A well-known sports league's digital collectible contract has a serious vulnerability, allowing hackers to mint for free and profit.

robot
Abstract generation in progress

Recently, a digital collectible launched by a well-known sports league has attracted the attention of security experts. Professionals discovered a serious security vulnerability after reviewing its sales contract. This vulnerability allows technically savvy individuals to create collectibles without paying any fees and profit from them.

The root of the problem lies in the defect of the contract's signature verification mechanism for whitelisted users. Specifically, the contract fails to ensure the exclusivity and one-time use of the whitelist signatures. This means that potential attackers can reuse the signatures of other whitelisted users to mint collectibles.

From a technical perspective, the design of the verify function has obvious flaws, as it does not include the sender's address in the signature verification process. More notably, there is also no mechanism set in the contract to ensure that each signature can only be used once. These should be basic software security measures, yet they have been overlooked in this high-profile project.

Security experts expressed surprise at this, believing that such basic security practices should be an indispensable part of any blockchain project development process. They emphasized that even well-known projects cannot overlook the most fundamental security audit steps.

This event once again highlights the importance of security in the blockchain and digital asset space, which cannot be overlooked. For developers and investors participating in such projects, enhancing security awareness and conducting thorough security audits will be one of the key factors for the success of future projects.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 7
  • Share
Comment
0/400
BridgeJumpervip
· 10h ago
Is it just a shoddy job to launch it?
View OriginalReply0
SatoshiLegendvip
· 10h ago
From the perspective of the source code, history will always repeat itself.
View OriginalReply0
DaoGovernanceOfficervip
· 10h ago
*sigh* yet another protocol skipping basic security measures... predictable tbh
Reply0
MissingSatsvip
· 10h ago
Again, it's an Allowlist Replay Attack. The security is still too poor.
View OriginalReply0
ClassicDumpstervip
· 10h ago
This bug is really nice To da moon
View OriginalReply0
DaoDevelopervip
· 10h ago
smh... basic reentrancy check would've caught this
Reply0
ApeWithAPlanvip
· 10h ago
How could such a big loophole in the contract pass compliance audit?
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate app
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)