always clear to users exactly what permissions they are giving by signing a transaction. Most of the time, the victim assumes these are regular transactions when in fact, they were giving control over their own NFTs.”

In granting the request, the fraudulent scheme effectively permits the adversary to transfer all the NFTs from the victim’s account, which can then be sold by the attacker on the marketplace for a higher price.

“The vulnerability could potentially affect users only in case they deliberately leave Rarible.com for a third-party resource with malicious content, and consciously sign suggested transactions with their wallets,” Rarible said in a statement shared with The Hacker News.

“Simply clicking the link is not enough and user interaction and confirmation for transactions is required. We encourage users to stay vigilant, and pay attention to the websites they visit and transactions they sign to stay safe.”

As safeguards, it’s recommended that users carefully scrutinize transaction requests prior to providing any kind of authorization. Previous token approvals can be reviewed and revoked by visiting Etherscan’s Token Approval Checker tool.

“NFT users should be aware that there are various wallet requests – some of them are used just to connect the wallet, but others may provide full access to their NFTs and Tokens,” the researchers said.


Credit: Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: AttackerscouldvecryptoFlawHijackmarketplaceNFTRariblewallets
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Bitcoin 2022 Recap, GA Day 2. Afternoon: Peterson, Alden, Weinstein, Stark & More

Next Post

Generation Z To Alpha On Financial Freedom And NFTs & Web3

Related Posts

SEC became a defendant in the NFT classification lawsuit

SEC became a defendant in the NFT classification lawsuit

30 July 2024
0

Law professor and filmmaker Brian Frye and songwriter Jonathon Mann have filed a lawsuit against the U.S. Securities and Exchange...

DraftKings Dumps NFT Business, Citing Legal Developments

DraftKings Dumps NFT Business, Citing Legal Developments

30 July 2024
0

Sports gambling company Draftkings is shutting down its non-fungible token (NFT) business "effective immediately," the company said in an email...

Empire Newsletter: Why the Song-a-Day man is suing the SEC

Empire Newsletter: Why the Song-a-Day man is suing the SEC

30 July 2024
0

Today, enjoy the Empire newsletter on Blockworks.co. Tomorrow, get the news delivered directly to your inbox. Subscribe to the Empire newsletter....

Two artists sue the SEC for regulation on NFTs

Two artists sue the SEC for regulation on NFTs

30 July 2024
0

Still confusion in the field of regulation in the USA: two artists have sued the SEC, drawing a comparison between...

BlockDAG Soars Over Solana Bullish Surge, Polkadot Price

BlockDAG Soars Over Solana Bullish Surge, Polkadot Price

29 July 2024
0

The crypto market opens with optimistic trends of Solana’s bullish surge and Polkadot price increase. As investors focus on Solana’s...

Load More
Next Post

Generation Z To Alpha On Financial Freedom And NFTs & Web3

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance

Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance

11 September 2025
SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?

SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?

11 September 2025
Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block

Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block

11 September 2025
Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action

Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action

11 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • Solana Treasury Firms Boost Holdings to 6.5M SOL as Upexi Posts 126% Surge – Yahoo Finance
  • SharpLink Transfers 379M USDC To Galaxy Digital: Ethereum Buy Incoming?
  • Galaxy's Novogratz calls it the 'season of SOL', says Solana is tailor made for financial markets – The Block
  • Can CPI Rates Drive Market Sentiment-Bitcoin and Altcoins Poised for a Massive Price Action
  • 78,229 Ethereum Leaves Kraken As 4 New Wallets Move ETH: Institutional Accumulation?

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 115,043.00
  • ethereumEthereum (ETH) $ 4,444.19
  • xrpXRP (XRP) $ 3.03
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 900.13
  • solanaSolana (SOL) $ 228.37
  • usd-coinUSDC (USDC) $ 0.999818
  • dogecoinDogecoin (DOGE) $ 0.255446
  • staked-etherLido Staked Ether (STETH) $ 4,436.54
  • tronTRON (TRX) $ 0.345784
  • cardanoCardano (ADA) $ 0.890901
  • wrapped-stethWrapped stETH (WSTETH) $ 5,387.66
  • chainlinkChainlink (LINK) $ 24.26
  • hyperliquidHyperliquid (HYPE) $ 56.46
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,788.36
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 114,929.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.67
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • stellarStellar (XLM) $ 0.394140
  • avalanche-2Avalanche (AVAX) $ 29.07
  • wrapped-eethWrapped eETH (WEETH) $ 4,776.66
  • bitcoin-cashBitcoin Cash (BCH) $ 594.45
  • wethWETH (WETH) $ 4,443.58
  • hedera-hashgraphHedera (HBAR) $ 0.240040
  • leo-tokenLEO Token (LEO) $ 9.59
  • litecoinLitecoin (LTC) $ 115.89
  • crypto-com-chainCronos (CRO) $ 0.259476
  • the-open-networkToncoin (TON) $ 3.20
  • usdsUSDS (USDS) $ 0.999830
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 115,051.00
  • polkadotPolkadot (DOT) $ 4.25
  • whitebitWhiteBIT Coin (WBT) $ 43.63
  • uniswapUniswap (UNI) $ 9.96
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199275
  • mantleMantle (MNT) $ 1.65
  • ethenaEthena (ENA) $ 0.774667
  • moneroMonero (XMR) $ 271.08
  • aaveAave (AAVE) $ 308.71
  • bitget-tokenBitget Token (BGB) $ 4.91
  • pepePepe (PEPE) $ 0.000011
  • daiDai (DAI) $ 0.999426
  • okbOKB (OKB) $ 194.28
  • bittensorBittensor (TAO) $ 358.91
  • nearNEAR Protocol (NEAR) $ 2.75
  • ondo-financeOndo (ONDO) $ 1.07
  • jito-staked-solJito Staked SOL (JITOSOL) $ 280.71