NFT marketplace bug undervalues tokens, helps exploiter nab $750,000

2 years ago

The NFT marketplace bug was reportedly discovered connected Dec. 31, which showed transferred NFTs arsenic listed connected OpenSea.

1801 Total views

7 Total shares

NFT marketplace bug undervalues tokens, helps exploiter nab $750,000

A bug successful the beforehand extremity of fashionable nonfungible token (NFT) marketplace OpenSea has reportedly led to an exploit allowing users to bargain fashionable NFTs astatine their erstwhile listing price.

The bug seems to beryllium prevalent with Bored Ape Yacht Club (BAYC) and Mutant Ape Yacht Club (MAYC) NFT collectibles, wherever the exploiter managed to bargain them astatine their aged listing terms and past sold them for the existent marketplace price. The affected NFTs see BAYC #9991, BAYC #8924, MAYC #4986.

Opensea User Activity Tab Source: OpenSea

A idiosyncratic named jpegdegenlove is suspected of exploiting the existent bug and has reportedly profited 332 Ether (ETH) ($754,000). OpenSea didn’t instantly respond to Cointelegraph’s petition for comment.

Reported exploiter Ether wallet equilibrium Source: Etherscan

An earlier exploit connected Dec, 31 saw a akin scenario, wherein a bug seems to originate from the transportation of assets from the OpenSea wallet to a antithetic wallet without canceling the listing.

Related:  Nifty News: FLUF World and Snoop Dogg fundraise, Adidas and Prada NFTs, WAX gifts 10M NFTs

One Twitter idiosyncratic explained that, erstwhile a idiosyncratic lists their collectible for auction connected the OpenSea and decides to cancel it for immoderate reason, the marketplace charges a important interest and the level terms of the collectible besides decreases. Users recovered a mode astir it and alternatively of canceling their sale, they transportation their plus to a antithetic wallet which automatically removes the listing from OpenSea, However, the bug keeps the listing progressive done OpenSea’s API. 

1/ Recently there's been an @opensea exploit that has allowed for assets to beryllium purchased astatine greatly discounted prices, including 3 freshdrops passes, a BAYC https://t.co/8pEgeXkOBo, aggregate MAYCs, and more. I did immoderate probe this greeting and here's what's happening -> a

— cap10bad.ΞTH | freshdrops.io (@cap10bad) December 31, 2021

Users tin cheque whether their listing has been removed connected Rarible, different NFT marketplace that uses OpenSea’s API. The idiosyncratic claimed that the bug was flagged aft the December incident, but the level didn’t instrumentality immoderate measures to code the issue.

NFTs exploded successful popularity successful 2021 with large brands and celebrities each hopping connected the bandwagon, which has attracted an expanding fig of scams

View source