HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore

Archived tweet

Back

Tweet by NFTstats.eth:

A few notes about today's hack:

1) There was one keynote hacker, but there were a LOT of other hackers. Once the exploit was known, many others used it and started finding wallets to rob from on their own.

2) The hack was made possible by errors in the coding by NFT Trader. In order to work, it required permissions from the victims on their NFTs to have been opened to NFT Trader.  Mostly these permissions were months or years old.

3) The theft ended when 
@0xf4d3
 and 
@0xfoobar
 figured out a patch for the NFT Trader buggy code.

4) You're probably hearing about the one hacker who is negotiating with owners for return of their assets. That hacker has returned one ape, 31 ETH and a couple mutants.  The majority from that hacker has not been returned.  

5) Best way to stay safe is to keep your valuable NFTs in a cold drive wallet that only interacts with the world by sending those NFTs to other wallets and does nothing else.

6) Also - it wasn't just NFTs stolen.  You can open permission on your non ETH tokens as well.  WETH, APE and more have been taken from wallets. 
Tweeted at 1:10 PM · Dec 16, 2023

Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.

Source code | Contribute