Cointime

Download App
iOS & Android

Unverified Ember Sword NFT auction contract vulnerability has caused nearly $200,000 in losses

Certik has discovered a vulnerability in the unverified Ember Sword NFT auction contract, which has earned 60 WETH (approximately $195,000) from 159 victims who approved the contract. Certik reminds users to revoke their approval of the relevant contract on Polygon.

Comments

All Comments

Recommended for you

  • State of Venus Q1 2024

    Venus (XVS) is a decentralized finance platform built on the BNB chain, offering a robust money market protocol for the crypto community. At its core, Venus enables users to deposit various cryptoassets, which can then be borrowed. Venus employs a unique algorithmic approach unlike traditional financial systems, where central entities often set interest rates. The interest rates for borrowing and lending on Venus are dynamically adjusted based on a jump rate model and whitepaper rate model. These models leverage the utilization ratio, which is the proportion of deposited assets that have been borrowed.
  • State of Aptos Q1 2024

    Aptos (APT) is a Layer-1 blockchain designed around the core tenets of scalability, safety, reliability, and upgradeability. Aptos was born out of Meta’s Diem and Novi projects, eventually launching in October 2022. Core developer Aptos Labs raised about $400 million in two 2022 private investor rounds.
  • How To Get Polygon Amoy Testnet MATIC and LINK Tokens

    Polygon Amoy is a testnet that allows developers to deploy, test, and optimize their smart contracts before deploying them on mainnet. This enables them to get their dApp user-ready without having to pay for gas on mainnet. Instead, they can power transactions with free testnet MATIC.
  • The address that defrauded 1,155 wBTC has returned more than 96% of the funds to the victims

    Blockchain data shows that the address poisoning attacker lured users to send 1,155 Wrapped Bitcoins (wBTC) (valued at $68 million at the time) to them. The attacker has returned almost all of the stolen funds. These funds were exchanged for Ethereum (ETH) during the attacker's holding period, and the price of ETH has since fallen. However, the attacker returned about 22,960.07 ETH, worth about $65.7 million, which accounts for over 96% of the initial stolen funds in terms of US dollar value.
  • Ethereum's Evolving Ecosystem - Staking, DeFi, and Derivative Markets

    The third part of our Glassnode Spotlights series, presenting the most interesting and actionable insights from the Coinbase x Glassnode Q2 Guide to Crypto Markets, explores Ethereum's Evolving Ecosystem - Staking, DeFi, and Derivative Markets.
  • Bitcoin’s Price Dynamics: Federal Reserve Policies and Economic Shifts in Focus

    This year, the factors influencing Bitcoin’s price shifted away from the interest rate narrative when spot Bitcoin ETFs were approved in the US in January. Since then, Bitcoin’s prices have re-aligned with market expectations on interest rates, now that ETF flows have diminished. The Federal Reserve is confronted with a challenging dilemma: it needs to control persistent inflation while also supporting a weakening U.S. economy. Over the long term, this predicament could turn out to be advantageous for Bitcoin.
  • Exploring Consensus With Parallel Proposals: The Difference Between PBFT and BBCA-Chain

    Recent works [BBCA-Chain, Motorway, Cordial-Miners, Shoal, Mysticeti-C, Sailfish] debunk the belief that Block-DAG BFT Consensus protocols have to pay significant latency to achieve throughput scalability. They provide alternative ways for leveraging parallel transaction dissemination.
  • TrumpAI tokens on Ethereum have been RUG

    PeckShield has monitored that the TrumpAI token on the Ethereum blockchain has fallen by 100%. An address starting with 0x935A sold 5,000,000,000,000,000,000,000 TrumpAI tokens, which is about 26.57 WETH (approximately $80,000). Note: rugpull tokens have the same name as legitimate tokens.
  • WOOFi attacker address has transferred 100 ETH to Tornado cash

    PeckShield monitoring shows that the address marked by the WOOFi attacker has transferred 100 ETH to Tornado cash. The WOOFi attacker has already transferred 2200 ETH (worth about $6.5 million) to Tornado cash.
  • The Base ecosystem Bloom project said it has recovered 90% of the funds stolen in the attack

    On May 10th, Bloom, a decentralized derivatives exchange on the X platform, announced that they have recovered $486,000 (minus 10% for bug bounties) out of the total funds utilized ($540,000). All of these funds will be redistributed to limited partners. 10% of the bug bounty has been agreed upon in exchange for not pressing charges against those who exploited the bug. A compensation plan for limited partners affected by the bug will be completed within the next 24-48 hours. Funds are safe and there is currently no need to revoke contract access.