• Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
Thursday, September 11, 2025
  • Login
  • Register
Coin24h.com
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining
No Result
View All Result
Coin24h.com
No Result
View All Result
Ledger Nano X - The secure hardware wallet
ADVERTISEMENT

Security flaw in Rarible NFT platform allowed attackers to steal crypto assets

15 April 2022
in Meta News
Reading Time: 6 mins read
A A
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter
cryptotrader
ADVERTISEMENT

Related articles

DraftKings Exits NFT Business Due to Legal Issues

DraftKings Exits NFT Business Due to Legal Issues

30 July 2024
BlockDAG’s Leadership Unveil – Crypto Market Titans Behind Game Changing Presale Challenge VeChain and Optimism’s Growth

BlockDAG’s Leadership Unveil – Crypto Market Titans Behind Game Changing Presale Challenge VeChain and Optimism’s Growth

30 July 2024

NFT and crypto tokens were stolen from Rarible customers before the issue was fixed. Learn more about it and how to prevent from this kind of threat.

Image: elenabs/Getty Images

Must-read security coverage

A new report from Check Point Research exposes a security flaw within the Rarible NFT (non-fungible tokens) marketplace. The security flaw was immediately reported to Rarible, which acknowledged and installed a fix for the issue.

Rarible is an online platform where users can create, buy or sell NFTs. It has more than 2 million registered users, and the company reported over $273 million trading volume in 2021, making it one of the biggest NFT marketplaces on the web.

The security flaw in Rarible

The Non-Fungible Token Standard, EIP-721, allows the implementation of a standard API for NFTs within smart contracts. The standard provides basic functionality to track and transfer NFTs.

One of the functions listed in the standard is called setApprovalForAll (Figure A).

Figure A

Image: Ethereum.org. Function setApprovalForAll from EIP-721 standard.
Image: Ethereum.org. Function setApprovalForAll from EIP-721 standard.

Researchers from CheckPoint explained that “this function basically designates who is authorized to control all your tokens/NFTs, which is mainly created for third parties like Rarible/OpenSea, etc., to control the NFT/tokens on behalf of the users.”

That function allows anyone to control a user’s NFTs if that user gets tricked into signing it. Since a lot of users do not really understand all the technical aspects of NFTs, they might sometimes give control over their NFTs while they thought they were just handling a regular transaction. Phishing attacks sometimes use this trick of luring victims into doing what seems to them as regular transactions while in fact they are giving their NFTs to an attacker. Yet it gets worse when it comes from the NFT marketplace itself.

The proof of concept for this NFT attack

CheckPoint researchers decided to create a SVG file containing a payload that would execute Javascript code.

That payload checks what NFTs the user has, using the function tokennfttx from the Ethereum API. The payload would then loop through all the NFTs, sending a setApprovalForAll transaction to the wallet (Figure B).

Figure B

Image: CheckPoint. Using API to send setApprovalForAll requests for every NFT belonging to the victim.
Image: CheckPoint. Using API to send setApprovalForAll requests for every NFT belonging to the victim.

If the user clicked on the confirmation button, they would provide full access to all their NFTs to the attacker (Figure C).

Figure C

Image: CheckPoint. The malicious art on the left and the fraudulent request on the right.
Image: CheckPoint. The malicious art on the left and the fraudulent request on the right.

The attacker would then be able to transfer all the NFTs to his or her own account.

Jay Chou had an NFT stolen by this attack

The same attack targeted successfully Jay Chou, a famous Taiwanese singer, who fell for the phishing and granted full access to his NFT to the attacker. Once the access was provided, the attacker transferred one NFT to another wallet and later sold it on the marketplace for about $500,000.

The business impact of this NFT-stealing attack

There are many uses for NFTs within companies, and some of them have immediately rushed to the NFT phenomena. The main use of NFTs for business is to promote brands by selling exclusive items to customers or fans. Some companies also offer NFTs to their customers as gifts. Another interesting use for branding is to use NFTs to help build new communities, in which users get social value by the number of NFTs they own.

NFTs can also be used as proof of attendance for events or trainings/certifications. People participating in the event would receive a unique token as a proof that they have indeed attended.

Those companies generally use popular NFT marketplaces to sell or handle their items (Figure D), which makes them vulnerable to the attack exposed in this article. The company’s account could be targeted by cybercriminals in an attempt to have the account grant full access to all its NFTs using the setApprovalForAll method exposed by CheckPoint, and have the tokens be transferred to other wallets before being sold.

Figure D

Image: Twitter. The Coca-Cola company using OpenSea platform to handle NFT.
Image: Twitter. The Coca-Cola company using OpenSea platform to handle NFTs.

How to protect your NFTs from this security threat

  • NFT and blockchains are complex for most users, and that complexity is mostly due to users not really caring about how it really works. It makes attacks easier and helps cybercriminals to steal NFTs with a few social engineering methods. Users should read and understand more about blockchains and NFTs, in order to have sufficient knowledge to distinguish a scam from a legitimate request.
  • Users should always carefully review any request they get and consider whether it seems suspicious or not.
  • If any doubt subsists, users should reject the request or ask their cybersecurity department about it.
  • Users should review and revoke token approvals when necessary.

Disclosure: I work for Trend Micro, but the views expressed in this article are mine.

Credit: Source link

Cryptohopper
ADVERTISEMENT
[crypto-donation-box]
Tags: AllowedAssetsAttackerscryptoFlawNFTPlatformRaribleSecuritySteal
Share76Tweet47
Ledger Nano X - The secure hardware wallet
Previous Post

Instagram NFT Marketplace Eyeing TikTok Expansion

Next Post

Should You Buy BNB (BNB) Friday?

Related Posts

DraftKings Exits NFT Business Due to Legal Issues

DraftKings Exits NFT Business Due to Legal Issues

30 July 2024
0

DraftKings Inc. (NASDAQ:DKNG) is shutting down its non-fungible token (NFT) business “effective immediately,” as announced in an email to customers....

BlockDAG’s Leadership Unveil – Crypto Market Titans Behind Game Changing Presale Challenge VeChain and Optimism’s Growth

BlockDAG’s Leadership Unveil – Crypto Market Titans Behind Game Changing Presale Challenge VeChain and Optimism’s Growth

30 July 2024
0

With the cryptocurrency market rebounding from earlier volatility, both Optimism (OP) NFT trading and VeChain (VET) price predictions are trending...

DoodlesTV Launches With Season Pass on Base for Exclusive Content

DoodlesTV Launches With Season Pass on Base for Exclusive Content

30 July 2024
0

Ahead of impending film and music releases, Ethereum NFT-based project Doodles announced the launch of DoodlesTV Super Pass on Tuesday,...

Crypto Rallies Behind Artists Who Sued SEC Over NFT Regulatory Jurisdiction

Crypto Rallies Behind Artists Who Sued SEC Over NFT Regulatory Jurisdiction

30 July 2024
0

KEY POINTSFrye and Mann filed the complaint to ask whether the SEC should regulate 'art'They accused the SEC of waging...

How Much U.S. Government Holds In Bitcoin? Arkham Reveals

How Much U.S. Government Holds In Bitcoin? Arkham Reveals

30 July 2024
0

some of the major developments in the world of cryptocurrencies The US government still owns over 183,000 Bitcoin BTC $66,537, worth...

Load More
Next Post

Should You Buy BNB (BNB) Friday?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Plugin Install : Widget Tab Post needs JNews - View Counter to be installed
  • Trending
  • Comments
  • Latest
ADA Price Holds Key Support Despite 0M Whale Sell-Off

ADA Price Holds Key Support Despite $140M Whale Sell-Off

11 September 2025
Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance

Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance

11 September 2025
BNB Hits New All-Time High Above 7 Amid Strong Futures Activity – Coinspeaker

BNB Hits New All-Time High Above $907 Amid Strong Futures Activity – Coinspeaker

11 September 2025
CryptoQuant Predicts BNB To Hit ,000

CryptoQuant Predicts BNB To Hit $1,000

11 September 2025

About Us

We publish a comprehensive news feed covering all news relevant to the crypto user, covering main industry news, politics and regulation as well as consumer-level “news you can use” (practical stuff), including handy DIY tips, links to useful tools, unbiased reviews and opinions revolving around cryptocurrency. Simple logic and real-world examples are preferred before technical jargon and personal rants.

Categories

  • Altcoin
  • ApeCoin
  • Bitcoin
  • Blockchain
  • BNB
  • Cardano
  • Cryptocurrency
  • DOGE
  • DOT
  • Ethereum
  • HBAR
  • Litecoin
  • Market
  • Meta News
  • Mining
  • NFT
  • QNT
  • Regulation
  • SHIBA
  • Solano
  • Tether
  • Uncategorized
  • XDC
  • XLM
  • XRP

What’s New Here!

  • ADA Price Holds Key Support Despite $140M Whale Sell-Off
  • Here’s why Bitwise is tipping Solana for an end-of-year rally. And what could stall it – Yahoo Finance
  • BNB Hits New All-Time High Above $907 Amid Strong Futures Activity – Coinspeaker
  • CryptoQuant Predicts BNB To Hit $1,000
  • Morning Minute: Solana's New Path to ATH – Yahoo Finance

Subscribe Now

Our Partner

Round Main Logo
  • About Us
  • Privacy Policy
  • Contact Us

© 2022-2025 coin24h.com

No Result
View All Result
  • Home
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • XRP
    • Litecoin
    • Altcoin
    • Cardano
    • Tether
    • DOGE
    • Solano
    • XLM
    • DOT
    • XDC
    • SHIBA
    • BNB
    • Ape
    • HBAR
    • QNT
  • Blockchain
  • Regulation
  • Market
  • Live
    • Prices
    • ICO
  • Meta
    • NFT
  • Technical Analysis
    • XRP
    • BTC
    • XLM
    • ADA
    • TETHER
    • ETC
    • ETH
    • DOGE
    • LTC
  • Exchange
  • Mining

© 2020 coin24h.com

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • bitcoinBitcoin (BTC) $ 114,011.00
  • ethereumEthereum (ETH) $ 4,400.88
  • xrpXRP (XRP) $ 2.99
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 897.38
  • solanaSolana (SOL) $ 226.14
  • usd-coinUSDC (USDC) $ 0.999809
  • staked-etherLido Staked Ether (STETH) $ 4,393.60
  • dogecoinDogecoin (DOGE) $ 0.248160
  • tronTRON (TRX) $ 0.344742
  • cardanoCardano (ADA) $ 0.874234
  • wrapped-stethWrapped stETH (WSTETH) $ 5,336.36
  • chainlinkChainlink (LINK) $ 23.56
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,740.77
  • hyperliquidHyperliquid (HYPE) $ 54.13
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 113,832.00
  • ethena-usdeEthena USDe (USDE) $ 1.00
  • suiSui (SUI) $ 3.59
  • stellarStellar (XLM) $ 0.384945
  • figure-helocFigure Heloc (FIGR_HELOC) $ 0.992931
  • avalanche-2Avalanche (AVAX) $ 28.80
  • wrapped-eethWrapped eETH (WEETH) $ 4,730.03
  • bitcoin-cashBitcoin Cash (BCH) $ 591.60
  • wethWETH (WETH) $ 4,402.13
  • hedera-hashgraphHedera (HBAR) $ 0.234417
  • leo-tokenLEO Token (LEO) $ 9.57
  • litecoinLitecoin (LTC) $ 114.44
  • crypto-com-chainCronos (CRO) $ 0.256323
  • the-open-networkToncoin (TON) $ 3.16
  • usdsUSDS (USDS) $ 0.999696
  • shiba-inuShiba Inu (SHIB) $ 0.000013
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999652
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 113,965.00
  • polkadotPolkadot (DOT) $ 4.16
  • whitebitWhiteBIT Coin (WBT) $ 43.27
  • uniswapUniswap (UNI) $ 9.78
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.199781
  • mantleMantle (MNT) $ 1.62
  • ethenaEthena (ENA) $ 0.751277
  • moneroMonero (XMR) $ 271.71
  • aaveAave (AAVE) $ 302.06
  • bitget-tokenBitget Token (BGB) $ 4.89
  • daiDai (DAI) $ 1.00
  • pepePepe (PEPE) $ 0.000010
  • okbOKB (OKB) $ 193.62
  • bittensorBittensor (TAO) $ 355.09
  • nearNEAR Protocol (NEAR) $ 2.69
  • jito-staked-solJito Staked SOL (JITOSOL) $ 278.27
  • memecoreMemeCore (M) $ 1.97